Hamburger menu
TechBag
Search icon
Enterprise
Small Businesses
Industries
Blog
About Us
Shopping Bag
Get Quote
Category: Email Securityby FortinetTechBag Intel Page

Fortinet FortiClient

Secure the front door. Email is where most attacks arrive — Fortinet FortiClient is the unified endpoint agent — Universal ZTNA for least-privilege, posture-verified access (consistent on-prem and cloud), plus protection, natively integrated with the Security Fabric.

Endpoints need secure, verified access anywhereUniversal ZTNA replaces the broad VPNAccess by device posture — consistent on-prem & cloud

Buy through TechBag

Same software. Better outcome — at no extra cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free, vendor-neutral, 30 minutes

How it’s rated

Full scoreboard ↓
The category
endpoint connectivity
Agent + ZTNA
The key job
least-privilege access
Universal ZTNA
The edge
posture-aware access
Fabric integration
Gartner Peer Insights
endpoint / ZTNA*
4.5 / 5

Quick answer

FortiClient is Fortinet's unified endpoint agent — the software installed on laptops, desktops and mobile devices that connects them securely to the Fortinet Security Fabric and provides the endpoint's access, protection and visibility functions. Where FortiEDR is the advanced detection-and-response engine, FortiClient is the versatile agent that delivers secure connectivity (VPN and, more importantly, Zero Trust Network Access / Universal ZTNA), endpoint protection (anti-malware, web filtering, application firewall), and Security Fabric integration (device posture checking, telemetry, and the endpoint's link into central management). Its most strategically important role today is Universal ZTNA: FortiClient enables least-privilege, per-session access to applications — verified against device posture and identity, and enforced consistently whether the user connects through an on-prem FortiGate or cloud FortiSASE — replacing the broad, insecure access of traditional VPNs. Because it's part of the Fabric, FortiClient continuously reports device posture and telemetry, so the FortiGate and FortiSASE can make access decisions based on the endpoint's actual security state, and the endpoint is part of the correlated, Fabric-wide security picture. FortiClient is licensed via FortiClient EMS (Endpoint Management Server) for centralised deployment and management, with a free tier for small numbers of users. Fortinet serves ~70% of the Fortune 100. TechBag scopes, PoCs and quotes it in INR/GST.

Part 01 · Orient

The Fortinet Security Fabric family

This page covers FortiClient — the endpoint agent & ZTNA. The rest of the Security Fabric:

Quick facts

30-second orientation
Product
FortiClient — unified endpoint agent
Vendor
Fortinet (founded 2000 · Sunnyvale · Ken Xie)
The category
Endpoint Agent & Zero Trust Access (ZTNA)
The role
Secure connectivity + protection + Fabric integration
The key job
Universal ZTNA — least-privilege app access
vs FortiEDR
FortiClient is the agent; FortiEDR is the detection engine
Also
VPN, anti-malware, web filter, device posture
Management
FortiClient EMS (centralised); free tier available
Part of
Fortinet Security Fabric
In India via
TechBag — quotes, PoCs, GST invoicing, Tier-1 support
Part 02 · Learn

Understand email security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is FortiClient?

Fortinet's unified endpoint agent — secure access (Universal ZTNA + VPN), protection, and Fabric integration.

The agent; FortiEDR is the detection engine.

Unprotected inbox vs AI email security — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionUnprotected / signature emailFortiClient (Fortinet)
Remote accessWhole-network VPNLeast-privilege ZTNA
Access decisionCredentials onlyDevice posture + identity
On-prem vs remoteDifferent toolsUniversal ZTNA, consistent
A risky deviceGets full accessBlocked / limited by posture
Endpoint agentsSeveral separateOne unified FortiClient
Endpoint visibilitySiloedFabric telemetry
ManagementPer-deviceCentral (EMS)
The estateEndpoint siloSecurity Fabric

Endpoints need secure, verified access from anywhere — and VPNs grant too much. Universal ZTNA + device posture, consistent on-prem and cloud. Native to the Fabric.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The access

Universal ZTNA

Least-privilege access

Enables Zero Trust Network Access — per-session, least-privilege access to applications, verified against device posture and identity, enforced consistently by FortiGate (on-prem) or FortiSASE (cloud).

