Built for distributed organizations with dozens of sites and lean IT teams. Inventory, backup, compliance, and remediation in one platform.
How It Works
From inventory to verified fix. Every configuration change is tracked, validated, and confirmed.
Devices polled from PRTG, Active Directory, XProtect, or managed directly
Scheduled config capture commits to your Git repository
Governance policies check backups against your rules
Actions execute on live devices to resolve violations
Config backed up again to confirm the fix worked
Continuous loop
Capabilities
Inventory management, configuration backup, compliance validation, and optional remediation.
Poll devices from PRTG, Active Directory, Milestone XProtect, and Cradlepoint NCM. Automatic deduplication and metadata enrichment from config backups.
Every configuration backup commits to your repository with full version history. Diff visualization and change timeline for any device.
Define compliance rules that run against stored configs. Scheduled validation with severity levels. Historical compliance at any point in time.
When violations are detected, the system can suggest fix commands for your review. Approve and execute on live equipment, then recapture configs to confirm.
Credentials retrieved from Azure Key Vault only at execution time. Never stored on disk, never accessible to vendors.
On premises agents deployed to your sites connect outbound to the platform. No inbound firewall rules or VPNs required.
Governance
Describe what you want to validate in plain English. A private Azure hosted model generates deterministic validation logic. Your data stays private, and the model never learns from your configs.
When a device fails validation, you see the specific configuration lines that need attention. Shows the failing config lines directly.
Azure Hosted
RealmHelm Platform
Secrets
Azure Key Vault
Customer Owned
Git Repository
Your Sites
On-Prem Agent
Managed
Network & Server Infrastructure
Architecture
The RealmHelm platform runs in Azure—hosted by NetPrecedent, your MSP, or deployed to your own tenant. Lightweight agents at your sites connect outbound to check in with the platform and retrieve credentials from Key Vault.
Run the platform in our cloud, your MSP's environment, or your own Azure tenant.
Agents retrieve credentials from your Key Vault only at execution time. Never stored on disk.
Config backups commit to your own repository. Full history and audit trail under your control.
Supported Platforms
Backup, validate, and remediate across your entire infrastructure stack.