

Read in order for a complete onboarding path, or jump to any chapter. Each chapter opens the full article with steps and tables.
Chapter 1 · Getting Started
Understand the Trustity platform, its management and enforcement components, and the recommended path to a verified first deployment.
Open chapter →Chapter 2 · Getting Started
Which Trustity website to use, where to sign in, and how the public marketing site, Cloud Portal, MSSP portal, Dev, and Labs fit together.
Open chapter →Chapter 3 · Getting Started
Prepare administrators, entitlements, policies, deployment controls, and acceptance criteria for a new Trustity organization.
Open chapter →Chapter 4 · Getting Started
Map Trustity entitlements to portal areas, endpoint components, supported platforms, policies, and deployment checks.
Open chapter →Chapter 5 · Getting Started
Prepare DNS, HTTPS egress, proxy, TLS inspection, browser services, and validation for Trustity endpoints and administrators.
Open chapter →Chapter 6 · Getting Started
Navigate the Trustity Cloud Portal and use its deployment, policy, device, event, user, and audit areas safely.
Open chapter →Chapter 7 · Cloud Portal
Download entitled endpoint installers, enroll devices with your organization license key, and validate successful deployment.
Open chapter →Chapter 8 · Cloud Portal
Prod and eval branches, Latest/Previous targeting, and quiet auto-update for Windows and Linux TAO agents.
Open chapter →Chapter 9 · Getting Started
Deploy and enroll the Trustity Agent on Windows interactively or silently, then verify service, portal, and module health.
Open chapter →Chapter 10 · Getting Started
Download TAO from the Cloud Portal, install and enroll it on supported Linux systems, and verify systemd and portal health.
Open chapter →Chapter 11 · Getting Started
Prove that the first TAO endpoint is installed, enrolled, online, current, receiving policy, and ready for a controlled module test.
Open chapter →Chapter 12 · Getting Started
Expand Trustity from a verified pilot into production with staged rings, change control, and measurable exit criteria.
Open chapter →Chapter 13 · Cloud Portal
Navigate entitled policy areas, make controlled changes, and validate endpoint enforcement.
Open chapter →Chapter 14 · Cloud Portal
Configure Windows agent uninstall, service-stop, and standard-user UI protections.
Open chapter →Chapter 15 · Cloud Portal
Monitor enrolled endpoints, request inventory scans, search fleet software, and manage baselines.
Open chapter →Chapter 16 · VisionX Visual DLP
Plan, configure, validate, and operate VisionX visual-channel protection on managed Windows endpoints.
Open chapter →Chapter 17 · VisionX Visual DLP
Choose and validate Always on, Standby, or On-demand VisionX activation.
Open chapter →Chapter 18 · VisionX Visual DLP
Triage VisionX events (including strict no-camera locks), handle evidence responsibly, and support a locked user.
Open chapter →Chapter 19 · VisionX Visual DLP
Tune lock response, confidence, persistence, cooldown, evidence, and locking through a controlled pilot.
Open chapter →Chapter 20 · GenGuard Browser DLP
Plan, pilot, deploy, and validate the managed GenGuard browser extension.
Open chapter →Chapter 21 · GenGuard Browser DLP
Practical GPO/Intune checklist to force-install GenGuard and push tenant configuration.
Open chapter →Chapter 22 · GenGuard Browser DLP
Build and validate GenGuard policy with templates, DLP keywords, domain rules, and web categories.
Open chapter →Chapter 23 · GenGuard Browser DLP
Monitor browser-extension health, triage DLP events, and investigate reporting gaps.
Open chapter →Chapter 24 · Vault & PAM
Configure, validate, and operate password rotation for managed Windows local accounts.
Open chapter →Chapter 25 · Vault & PAM
Safely force-rotate a local account and manage the Windows built-in administrator identity.
Open chapter →Chapter 26 · Vault & PAM
Reveal local-account credentials safely and maintain least-privilege Vault roles.