02
The tunnel

Secure Connectivity

VPN + ZTNA

Provides both traditional VPN (SSL/IPsec) and the modern ZTNA access model — connecting endpoints securely to corporate resources wherever the user is.

03
The guard

Endpoint Protection

AV, web, firewall

Delivers anti-malware, web filtering and application-firewall protection on the endpoint — the baseline hygiene, integrated with the Fabric.

04
The reporter

Fabric Telemetry

Posture & visibility

Continuously reports device posture and telemetry to the Security Fabric — so access decisions reflect the endpoint's actual security state, and it's part of the correlated picture.

05
The console

FortiClient EMS

Central management

Managed centrally via FortiClient EMS (Endpoint Management Server) — deployment, policy, posture and visibility across the endpoint fleet, part of the Fabric.

One agent on every machine, one console over all of them — modules attach without a second operational world.

Part 03 · Evaluate

Twelve capabilities. Access, protect, prove.

FortiClient connects endpoints securely into the platform — Universal ZTNA and posture-verified access, part of the portfolio, and paired with the human firewall.

Access
ZTNA

Universal ZTNA

Least-privilege, per-session access to specific applications — verified by device posture and identity, enforced consistently on-prem (FortiGate) or cloud (FortiSASE).

Access
Consistent

Consistent Access Everywhere

The same ZTNA access model whether the user is in the office (via FortiGate) or remote (via FortiSASE) — one experience, one policy, wherever they are.

Access
VPN

VPN (SSL/IPsec)

Traditional VPN connectivity for scenarios that still need it — SSL and IPsec tunnels back to FortiGate, alongside the modern ZTNA model.

Access
Posture

Device Posture Check

Verifies the endpoint's security posture (patch level, AV status, compliance) before granting access — so a non-compliant or risky device is blocked or limited.

Protect
AV

Anti-Malware

Endpoint anti-malware protection — the baseline defence against malware, integrated with FortiGuard intelligence and the Fabric.

Protect
Web filter

Web Filtering

Endpoint web filtering — blocking malicious and inappropriate sites even when the user is off the corporate network.

Protect
App firewall

Application Firewall

Controls application traffic on the endpoint — an extra layer of control over what apps can communicate and how.

Protect
Ransomware

Ransomware Protection

Behavioural ransomware protection on the endpoint — detecting and stopping ransomware-like activity before it encrypts.

Protect
Vuln

Vulnerability Scanning

Scans the endpoint for vulnerabilities and missing patches — surfacing the exposures that need remediation before they're exploited.

Prove
Telemetry

Fabric Telemetry

Continuously reports device posture and telemetry to the Security Fabric — so the whole platform sees the endpoint's state and can act on it.

Prove
EMS

Central Management (EMS)

Managed via FortiClient EMS — centralised deployment, policy, posture and visibility across the whole endpoint fleet.

Prove
Fabric

Security Fabric

Part of the Fortinet Security Fabric — the endpoint agent that links devices into the platform for correlated, posture-aware security.

See it, don’t just read it

Watch Fortinet FortiClient in action

The overview, getting started, and protecting M365 email.

Fortinet (official)·Demo

Fortinet Universal ZTNA | Product Demo

Universal ZTNA with FortiClient.

Fortinet (official)·Demo

Using FortiClient to Protect against Ransomware

FortiClient ransomware protection.

Fortinet (official)·Demo

How to Deploy and Manage FortiClient (Endpoint)

Deploying and managing FortiClient.

Want a live, India-context walkthrough on your own fleet?

Book a guided demo →
Why FortiClient

The endpoint catches what arrives. Email stops it arriving.

