Windows updates itself; your browsers, readers and runtimes may not. The gaps auditors find are in the apps — Heimdal Patch & Asset Management installs OS updates and patches for 350+ catalogue applications on Windows, macOS and Ubuntu, lists every device’s missing fixes by CVE and severity, and keeps an asset inventory from the same agent.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Heimdal Patch & Asset Management — OS and third-party patching with an asset inventory, with Infinity Management for custom software as a separately priced line. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
An agent finds the missing updates on each device and installs them, while an inventory shows what software runs where.
What consolidation actually replaces, dimension by dimension.
| Dimension | Vendor updaters and a quarterly scan | Heimdal Patch & Asset Management |
|---|---|---|
| Third-party apps | Each vendor’s own updater, if it runs at all | One catalogue of 350+ titles, repackaged by Heimdal |
| Finding the gaps | A quarterly scan and a spreadsheet | Missing updates per device, with CVE and severity |
| In-house software | Login scripts and a shared folder | Infinity Management pushes EXE, MSI, ZIP or MSP |
| Linux servers | Patched by hand over SSH | Catalogue updates on Ubuntu, without an agent screen |
| Rolling out safely | Everything at once on Patch Tuesday | A pilot ring first (release candidate, June 2026) |
| What it is NOT | — | An RMM, a PSA, or a published price |
The cheapest test is the free trial: put the agent on 25 mixed machines and count which of your everyday apps it patches.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
One agent on each Windows, macOS or Ubuntu machine reports installed software and missing updates, then installs what policy approves; other Heimdal modules use the same agent.
Heimdal says it tests and repackages third-party updates on its own patching server before release, so the agent can install them silently rather than run each vendor’s setup.
Policies in the cloud dashboard choose which OS and application updates go to which groups and when, with CVE and severity per device; rings came in the 5.5.0 release candidate.
A separately priced module that sends your own EXE, MSI, ZIP or MSP packages out with silent install switches; it runs on Windows and Ubuntu endpoints, not on macOS.
One agent per device, updates repackaged by Heimdal — OS and catalogue patches pushed by cloud policy, tracked by CVE.
Heimdal Patch & Asset Management closes OS and third-party update gaps from one cloud dashboard and shows which device still lacks which fix.
Operating-system updates go out from the same policy set to Windows 10/11, Windows Server 2016–2025, macOS 10.15+ and Ubuntu 16+.
Heimdal lists over 350 supported applications, each repackaged on its own server so the agent installs it without prompting users.
Heimdal documents working alongside WSUS, so Windows updates can move across in stages instead of the server being retired on day one.
Every endpoint shows its missing updates with CVE and severity, and a deployment can target a CVE rather than a product name.
Asset inventory comes from the agent that does the patching, so the record of what is installed where refreshes itself, not by hand.
Patching in rings, added as a release candidate in dashboard 5.5.0 in June 2026, lets a test group take updates ahead of everyone.
Infinity Management deploys in-house EXE, MSI, ZIP or MSP packages to Windows and Ubuntu; it is a line item of its own.
Heimdal offers a Priority Server Updates option for sites on thin links; check in the trial how it shapes traffic at your branches.
Heimdal lists ConnectWise RMM, Autotask PSA and HaloPSA among its integrations, and a REST API feeds data to your own tools.
The current product demo, Heimdal’s overview of patching and asset inventory, and a longer best-practice session on patching. All from Heimdal’s official channel.
The current dashboard walk-through: catalogue policies, OS updates and the per-device view of what is missing.
Heimdal’s own summary of the module, from third-party patching to the asset inventory it keeps.
A longer session on patching practice in general, useful for setting rings and deadlines before a rollout.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
An up-to-date operating system still leaves every installed application to patch. Heimdal covers Windows, macOS and Ubuntu plus a 350+ app catalogue it repackages itself, and lets you deploy by CVE, so audits ask which device lacks which fix.
Windows desktops and servers, macOS from 10.15 and Ubuntu from 16 all take third-party patches, though Linux has no agent interface. Infinity Management, a further line, sends in-house EXE, MSI, ZIP or MSP packages to Windows and Ubuntu.
Heimdal’s DNS filtering, antivirus, ransomware and privilege modules run on the same agent, each licensed apart. A team already running one adds patching with a licence and a policy, and missing updates sit beside the security alerts.
Prices are quotes, per device per year. A switched-off device waits until it returns, and uninstall needs an MSI or quiet uninstall string. Rings are a release candidate, there is no India data region, and Heimdal sells no RMM or PSA for tickets.
Pull the twenty applications every device runs and check each against Heimdal’s 350+ catalogue before anything else.
Put the agent on 25 Windows, macOS and Ubuntu machines and record which updates land, which fail and which are absent.
Split a pilot ring from production, decide which CVE severities deploy at once, and leave WSUS running for now.
If you buy Infinity Management, wrap line-of-business installers as EXE, MSI, ZIP or MSP and test the silent install.
Export missing-patch and CVE views for the auditor, and chase devices that stay offline, since they cannot be patched.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We matched our top twenty apps against the catalogue during the trial; eighteen were there and two went to Infinity.”
“Deploying by CVE changed our audit pack. The auditor named one advisory and we showed every laptop still missing it.”
