Meta pixel

Select the plan based on your needs

IT
Security

Free

Unlimited hosts

$0

Get started free

Includes:

Opt-in macOS MDM

REST API and webhooks

YAML configuration

Enforce device configurations

Run MDM commands via CLI

End user transparency

Community support (MacAdmins Slack)

Self-hosted

Manage osquery at enterprise scale

Monitor query performance

REST API and webhooks

YAML configuration

Detect vulnerabilities

Software inventory

Device health report

Ship logs to Splunk, Snowflake, and more

Self-hosted

Premium

Unlimited hosts

Starting at

$7.00

/ host
/ month
Get started

For organizations with large deployments, contact sales.

All of Free plus:

Zero-touch MDM for macOS

Windows MDM with Autopilot*

Safely execute remote scripts*

Programmable remediations*

Disk encryption key escrow

macOS update via Nudge

Remote lock and wipe

24x7 support

Self-managed or private cloud hosted

Dedicated Slack channel

End user sign-in with Okta, AD, or any IDP

Integrate with Munki, Chef, and Puppet

Enterprise-ready MDM migration

GitOps-ready

CIS for macOS and Windows

Custom vulnerability reporting

Phased rollouts (canaries)

Single-Sign On (SSO)

Version history for queries and config

Granular role-based access

Target and configure specific device groups

Programable audit log

Vulnerability scores (EPSS and CVSS)

CISA known exploited vulnerabilities

24x7 support

Self-managed or private cloud hosted

Sync user roles from Okta, AD, or any IDP

Just-in-time (JIT) provisioning

Aggregate insights for groups of devices

Agent auto-updates

Manage osquery extensions remotely

Compare plans

Device management

Free Premium
User-initiated enrollment of macOS computers checkmark checkmark
Remotely enforce macOS settings checkmark checkmark
Low-level macOS MDM commands (e.g. remote restart) checkmark checkmark
Native macOS update reminders checkmark checkmark
Zero-touch setup for macOS computers checkmark
Safely execute custom scripts checkmark
End-user macOS update reminders (via Nudge) checkmark
Encrypt macOS hard disks with FileVault checkmark
Manage queued MDM commands on macOS* checkmark
Remotely lock and wipe macOS computers checkmark
Update apps on macOS computers* checkmark
Puppet integration checkmark
Interactive MDM migration checkmark

Support

Public issue tracker (GitHub) checkmark checkmark
Community Slack channel checkmark checkmark
Unlimited email support (confidential) checkmark
Phone and video call support checkmark

Inventory management

Secure REST API checkmark checkmark
Command line tool (CLI) checkmark checkmark
Realtime device inventory dashboard checkmark checkmark
Browse installed software packages checkmark checkmark
Search devices by IP, serial, hostname, UUID checkmark checkmark
Target and configure specific groups of devices checkmark
Aggregate insights for groups of devices checkmark

Collaboration

Shareable device health reports checkmark checkmark
Versionable queries and config (GitOps) checkmark checkmark
Human-to-device mapping checkmark checkmark
Scope transparency checkmark checkmark

Security and compliance

Single sign on (SSO, SAML) checkmark checkmark
Report on disk encryption status (FileVault) checkmark checkmark
Audit queries and user activities checkmark checkmark
Grant API-only access checkmark checkmark
Role-based access control checkmark checkmark
Ship logs to Splunk, Snowflake, and more checkmark checkmark
Programmable audit log checkmark
Just-in-time (JIT) provisioning checkmark
Automated user role sync via Okta, AD, or any IDP checkmark
Vanta integration checkmark
Trigger a workflow based on a failing policy* checkmark
Granular role-based access control checkmark

Monitoring

Schedule and automate custom queries checkmark checkmark
Detect vulnerable software checkmark checkmark
Query performance monitoring checkmark checkmark
Standard query and policy library checkmark checkmark
Policy and vulnerability automations (webhook, Zendesk, JIRA, ServiceNow*) checkmark checkmark
Detect and surface issues with devices (policies) checkmark checkmark
Mark policies as critical checkmark
Vulnerability scores (EPSS and CVSS) checkmark
CISA known exploited vulnerabilities checkmark
End-user self-service checkmark

Data outputs

Flexible log destinations (AWS Kinesis, Lambda, GCP, Kafka) checkmark checkmark
File carving (AWS S3) checkmark checkmark