Here’s what genuinely sets Fortinet FortiClient apart.

01

The endpoint's link into the Security Fabric

FortiClient is the endpoint agent that connects devices — laptops, desktops, mobiles — securely into the Fortinet Security Fabric, and understanding its role clarifies how Fortinet's endpoint story fits together. FortiClient is the versatile, unified agent that provides the endpoint's connectivity, baseline protection, and — critically — its integration with the rest of the Fabric: it continuously reports the device's posture and telemetry, so the platform knows each endpoint's actual security state, and it enforces access based on that state. It's distinct from FortiEDR (Fortinet's advanced detection-and-response engine, for deep behavioural detection and automated response): FortiClient is the broad agent for secure access and Fabric integration, while FortiEDR is the specialist detection engine, and they complement each other. FortiClient's importance has grown as work went remote and hybrid, because it's the software on the user's device that makes secure, verified access possible from anywhere — and as the enforcement point for Fortinet's Zero Trust access model. For any organisation building on Fortinet, FortiClient is the essential endpoint component that ties devices into the security platform.

02

Universal ZTNA: replacing the VPN, consistently

FortiClient's most strategically important role today is enabling Universal ZTNA — Fortinet's Zero Trust Network Access — which is a major security improvement over the traditional VPN it replaces. The problem with VPNs is that they grant a remote user broad access to the corporate network: once connected, the user (or an attacker who's compromised their device or credentials) is 'inside' and can often reach far more than they need, enabling lateral movement — exactly the over-privileged access modern attacks exploit. ZTNA takes a fundamentally more secure approach: instead of putting the user on the network, it grants access only to the specific applications they're explicitly authorised to use, verified per-session and against the device's security posture, with everything else invisible and unreachable. FortiClient is the agent that makes this work on the endpoint — establishing the ZTNA connection, providing the device posture that access decisions depend on, and enforcing least-privilege access. What makes Fortinet's approach 'Universal' ZTNA is consistency: the same ZTNA access model and policy applies whether the user connects through an on-premises FortiGate (in the office) or a cloud FortiSASE (remote) — one experience, one policy, wherever the user is. This consistency, and the shift from broad VPN access to posture-verified least-privilege ZTNA, makes FortiClient central to modernising and securing access, and it's one of the highest-impact security improvements an organisation can make.

03

Access based on device posture — not just credentials

A key security capability FortiClient provides is device posture checking — verifying the endpoint's actual security state before (and while) granting access, so access decisions reflect not just who the user is but whether their device is safe. This matters because a valid user on a compromised, non-compliant or risky device is a real threat: if a user's laptop is missing critical patches, has disabled antivirus, or shows signs of compromise, granting it full access to corporate resources is dangerous, even if the user's credentials are legitimate. FortiClient continuously assesses the device's posture — patch level, security software status, compliance with policy, indicators of compromise — and feeds this to the Security Fabric, so the FortiGate or FortiSASE enforcing access can make decisions based on it: a healthy, compliant device gets normal access; a risky or non-compliant one can be blocked, limited to remediation, or granted only restricted access until it's fixed. This posture-aware, zero-trust approach — 'trust the device only if it's verifiably healthy, continuously' — is far more secure than the traditional model of granting access based on credentials alone and assuming the device is fine. It closes the gap where a legitimate user's compromised or non-compliant device becomes an attacker's route in, and it's a core reason FortiClient (as the posture-reporting agent) is essential to Fortinet's zero-trust security model.