“Our Ubuntu build servers take catalogue updates with no agent screen to open, which took the team a week to trust.”
“Laptops left switched off for a fortnight stay on the missing list until they come back, so we chase those users.”
“We already ran Heimdal DNS filtering, so patching was a licence and a policy, not a fresh rollout to 900 machines.”
“No price list meant three calls before we had a budget number, and rings were still a release candidate when we signed.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the patch management market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per device per year; no public price.
The grid nobody publishes — how many operating systems and catalogue apps a product patches vs how much of the wider RMM job it also does.
Three OSes and 350+ apps; no monitoring, PSA or remote console in this module.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Action1, NinjaOne Patch Management, ManageEngine Endpoint Central, Datto RMM and N-able N-central — on coverage, price, limits, vulnerability depth, integrations, support and India.
| Dimension | Heimdal Patch & Asset Management | Action1 Patch Management | NinjaOne Patch Management | ManageEngine Endpoint Central | Datto RMM | N-able N-central |
|---|---|---|---|---|---|---|
| What it is | Patching plus assets | Cloud patching platform | Patching inside an RMM | UEM with patching | Kaseya’s MSP RMM | Multi-tenant MSP RMM |
| Deployment | Cloud dashboard + agent | Cloud, no WSUS or VPN | SaaS only | On-prem or cloud | AWS cloud only | Self-host or hosted |
| OS and app coverage | 3 OSes, 350+ apps | 200+ Windows apps | 3 OSes, deep catalogue | 850+ apps, mobile too | Windows-native, ASM apps | 3 OSes plus SNMP |
| Pricing model | Per device, per year | Free to 200, then quote | Per device, in platform | Per 50 endpoints a year | Quote, or Kaseya 365 | Quote only |
| Published entry price | Not published | $0 for 200 endpoints | $1.50–3.75 per device | $795 per 50, on-prem | Reported via Kaseya 365 | Reported ~$1.50–3.50 |
| Included vs add-on | Infinity is extra | Deploy, remediate in | MDM, backup, EDR extra | Editions add features | App catalogue is extra | Backup and EDR apart |
| Scale and limits | Device must be online | Offline caught on return | Up to 150,000 endpoints | Free tier caps at 25 | 50-endpoint bundle floor | Weeks to stand up |
| Vulnerability depth | CVE and severity view | Remediation by CVE | Rings, rollback, reports | Security edition adds VM | Ransomware detection | Per-client patch policy |
| Integrations | PSA, RMM, firewall, API | No PSA of its own | PSA, EDR and Okta links | ManageEngine family | Autotask, IT Glue | 75+ integrations |
| Governance and SSO | SOC 2 Type II, ISAE 3000 | SOC 2 Type II, ISO 27001 | SOC 2, ISO, FedRAMP | Data under your control | KaseyaOne SSO | Per-client RBAC |
| India storage region | EU, US or UK; not India | India committed, 2026 | None listed in India | Indian DCs or on-prem | Sydney is the nearest | Self-host for India |
| Support | Mumbai office, trial | Community, then a fee | No-fee support, training | Vendor in India | Phone, around the clock | 24/7 and Bengaluru |
| Lock-in and exit | Shared Heimdal agent | Low cost to walk away | Cancel on 60 days | Your server, your data | Tied to Kaseya bundle | Policies take rebuilding |
| Best fit | Security-led patching | Small or patch-first | Broad RMM buyers | On-prem or India-hosted | Kaseya-stack MSPs | MSPs needing separation |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Heimdal Patch & Asset Management is one of 24 RMM & patch products TechBag carries. The RMM & Patch guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints you patch; IT staff-hour cost). Estimates model the staff time spent chasing OS and third-party updates by hand, packaging installers and compiling patch reports, at an assumed 1.5 hours per endpoint a year, with 70% of it saved by catalogue patching and CVE views. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Heimdal publishes no prices: its pricing calculator lists Patch & Asset Management as a separate line item charged per device per year and returns a quote, not a figure. Infinity Management, for deploying your own software, is a further per-device line, and every other Heimdal module is priced on its own. A free trial comes first. TechBag counts your devices and checks the catalogue first, then quotes in INR with GST.
Best for OS and catalogue patching
Best for a broader rollout
Best for in-house installers
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are your top twenty applications among Heimdal’s 350+ supported titles, on every operating system you run?
Is every device Windows 10/11, Server 2016–2025, macOS 10.15+ or Ubuntu 16+? Other Linux distributions need checking.
Do you need Infinity Management for in-house installers, and are they EXE, MSI, ZIP or MSP on Windows or Ubuntu?
How many laptops sit switched off for weeks? Heimdal cannot patch a device until it is back online.
Do you need staged rollout today? Rings arrived as a release candidate in dashboard 5.5.0 in June 2026.
Will you remove software centrally? Uninstall works only for MSI apps or those with a quiet uninstall string.
Can tenant data live in Europe, the US or the UK? Heimdal has no India region, so get your choice into the contract.
Does the quote list devices, Patch & Asset and any Infinity line separately? Ask for INR with GST and the term.
Check your top twenty applications against the catalogue first, or let a TechBag advisor run the trial on a mixed pilot group and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.