Deployment

Self-hosted checkmark checkmark
Deployment tools (Helm, Terraform) checkmark checkmark
Configure osquery startup flags remotely checkmark checkmark
Auto-update osquery agents checkmark checkmark
Self-managed auto-update registry checkmark
Manage osquery extensions remotely checkmark
Managed Cloud checkmark

* Coming soon

Device management

User-initiated enrollment of macOS computers
Free checkmark
Premium checkmark
Remotely enforce macOS settings
Free checkmark
Premium checkmark
Low-level macOS MDM commands (e.g. remote restart)
Free checkmark
Premium checkmark
Native macOS update reminders
Free checkmark
Premium checkmark
Zero-touch setup for macOS computers
Free
Premium checkmark
Safely execute custom scripts
Free
Premium checkmark
End-user macOS update reminders (via Nudge)
Free
Premium checkmark
Encrypt macOS hard disks with FileVault
Free
Premium checkmark
Manage queued MDM commands on macOS*
Free
Premium checkmark
Remotely lock and wipe macOS computers
Free
Premium checkmark
Update apps on macOS computers*
Free
Premium checkmark
Puppet integration
Free
Premium checkmark
Interactive MDM migration
Free
Premium checkmark

Support

Public issue tracker (GitHub)
Free checkmark
Premium checkmark
Community Slack channel
Free checkmark
Premium checkmark
Unlimited email support (confidential)
Free
Premium checkmark
Phone and video call support
Free
Premium checkmark

Inventory management

Secure REST API
Free checkmark
Premium checkmark
Command line tool (CLI)
Free checkmark
Premium checkmark
Realtime device inventory dashboard
Free checkmark
Premium checkmark
Browse installed software packages
Free checkmark
Premium checkmark
Search devices by IP, serial, hostname, UUID
Free checkmark
Premium checkmark
Target and configure specific groups of devices
Free
Premium checkmark
Aggregate insights for groups of devices
Free
Premium checkmark

Collaboration

Shareable device health reports
Free checkmark
Premium checkmark
Versionable queries and config (GitOps)
Free checkmark
Premium checkmark
Human-to-device mapping
Free checkmark
Premium checkmark
Scope transparency
Free checkmark
Premium checkmark

Security and compliance

Single sign on (SSO, SAML)
Free checkmark
Premium checkmark
Report on disk encryption status (FileVault)
Free checkmark
Premium checkmark
Audit queries and user activities
Free checkmark
Premium checkmark
Grant API-only access
Free checkmark
Premium checkmark
Role-based access control
Free checkmark
Premium checkmark
Ship logs to Splunk, Snowflake, and more
Free checkmark
Premium checkmark
Programmable audit log
Free
Premium checkmark
Just-in-time (JIT) provisioning
Free
Premium checkmark
Automated user role sync via Okta, AD, or any IDP
Free
Premium checkmark
Vanta integration
Free
Premium checkmark
Trigger a workflow based on a failing policy*
Free
Premium checkmark
Granular role-based access control
Free
Premium checkmark

Monitoring

Schedule and automate custom queries
Free checkmark
Premium checkmark
Detect vulnerable software
Free checkmark
Premium checkmark
Query performance monitoring
Free checkmark
Premium checkmark
Standard query and policy library
Free checkmark
Premium checkmark
Policy and vulnerability automations (webhook, Zendesk, JIRA, ServiceNow*)
Free checkmark
Premium checkmark
Detect and surface issues with devices (policies)
Free checkmark
Premium checkmark
Mark policies as critical
Free
Premium checkmark
Vulnerability scores (EPSS and CVSS)
Free
Premium checkmark
CISA known exploited vulnerabilities
Free
Premium checkmark
End-user self-service
Free
Premium checkmark

Data outputs

Flexible log destinations (AWS Kinesis, Lambda, GCP, Kafka)
Free checkmark
Premium checkmark
File carving (AWS S3)
Free checkmark
Premium checkmark

Deployment

Self-hosted
Free checkmark
Premium checkmark
Deployment tools (Helm, Terraform)
Free checkmark
Premium checkmark
Configure osquery startup flags remotely
Free checkmark
Premium checkmark
Auto-update osquery agents
Free checkmark
Premium checkmark
Self-managed auto-update registry
Free
Premium checkmark
Manage osquery extensions remotely
Free
Premium checkmark
Managed Cloud
Free
Premium checkmark