04

Broad protection and connectivity in one agent

FortiClient is a versatile, unified agent that delivers a broad set of endpoint functions in one piece of software, which simplifies the endpoint stack. Beyond its ZTNA and connectivity role, FortiClient provides endpoint protection functions — anti-malware, web filtering (blocking malicious sites even off the corporate network), an application firewall, behavioural ransomware protection, and vulnerability scanning (surfacing missing patches and exposures) — the baseline endpoint hygiene and defence. And it provides secure connectivity in multiple forms: modern ZTNA for least-privilege app access, plus traditional VPN (SSL and IPsec) for scenarios that still require it. Having all of this — secure access (ZTNA and VPN), baseline protection (AV, web filter, app firewall, ransomware, vulnerability scanning), and Fabric integration (posture and telemetry) — in one unified agent means fewer separate agents on the endpoint, one thing to deploy and manage (via FortiClient EMS), and a coherent, integrated endpoint experience. For organisations building on Fortinet, this consolidation of endpoint connectivity and protection functions into one Fabric-integrated agent reduces complexity and provides a consistent foundation. And with a free tier available for small numbers of users and centralised management via FortiClient EMS for larger deployments, it scales from small to large. TechBag scopes the right FortiClient/EMS configuration and licensing for your endpoint fleet.

05

Central management and Fabric consolidation

FortiClient is managed centrally through FortiClient EMS (Endpoint Management Server), which provides centralised deployment, policy configuration, posture management and visibility across the entire endpoint fleet — so an organisation can roll out, configure, monitor and update FortiClient on all its devices from one place, rather than managing endpoints individually. This central management is essential at any scale beyond a handful of devices, and EMS is itself part of the Fortinet Security Fabric — so endpoint management is integrated with the rest of your Fortinet security rather than a separate silo. This Fabric integration is the broader strategic point: because FortiClient (and EMS) is part of the Security Fabric, the endpoint isn't isolated — it shares posture and telemetry with the FortiGate (network), FortiSASE (access), FortiEDR (detection) and the rest, so the whole platform has a correlated, up-to-date view of every endpoint's state and can make coordinated decisions. An endpoint FortiClient flags as compromised or non-compliant can trigger the FortiGate to restrict its network access; a threat seen elsewhere in the Fabric can inform endpoint policy. For Fortinet-centric organisations, having the endpoint agent be a native, integrated part of the security platform — rather than a disconnected endpoint tool from a different vendor — provides consistency, correlation and consolidation that a standalone agent can't match. TechBag scopes how FortiClient and EMS fit your Fortinet estate and endpoint strategy.

06

The honest scope

FortiClient is a versatile, valuable unified endpoint agent whose real strengths are Universal ZTNA (consistent, posture-verified least-privilege access replacing VPNs), broad connectivity-and-protection in one agent, and native Security Fabric integration — especially compelling for Fortinet-centric organisations. The honest framing: FortiClient's role is primarily the agent, secure access and Fabric integration; for the deepest endpoint detection and response, its companion FortiEDR (a separate page in this suite) is the specialist engine, and for the very deepest standalone EDR the pure-play leaders (CrowdStrike, SentinelOne — hubs live) lead. For ZTNA specifically, dedicated ZTNA/SSE vendors (Zscaler, etc.) and other approaches compete. FortiClient's edge is being the consistent, Fabric-integrated endpoint agent and Universal ZTNA enforcement point across on-prem and cloud, at Fortinet's value. TechBag scopes FortiClient (with EMS, and alongside FortiEDR/FortiSASE) for your endpoint access and protection needs, honestly.

The top vector
Where most attacks start
AI detection
Phishing, BEC, impersonation
Universal ZTNA
On-prem + cloud, Fabric-native
Proof, not promises

The numbers behind the platform

0 agent
connectivity + protection + Fabric integration
Unified
0 Universal ZTNA
least-privilege access, on-prem AND cloud
The key job
0 posture check
access based on device state, not just creds
Zero trust
0 whole-network VPN
ZTNA replaces broad access
The security win
0 EMS console
central management across the fleet
Managed at scale
0%
of the Fortune 100 are Fortinet customers
Company reporting

What your endpoint-access journey looks like

Day 0Free

Endpoint-access scoping

Your endpoints and users (remote/hybrid), your VPN pain, your device-posture and protection needs, your Fortinet estate. TechBag scopes it free.

