14-day trial, no credit cardStart now

Features

What PermitUSB does today, by area. A USB device control platform for Windows endpoints: block-by-default whitelisting with a cloud control plane.

ReferenceUpdated for agent 1.0.60

Enforcement

  • Block-by-default whitelisting on USB devices
  • Kernel-mode enforcement via a Microsoft-signed filter driver, blocking devices on the USB stack below anything reachable from Device Manager or an elevated shell
  • Enforcement from early boot using a locally cached policy snapshot, before the agent service starts
  • Kernel enforcement active wherever the driver is installed, with a per-endpoint and workspace-wide kill switch to stand it down
  • User-mode enforcement through Windows Configuration Manager APIs as a second layer, and as the only layer on endpoints without the driver
  • Match on vendor and product (VID/PID), serial, device group, vendor name, or device class
  • Allow, block and audit actions
  • Built-in HID-class guardrails
  • HID-injection detection: flags rapid keystroke injection by typing rate, prompts the user, and raises a security event if declined

Cloud management

  • Multi-tenant dashboard with per-tenant data isolation
  • Email and password sign-in with TOTP multi-factor authentication, or a passkey
  • Role-based access: owner, admin, operator, auditor
  • User invitations
  • Endpoint groups with per-group policies
  • Temporary approvals: allow a device through end of a chosen day - or until an exact time that day - and it stops working at the deadline, online or offline, with the expired entry kept as history
  • Per-group discovery mode for a risk-free rollout
  • Check in now: an online endpoint applies a policy change within seconds instead of waiting for its next check-in. Approve a drive that is already plugged in and it starts working in place, with no replug and nothing for the user to do - group changes made from an event nudge that endpoint automatically

Operations

  • Tray app with a toast on every block
  • Service ACL self-protection
  • Watchdog that re-disables a manually re-enabled blocked device
  • Stale-policy fail-closed when an endpoint loses cloud connectivity
  • Tamper event reporting

Deployment

  • EV code-signed MSI installer with the signed kernel driver bundled
  • One-line PowerShell install straight from the dashboard
  • Group Policy and Microsoft Intune deployment guides

Billing and lifecycle

  • Stripe Checkout and Customer Portal
  • 14-day no-card trial
  • Trial expiry with a 30-day grace period

Compliance and observability

  • Admin audit log
  • Reports: blocked devices, device inventory, silent endpoints, and tamper or protection-pause activity, each exportable as CSV and always stating how much of the truth the table shows
  • Device history: search everything the fleet has seen, then one page per device with its group memberships, every endpoint it touched, and its full event timeline
  • Full-history event export with an explicit date range and a row count shown before the download starts
  • Event export to CSV and JSON
  • SIEM forwarding in CEF: the agent writes device and security events to the Windows event log, and an on-prem relay for Windows or Linux pulls them to your syslog SIEM
  • NIST 800-171 control mapping
  • Email and webhook alerts

Something missing or wrong here? Tell us. Documentation gaps get filled fast.