A monitoring agent your security team can sign off on
Productivity tools put an agent on every computer and send data off-site, so IT gets asked the hard questions. CyberWall Insights is built and run by a managed security provider. Security is our number one priority, and the product shows it: a small Windows service, Intune deployment, MFA on every login, and no content capture.
| Computer | User | Agent | Last seen |
|---|---|---|---|
| DESKTOP-14 | A. Rivera | Current | 1 min ago |
| LAPTOP-07 | J. Chen | Current | 2 min ago |
| LAPTOP-22 | M. Patel | Pending | — |
The questions you'd ask any monitoring vendor
Another agent on every endpoint
Each agent is something to deploy, update, troubleshoot and trust with data from the device.
Data collection that goes too far
Keystroke logging and full-URL capture create a store of sensitive data that becomes its own risk.
A vendor outside your security stack
A productivity vendor with no connection to your security program is one more third party to vet.
Behavior signals live in the wrong tool
USB copies and file-sharing sites are security signals, but they often land with HR's software instead of yours.
Deploy and manage it with Microsoft Intune
The Insights agent is a small Windows service. Push it to company computers through Microsoft Intune and track rollout status from the console. It sends short activity summaries a few times a minute over the internet, with negligible performance impact.
- Windows agent deployed through Microsoft Intune
- Rollout status and last-seen per computer
- Works on any network with internet access
| Computer | User | Agent | Last seen |
|---|---|---|---|
| DESKTOP-14 | A. Rivera | Current | 1 min ago |
| LAPTOP-07 | J. Chen | Current | 2 min ago |
| LAPTOP-22 | M. Patel | Pending | — |
Collect only what the reports need
Insights records whether input is present, never which keys. It records the foreground application and window, and websites by site name only. Screenshots are an add-on that's off by default, enabled only by CyberWall at your request, never taken while the screen is locked, and auto-deleted after 7, 14 or 30 days.
- No keystrokes, email, chat or document contents
- Site names only, never full URLs
- Screenshots off by default with auto-deletion
| Time | Productivity | Computer | App | Window | Site |
|---|---|---|---|---|---|
| 10:42:10 | Productive | DESKTOP-14 | Excel | Q3 forecast.xlsx | — |
| 10:39:52 | Neutral | DESKTOP-14 | Chrome | — | google.com |
| 10:31:04 | Productive | DESKTOP-14 | Chrome | — | salesforce.com |
| 10:12:40 | System | DESKTOP-14 | — | Screen locked | — |
| 10:02:18 | Unproductive | DESKTOP-14 | Chrome | — | youtube.com |
| 09:58:01 | Productive | DESKTOP-14 | Outlook | Inbox | — |
Built like the security platform it shares a console with
Every login uses MFA. Access is granted per manager, and each company's data is isolated from every other company's. Website blocking lets you keep users off sites you don't allow, and Microsoft, Windows Update and CyberWall sites can never be blocked by mistake.
- MFA on every login
- Per-company data isolation
- Website blocking list with protected system sites
Behavior signals and threat detection in one place
CyberWall Shield provides 24x7 managed detection and response, Microsoft 365 sign-in and account monitoring, and backup and recovery. Insights adds alarms for USB file copies, file-sharing sites and after-hours activity. Same console, same login, one security team watching both.
- 24x7 MDR and Microsoft 365 monitoring from Shield
- Insider-risk alarms from Insights
- Alerts to email, Teams, Slack or webhooks
The short version of the security questionnaire
| Question | Answer |
|---|---|
| Supported platforms | Windows computers |
| Deployment | Microsoft Intune |
| What's collected | Active vs idle time, foreground app and window, site names, system events (lock, unlock, sleep), USB file copy events |
| What's never collected | Keystrokes, email, chat or document contents, full URLs, screenshots while locked |
| Login security | MFA on every login |
| Tenant separation | Each company's data isolated |
| Notifications | Email, Microsoft Teams, Slack, generic webhooks |
| Exports | CSV |
| Single sign-on | Not available today |
A security provider that built a productivity tool
CyberWall runs managed IT and security for its clients. We built Insights by listening to those clients, tested every feature on our own staff first, and run it with the same security practices we apply to CyberWall Shield.
About CyberWallQuestions we hear
Does the agent run on macOS or Linux?
Insights runs on Windows computers today.
What network access does the agent need?
Outbound internet access to send activity summaries. No VPN or inbound connections are required. Contact us for the details your firewall team needs.
Can we use SSO?
Not today. Every login uses MFA, and access is granted per manager.
Is Insights a DLP or EDR product?
No. Insights flags behavior signals like USB copies and file-sharing site visits for human review. Threat detection and response come from CyberWall Shield.
Does Insights hold any certifications like SOC 2?
We don't claim certifications for Insights. We're happy to walk through how data is collected, stored and isolated, and the reports can support your own policy documentation.
Who can turn on screenshots?
Only CyberWall, at the customer's request. The add-on is off by default for every company.
Put Insights through your own review.
Start a 14-day trial on a few test machines, or talk with our security team about how it fits your stack.