Week 1–2Deploy

Deploy the agent

FortiClient deployed via EMS; Universal ZTNA configured (enforced by FortiGate/FortiSASE); device posture and baseline protection on.

Week 2+Deploy

ZTNA & posture

VPN replaced with least-privilege ZTNA; access decisions based on device posture; endpoints reporting telemetry into the Fabric.

Month 2+Scale

Consistent, verified access

Consistent Universal ZTNA on-prem and cloud, posture-verified, endpoints integrated into the Fabric. TechBag models it in INR/GST.

Trusted across regulated industries in 100+ countries

Remote & hybrid workforcesFortinet-standardised estatesFinancial servicesHealthcareManufacturingRetailEducationGovernmentDistributed enterprises~70% of the Fortune 100Remote & hybrid workforcesFortinet-standardised estatesFinancial servicesHealthcareManufacturingRetailEducationGovernmentDistributed enterprises~70% of the Fortune 100
Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.5
520+ reviews*
89% would recommend
Universal ZTNA4.6
Consistent on-prem + cloud access4.6
Fabric integration & posture4.5
Depth vs standalone EDR4.1
5
58%
4
30%
3
8%
2
2%
1
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Financial Services
Universal ZTNA via FortiClient replaced our VPN with least-privilege app access — and it's the same policy whether users are in the office (FortiGate) or remote (FortiSASE). Consistent everywhere.
Network Architect
Financial Services
Healthcare
Device posture checking is the win — a non-compliant or risky laptop gets blocked or limited, even with valid credentials. Access based on device health, not just who you are.
CISO
Healthcare
Manufacturing
One agent for ZTNA, VPN, AV, web filtering and posture — fewer things on the endpoint, managed centrally from EMS. Simplified our endpoint stack.
IT Director
Manufacturing
Retail
As a Fortinet shop, FortiClient tying our endpoints into the Fabric — sharing posture with FortiGate and FortiSASE — made everything coordinated. Not a disconnected agent.
Security Lead
Retail
Education
The free tier let us trial it, then EMS licensing scaled it across the fleet with central management. Easy to adopt and grow.
IT Manager
Education
Government
A compromised endpoint FortiClient flagged triggered the FortiGate to restrict its network access automatically — Fabric-wide coordinated response from the agent's posture.
SOC Lead
Government
Energy
Ransomware protection and vulnerability scanning on the same agent added baseline defence beyond just access. Broad functions, one piece of software.
Security Engineer
Energy
Technology
For deep EDR we pair it with FortiEDR — FortiClient is the agent and access, FortiEDR the detection engine. Together they cover endpoint well.
Security Architect
Technology
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the email security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Email-Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
FortiClientThis page

Unified agent + Universal ZTNA + native Fabric integration. This page's product.

Grid 02 · The architecture

Detection × Portfolio Integration

The grid nobody publishes — how strong the email detection is vs how integrated with the wider security portfolio.

Easy but shallowDeep & runnableLegacy toolsDeep but heavy
FortiClientThis page

Consistent Universal ZTNA + broad functions + Fabric integration.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

FortiClient vs the endpoint-agent field

Standalone VPNs, ZTNA specialists and single-function agents — honest lanes; the edge is a unified agent with consistent Universal ZTNA, native to the Fabric.

DimensionFortiClientStandalone VPNZscaler ZTNAOther agentsNo agent
Role & approachUnified agent + Universal ZTNA + FabricJust a tunnelCloud ZTNA leaderVariesThe gap
Universal ZTNA (on-prem + cloud)Consistent bothNo ZTNACloud-focusedVariesNone
Device posture & protectionPosture + AV/web/ransomwareNonePostureVariesNone
Platform integrationNative Security FabricStandaloneZscaler platformVariesNone
Best fitUnified agent + consistent Universal ZTNA, native to the Fortinet FabricLegacy remote access onlyCloud-first ZTNA/SSESingle-function needsNobody with remote access
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which email-security approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose FortiClient if…