Open chapter →Chapter 27 · Vault & PAM
Configure Personal Vault restrictions, manage user-owned encrypted files, and create limited sharing links.
Open chapter →Chapter 28 · Vault & PAM
Publish an employee File Vault that is separate from the Cloud Portal, with per-person encrypted files and optional password-protected share links.
Open chapter →Chapter 29 · HostGuard IPS
Deploy and operate endpoint failed-logon detection with report-only and blocking modes.
Open chapter →Chapter 30 · HostGuard IPS
Tune failed-logon thresholds and move safely from report-only observation to firewall blocking.
Open chapter →Chapter 31 · Trustity Axiom
Axiom is an on-premises security platform for organizations that want enforcement and operational evidence in the SMB and DNS paths without installing an agent
Open chapter →Chapter 32 · Trustity Axiom
A production Axiom deployment uses three separate Ubuntu or Debian servers: 1. **Management Server** - Web UI, node registry, policy control plane, reputation d
Open chapter →Chapter 33 · Trustity Axiom
The Management Server is the only role administrators need to browse directly. It stores policy and reputation data, registers data-plane nodes, receives teleme
Open chapter →Chapter 34 · Trustity Axiom
The SMB node needs a stable client-facing IP and reachability to the real file server. Clients will connect to the Axiom IP, not the file-server IP. Plan firewa
Open chapter →Chapter 35 · Trustity Axiom
Axiom can sit between endpoints and upstream resolvers, or between an internal DNS/DC server and its upstream resolvers. In an Active Directory environment, end
Open chapter →Chapter 36 · Trustity Axiom
An Axiom cluster is a Management-controlled group of nodes with the same data-plane role. An SMB cluster contains one source SMB node and one or more SMB replic
Open chapter →Chapter 37 · Trustity Axiom
Axiom license activation is designed for restricted networks. The Management Server creates a machine-bound activation request and verifies the signed response
Open chapter →Chapter 38 · Cloud Portal
Invite local portal users, assign Owner/Admin/Analyst/Viewer roles, complete set-password, validate access, and remove access safely.
Open chapter →Chapter 39 · Cloud Portal
Understand SSO authentication and SCIM lifecycle provisioning, configure the current preview safely, and explain the customer value.
Open chapter →Chapter 40 · Cloud Portal
Issue scoped Cloud Portal API keys for automations without using the organization license key.
Open chapter →Chapter 41 · Cloud Portal
Configure idle session guidance and revoke portal sessions for privileged operators.
Open chapter →Chapter 42 · Cloud Portal
Configure email and webhook routing for critical portal alerts without treating retries as guaranteed delivery.
Open chapter →Chapter 43 · Cloud Portal
Review policy history snapshots and roll back entitled module policies when a change needs to be reversed.
Open chapter →Chapter 44 · Cloud Portal
Set evidence and audit retention preferences, preview purge impact, and export audit JSONL with SHA-256 integrity headers.
Open chapter →Chapter 45 · Cloud Portal
Use Security Assurance to track MFA, SSO staging, alerts, and audit export readiness - not SOC 2 certification.
Open chapter →Chapter 46 · Cloud Portal
Search, validate, export, and retain organization-scoped administrative audit history.
Open chapter →Chapter 47 · Cloud Portal
Search and export cross-module operational activity for investigations and review.
Open chapter →Chapter 48 · Cloud Portal
Forward selected portal audit events to syslog or an HTTPS webhook and validate delivery.
Open chapter →Chapter 49 · Cloud Portal
Review portal identity details, enroll MFA, manage factors, and sign out securely.
Open chapter →Chapter 50 · Cloud Portal
Open, track, and securely communicate through Cloud Portal support tickets.
Open chapter →Chapter 51 · Getting Started
Diagnose enrollment, service, network, heartbeat, policy, and session issues without exposing credentials or destroying agent state.
Open chapter →