ZENQIX Endpoint / ARCHITECTURE

Evidence enters through a bounded service.

The current pilot shape connects a platform-specific agent, an authenticated FastAPI service and an operator review surface. Each layer has an explicit limit.

Architecture and data flow

Where evidence enters, and where it stops.

The flow mirrors the current product boundary. It does not imply an unimplemented platform layer.

  1. 01

    Agent

    A platform-specific agent reports enrollment, heartbeat and available inventory fields. It does not send credentials or document contents as routine telemetry.

  2. 02

    Authenticated service

    The FastAPI service authenticates the device, stores customer-scoped records and evaluates explainable availability and health evidence.

  3. 03

    Operator view

    Authenticated operators use server-side permission checks to review fleet, device, job, report and audit routes.

  4. 04

    Guarded support

    Remote support is device-bound, permission-gated and short-lived; it remains a private preview capability until physical QA is complete.

Available / Preview / Planned

Capability truth stays close to the evidence.

States below are intentionally conservative. Partial source coverage remains Preview until the full product boundary is accepted.

CapabilityStatusEvidence boundaryPublic proof
Enrollment and device identity
Device identity is stored server-side and scoped to the authenticated service.
AvailableSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Sanitized device identity view
Hardware inventory
Only fields reported by the agent are shown; missing telemetry stays unknown.
PreviewSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Interface preview
Software inventory
Publisher, install date and other fields remain dependent on agent support.
PreviewSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Software list preview
Online, offline and stale state
Silence is reported as unavailable or stale evidence, not as proof of shutdown.
AvailableSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Availability report preview
Lifecycle, site and hierarchy
Retire and restore preserve history and require fresh enrollment for a new credential.
AvailableSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Fleet filter preview
Jobs and bounded diagnostics
Operator, target, state and result evidence are retained in the authenticated service.
AvailableSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Job timeline preview
RBAC and audit
Administrative actions require server-side permissions; unknown admin routes deny by default.
AvailableSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Audit timeline preview
Remote support
The workflow is implemented but remains gated by physical QA and deployment configuration.
PreviewSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Sanitized support-session preview
Patch and broader device management
Patch execution, mobile management, EDR and endpoint privilege management are not claimed here.
PlannedSource-backed capability and test evidence.
Private operator boundary; no public credentials or production records.
Not shown as available

This public page shows source-backed product shape and sanitized demonstration evidence for Endpoint. It is not a customer report, production dashboard or general-availability promise.