* Coming soon

Compare plans

Security and compliance

Free Premium
Single sign on (SSO, SAML) checkmark checkmark
Report on disk encryption status (FileVault) checkmark checkmark
Audit queries and user activities checkmark checkmark
Grant API-only access checkmark checkmark
Role-based access control checkmark checkmark
Ship logs to Splunk, Snowflake, and more checkmark checkmark
Programmable audit log checkmark
Just-in-time (JIT) provisioning checkmark
Automated user role sync via Okta, AD, or any IDP checkmark
Vanta integration checkmark
Trigger a workflow based on a failing policy* checkmark
Granular role-based access control checkmark

Monitoring

Schedule and automate custom queries checkmark checkmark
Detect vulnerable software checkmark checkmark
Query performance monitoring checkmark checkmark
Standard query and policy library checkmark checkmark
Policy and vulnerability automations (webhook, Zendesk, JIRA, ServiceNow*) checkmark checkmark
Detect and surface issues with devices (policies) checkmark checkmark
Mark policies as critical checkmark
Vulnerability scores (EPSS and CVSS) checkmark
CISA known exploited vulnerabilities checkmark
End-user self-service checkmark

Inventory management

Secure REST API checkmark checkmark
Command line tool (CLI) checkmark checkmark
Realtime device inventory dashboard checkmark checkmark
Browse installed software packages checkmark checkmark
Search devices by IP, serial, hostname, UUID checkmark checkmark
Target and configure specific groups of devices checkmark
Aggregate insights for groups of devices checkmark

Collaboration

Shareable device health reports checkmark checkmark
Versionable queries and config (GitOps) checkmark checkmark
Human-to-device mapping checkmark checkmark
Scope transparency checkmark checkmark

Support

Public issue tracker (GitHub) checkmark checkmark
Community Slack channel checkmark checkmark
Unlimited email support (confidential) checkmark
Phone and video call support checkmark

Data outputs

Flexible log destinations (AWS Kinesis, Lambda, GCP, Kafka) checkmark checkmark
File carving (AWS S3) checkmark checkmark

Deployment

Self-hosted checkmark checkmark
Deployment tools (Helm, Terraform) checkmark checkmark
Configure osquery startup flags remotely checkmark checkmark
Auto-update osquery agents checkmark checkmark
Self-managed auto-update registry checkmark
Manage osquery extensions remotely checkmark
Managed Cloud checkmark

* Coming soon

Security and compliance

Single sign on (SSO, SAML)
Free checkmark
Premium checkmark
Report on disk encryption status (FileVault)
Free checkmark
Premium checkmark
Audit queries and user activities
Free checkmark
Premium checkmark
Grant API-only access
Free checkmark
Premium checkmark
Role-based access control
Free checkmark
Premium checkmark
Ship logs to Splunk, Snowflake, and more
Free checkmark
Premium checkmark
Programmable audit log
Free
Premium checkmark
Just-in-time (JIT) provisioning
Free
Premium checkmark
Automated user role sync via Okta, AD, or any IDP
Free
Premium checkmark
Vanta integration
Free
Premium checkmark
Trigger a workflow based on a failing policy*
Free
Premium checkmark
Granular role-based access control
Free
Premium checkmark

Monitoring

Schedule and automate custom queries
Free checkmark
Premium checkmark
Detect vulnerable software
Free checkmark
Premium checkmark
Query performance monitoring
Free checkmark
Premium checkmark
Standard query and policy library
Free checkmark
Premium checkmark
Policy and vulnerability automations (webhook, Zendesk, JIRA, ServiceNow*)
Free checkmark
Premium checkmark
Detect and surface issues with devices (policies)
Free checkmark
Premium checkmark
Mark policies as critical
Free
Premium checkmark
Vulnerability scores (EPSS and CVSS)
Free
Premium checkmark
CISA known exploited vulnerabilities
Free
Premium checkmark
End-user self-service
Free
Premium checkmark

