Self-hosted by design
The API, database, and enrollment workflows run on infrastructure you operate. That reduces dependency on a third-party MFA cloud for completing desktop access and supports stricter data residency expectations.
You still get modern mobile push. Delivery uses industry push networks where configured, while policy and secrets remain under your administration.
Verified push stops prompt bombing
Codes appear on the Windows screen only. Approving without the matching digits fails. Random taps on a compromised or distracted phone do not unlock the PC.
Combine that with fraud reporting and kill switch behavior to interrupt an active workstation session when users signal something is wrong.
USB storage block after MFA
A stolen password plus an open USB port is still a data-loss path. Fleetfold lets you deny removable USB disks from the same policy console that drives Windows MFA.
Agents enforce deny without a second USB product: registry policy, service control, and eject of mounted sticks, while keyboards and mice keep working.
Kill switch
Deny or report fraud can disconnect the initiating workstation through the agent lock command path.
Device posture
Agent signals such as Secure Boot, Defender, domain join, and provider health feed policy gates and Security Ops.
Audit and evidence
Hash-aware audit trails and evidence packs support investigation, compliance export, and leadership review.
USB storage block
One toggle blocks removable USB disks on enrolled PCs, without a separate USB DLP purchase.
Break-glass paths
Recovery and dual-control options support travel, elevated access, and operational continuity.
Dedicated console
Operators manage enrollment, policy, and response in a console separate from the public website.