  • You want Universal ZTNA — consistent least-privilege access on-prem AND cloud
  • Device-posture-based access (not just credentials) matters
  • You want one unified agent for access + protection + Fabric integration
  • You're a Fortinet estate wanting native endpoint integration

Standalone VPN if…

  • You only need legacy remote access — but that's broad and insecure vs ZTNA

Choose Zscaler ZTNA if…

  • You want a cloud-first ZTNA/SSE-focused approach

Pair with FortiEDR if…

  • You want deep endpoint detection & response alongside the agent (this suite)

No agent if…

  • Never — an unmanaged endpoint is an unverified, unprotected risk
Do the math

What do email threats cost you?

Drag the sliders (count users; IT-hour cost as loaded incident rate). Estimates assume ~1.5 hours per user per year handling email threats that reach the inbox without AI filtering, with ~70% removed by stopping the mass at the gateway — the avoided-breach value (most attacks start here) is the larger, unpriced win. Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models actual device counts and modules.

Current annual email-threat cost
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

FortiClient prices per endpoint/year via FortiClient EMS (a free tier is available for small numbers of users); indicative per-endpoint pricing runs ~$15-40/year by tier and volume. Quote-based via the channel — TechBag scopes and quotes it in INR/GST.

FortiClient (via EMS)

Best for secure access

  • Universal ZTNA + VPN
  • Anti-malware, web filter, posture
  • Central management (EMS)

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ FortiEDR / Fabric

Best for full endpoint

  • Add FortiEDR for deep detection & response
  • Fabric-correlated posture & telemetry
  • TechBag scopes the mix

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your device counts and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Universal ZTNA

Confirm consistent ZTNA access whether users are on-prem (FortiGate) or remote (FortiSASE) — one policy everywhere.

2
Device posture

Test posture-based access — a risky/non-compliant device blocked or limited, even with valid credentials.

3
VPN + ZTNA

Confirm both modern ZTNA and (where still needed) VPN connectivity are supported.

4
Protection

Verify the baseline protection (AV, web filter, ransomware, vulnerability scan) meets your needs.

5
EMS management

Test FortiClient EMS for centralised deployment, policy and posture across the fleet.

6
Fabric integration

Confirm endpoint posture/telemetry flows into the Fabric for correlated, coordinated response.

7
EDR pairing

For deep detection & response, scope pairing FortiClient with FortiEDR (this suite).

8
Licensing

Right-size FortiClient/EMS licensing (free tier for small numbers) — TechBag scopes and quotes in INR/GST.

FAQ

Questions buyers ask

FortiClient is Fortinet's unified endpoint agent — the software installed on laptops, desktops and mobile devices that connects them securely to the Fortinet Security Fabric and provides the endpoint's access, protection and visibility functions. Where FortiEDR is the advanced detection-and-response engine, FortiClient is the versatile agent that delivers secure connectivity (VPN and, more importantly, Zero Trust Network Access / Universal ZTNA), endpoint protection (anti-malware, web filtering, application firewall, ransomware protection, vulnerability scanning), and Security Fabric integration (device posture checking, telemetry, and the endpoint's link into central management). Its most strategically important role today is Universal ZTNA: FortiClient enables least-privilege, per-session access to applications — verified against device posture and identity, and enforced consistently whether the user connects through an on-prem FortiGate or cloud FortiSASE — replacing the broad, insecure access of traditional VPNs. Because it's part of the Fabric, FortiClient continuously reports device posture and telemetry, so the FortiGate and FortiSASE can make access decisions based on the endpoint's actual security state. FortiClient is licensed via FortiClient EMS (Endpoint Management Server) for centralised deployment and management, with a free tier for small numbers of users.

Ready to modernise endpoint access?

Scope a FortiClient PoC (Universal ZTNA replacing VPN, device-posture-based access, protection), evaluate EMS central management, or let a TechBag advisor plan your endpoint access and protection.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.