Inventory management

Secure REST API
Free checkmark
Premium checkmark
Command line tool (CLI)
Free checkmark
Premium checkmark
Realtime device inventory dashboard
Free checkmark
Premium checkmark
Browse installed software packages
Free checkmark
Premium checkmark
Search devices by IP, serial, hostname, UUID
Free checkmark
Premium checkmark
Target and configure specific groups of devices
Free
Premium checkmark
Aggregate insights for groups of devices
Free
Premium checkmark

Collaboration

Shareable device health reports
Free checkmark
Premium checkmark
Versionable queries and config (GitOps)
Free checkmark
Premium checkmark
Human-to-device mapping
Free checkmark
Premium checkmark
Scope transparency
Free checkmark
Premium checkmark

Support

Public issue tracker (GitHub)
Free checkmark
Premium checkmark
Community Slack channel
Free checkmark
Premium checkmark
Unlimited email support (confidential)
Free
Premium checkmark
Phone and video call support
Free
Premium checkmark

Data outputs

Flexible log destinations (AWS Kinesis, Lambda, GCP, Kafka)
Free checkmark
Premium checkmark
File carving (AWS S3)
Free checkmark
Premium checkmark

Deployment

Self-hosted
Free checkmark
Premium checkmark
Deployment tools (Helm, Terraform)
Free checkmark
Premium checkmark
Configure osquery startup flags remotely
Free checkmark
Premium checkmark
Auto-update osquery agents
Free checkmark
Premium checkmark
Self-managed auto-update registry
Free
Premium checkmark
Manage osquery extensions remotely
Free
Premium checkmark
Managed Cloud
Free
Premium checkmark

* Coming soon

FAQ

Is Fleet MIT licensed?

We have different licenses for portions of our software which are noted in the LICENSE file in our docs. The majority of Fleet is MIT licensed. Paid features require a license key.

What is your commitment to open source stewardship?

  1. When a feature is free and open source we won't move that feature to a paid tier. Features might be removed from the open source codebase in other cases, for example when combining features from multiple tiers into one new feature.
  2. The majority of new capabilities added to Fleet will benefit all users, not just customers.
  3. We won't introduce features into the open source codebase with a fixed delay; if a feature is planned to land in both it will be released simultaneously in both.
  4. We will always release and open source all tests that we have for any open source feature.
  5. The free version of Fleet is enterprise ready.
  6. The open source codebase will not contain any artificial limits on the number of hosts, users, size, or performance.
  7. The majority of new features contributed by Fleet Device Management Inc will be open source.
  8. The product will be available for download without leaving an email address or logging in.
  9. We will always allow you to benchmark the performance of Fleet. (Fleet also load tests the platform before every release, with increasingly ambitious targets. The scale of realtime reporting supported by Fleet has increased 5,000% since 2019. Today, Fleet deployments supports 500,000 devices, and counting. The company is committed to driving this number to 1M+, and beyond.)

How do I contact Fleet for support?

Find out how to contact support in our handbook.

What if we choose not to renew?

If you opt not to renew Fleet Premium, you can continue using Fleet Community Edition (same code base, just unconfigure the license key.)

Can we buy a licence to access premium features with reduced support for a reduced cost?

We aren’t able to sell licenses and support separately.

Do you offer pricing for ephemeral hosts which may scale up or down?

For now, the number of hosts is the maximum cap of distinct agents enrolled at any given time.

When run locally, what resources does the Fleet app typically consume on an individual instance, and when run in HA, at high volume? And how is latency on an individual instance vs clustered deployment?

Like any modern application, Fleet scales horizontally. The biggest potential bottleneck for Fleet is the number of hosts being monitored, so that's where we've devoted the most attention when testing. The largest number of hosts we've had a customer ask about was 350,000, for all of the production servers and employee laptops of a publicly traded company.

Where's the data stored?

Since Fleet is self-managed, some metadata is stored wherever it is deployed (e.g. Amazon, Azure, Google, your own data center, hybrid cloud, anywhere). That's done using a MySQL database, but the bulk of the data is not stored there — instead, it flows directly into a tool like Splunk or ElasticSearch. You can send that information to any of Fleet's supported log destinations.

Can I fork Fleet's source code and build upon it myself to create my own features?

Anyone is free to fork the project. We are always interested to hear feedback, and we are happy to take pull requests and ideas upstream any time we can.

Can I buy support or services separate from Fleet Premium?

The only way we are able to partner as a business to provide support and build new open source and paid features is through customers purchasing Fleet Premium.