14-day trial, no credit cardStart now

USB device control · At your fingertips

Every USB port,
shut by default.

Approve only the devices your team actually needs. Everything else is blocked at the kernel, and every attempt, allowed or blocked, lands in your dashboard within seconds.

No credit cardLive in <10 min$2 / endpoint / mo

Live events
Sample event log showing six recent USB device decisions
TimeDeviceVerdict
14:02:11SanDisk Ultra 64GBVID 0781 / PID 5583 · SN 4C531001…Blocked
13:47:03Kingston DataTravelerVID 0951 / PID 1666 · not on allow listBlocked
11:20:55Logitech M705 ReceiverHID · class-allowedAllowed
10:08:34Unknown mass storageVID 1f75 / PID 0621 · vendor unrecognizedBlocked
09:51:12IronKey D300S (encrypted)SN 0093F1B2 · approved 12 AugAllowed
09:14:40Generic SD card readerVID 05e3 / PID 0751 · discovery modeBlocked

4 blocked · 2 allowed · last 24h

What you get

Kernel-level enforcementMSI deploymentNIST 800-171 mappedDiscovery mode and event log

Three things we believe

01

Block by default

Allow what you intend, block everything else. No audit-only theater. Optional discovery mode watches until you turn enforcement on.

02

Nothing hidden

Pricing is published. Trials skip the credit card. Cancellation is one click. No sales calls, no quote forms, no surprises.

03

Auditor-ready

Direct mapping to 3.1.21, 3.4.6, 3.8.7 and 3.8.8 with language you can hand straight to an assessor. Useful even outside CMMC.

Four steps, one happy admin

Full quickstart →

The first two are the ten-minute quickstart on one test machine. The last two are the rollout, and they take as long as discovery mode needs to show you what your team actually plugs in.

msiexec /i PermitUSB.msi /qn ENROLL_TOKEN=pusb_live_… GROUP=line-1-workstations
  1. Step 1

    Sign up

    14-day trial, no card. Your workspace lands with a working starter policy already in place.

  2. Step 2

    Run one line

    Copy the install command from the dashboard, paste into elevated PowerShell. It enrolls and protects.

  3. Step 3

    Tune the policy

    Drop a serial on an allow list, group endpoints by team. Discovery mode stays audit-only until you say go.

  4. Step 4

    Deploy at scale

    GPO, Intune, or your RMM: same MSI, same parameters. New endpoints land in the right group.

What's included

Every feature is in the trial. There is no gated tier holding back the part you actually need.

Full feature list →
  • VID/PID, serial, class and vendor-name matching
  • Per-endpoint-group policies
  • Check in now: changes land in seconds
  • Per-group discovery mode
  • Tray app with a toast on every block
  • Self-protection: service ACL + watchdog
  • Stale-policy fail-closed
  • Email + webhook alerts
  • Blocked-device, inventory and history reports
  • Full-history CSV export with honest row counts
  • SIEM forwarding (CEF) + on-prem relay
  • Passkey login and audit log

Pricing

One number. Published.

$2 per endpoint per month, or $20 per year, two months free. Buy one license or a thousand, month-to-month, cancel from the dashboard.

See pricing & FAQ →

Trial

$0

14 days · up to 25 endpoints · no card

Paid

$2

per endpoint / month · no minimum

Plug a drive in. Watch it get blocked, then approve it in one click.

Sign up, paste the one-liner on a test machine, plug in a USB stick, and watch the event land in the dashboard. That's the whole demo.