

The endpoint that knows exactly what it is allowed to do.
XPC-Plus keeps Windows exactly where it is, then closes the two gaps that most endpoint estates never really close: unpatched software and uncontrolled execution. One subscription, one managed outcome, three layers working on the same endpoint.
$17 per endpoint / month
$17
Per endpoint / month
One price for the XPC experience layer, fully managed patching and fully managed deny-by-default execution control.
3
Layers, one endpoint
Experience control, patch remediation and execution control applied together instead of bought, integrated and staffed separately.
$0
OS migration cost
No Linux, no re-imaging and no second endpoint operating system. Windows stays installed, patched and managed underneath.
Three layers. One endpoint.
Control what users see. Patch what is installed. Control what can execute.
Each layer solves a problem the others cannot. Bought separately they are three products, three consoles and three ongoing workloads. In XPC-Plus they are one subscription and one managed outcome.

Control the experience
The user sees only what they are meant to see.
XPC replaces the general-purpose Windows desktop with one locked, brandable access screen that presents the connections you approve — Citrix, RDP, AVD, Windows 365, Horizon, WorkSpaces, Parallels RAS or a browser workspace. Windows stays underneath, patched and managed as normal.
- One access screen instead of a full desktop
- No local desktop wandering, no stray installs by habit
- XPC Mode and XPC-Lite Mode for different levels of lockdown
- Configured centrally from the XPC Cloud Portal
Eliminate patch neglect
Patch everything you are trusting.
Locking the user experience does not patch the software still installed on the machine. XPC-Plus includes fully managed patching and vulnerability remediation using Action1, covering Windows and the third-party applications that are most often left behind — browsers, runtimes, remote-access clients and helper agents.
- Continuous discovery of installed software and missing updates
- Windows and third-party application patching, managed for you
- Remediation applied on a schedule that respects shift patterns
- Patch and vulnerability status visible per endpoint
Control what can execute
Trust less — even after approval.
The third layer moves the endpoint from “block what we recognise as bad” to “only run what has been approved”. XPC-Plus includes fully managed deny-by-default execution control using ThreatLocker, so unapproved applications, scripts and libraries do not run in the first place.
- Deny-by-default application control rather than detect-and-respond
- Approved software still constrained in what it may reach
- Unapproved scripts and libraries denied by policy
- Policy authored and maintained by us, not handed to you as homework
XPC-Plus incorporates technology from
Action1 and ThreatLocker are trademarks of their respective owners. XPC is not affiliated with, or endorsed by, either company.
The XPC-Plus security stack
Every layer between the user and the hardware, accounted for
Nothing here replaces Windows. Each layer governs a different part of what the endpoint is allowed to do.
User
One access screen. No general-purpose desktop to wander around in.
XPC experience layer
Presents and launches only approved connections. Brandable, centrally configured.
Execution control
Deny-by-default application control and ringfencing (ThreatLocker).
Patch and vulnerability remediation
Managed Windows and third-party patching (Action1).
Windows
Kept, patched and managed. Familiar to users, familiar to your team.
Hardware
The PCs and thin clients you already own, kept in service longer.
Layer 02 — patching
Patch everything you are trusting
A locked access screen does not patch the software still installed underneath it. The browser, the remote-desktop client, the runtimes and the helper agents on a thin-client-style endpoint are exactly the components an attacker would prefer you forgot about — and on shared or unattended PCs, nobody is there to notice an update never landed.
XPC-Plus includes fully managed patching and vulnerability remediation, so patch currency is an outcome you are buying rather than a task you are hoping someone had time for.
Layer 03 — execution control
Trust less — even after approval
Patching closes known holes. Execution control changes the default answer to “something new wants to run”. Instead of assessing whether it looks malicious, XPC-Plus denies anything that has not been approved.
This is not a replacement for the antivirus, EDR or identity controls your policy or insurer requires. It reduces what can run at all, which is a different and complementary job.
Allowlisting and ringfencing
Allowlisting decides what runs. Ringfencing decides what it may do next.
Most people meet application control as a list of approved programs. That is only half of it. Approving an application does not mean the application should be able to reach every file, every network path and every other program on the machine. Deny-by-default control lets an approved application do its job and nothing beyond it.
An approved tool, an unapproved action
A legitimate scripting engine is genuinely needed by an installed application. Left alone, it can also be driven to fetch and run something else. Constrained, it does the job it was approved for and cannot be turned into a delivery mechanism.
An approved application, unapproved reach
An approved productivity application has no business enumerating a finance file share. Constraining its reach limits the damage a compromised or misused process can do, even though the application itself remains approved.
Approved software, unapproved children
Many attacks work by using something already trusted to launch something new. Controlling what an approved process may launch removes that route without removing the software people rely on.
Examples above are conceptual illustrations of how allowlisting and ringfencing differ. They are not descriptions of any specific incident, product configuration or customer environment.
The security loop
Discover, remediate, control, contain, present
Endpoint security fails at the point where it becomes someone’s recurring chore. XPC-Plus turns the loop into a service that runs whether or not your team had a quiet week.
01
Discover
Find what is actually installed and what is actually missing patches — on every endpoint, continuously.
02
Remediate
Apply Windows and third-party updates on a managed schedule so the gap closes instead of ageing.
03
Control
Allow only approved applications, scripts and libraries to execute at all.
04
Contain
Constrain what approved software may reach, so an approved process cannot be repurposed freely.
05
Present
Show the user one clean access screen, so the endpoint stays the endpoint you configured.
Then it starts again — continuously, as a managed service.

Managed, not abandoned
Stop babysitting it
XPC-Plus is not a promise that endpoints never need attention again. It is a promise that the recurring work — chasing patches, curating allowlists, reviewing what changed — is run by us as a managed service, so it happens whether or not your team had a quiet week.
The upgrade path
An upgrade, not a project
XPC-Plus applies to endpoints already running XPC. There is no re-imaging, no user migration and no change to the connection the user sees.
- 1
Log in to the XPC Cloud Portal
The same portal you already use to manage XPC endpoints. Nothing new to install for administrators.
- 2
Choose the endpoints to upgrade
Select individual endpoints, a device group, or the whole organisation. MSP-grade tenants can upgrade per customer organisation or in bulk across every organisation they manage.
- 3
Enable XPC-Plus
The patching and execution-control layers are deployed and enrolled to the selected endpoints. No re-imaging, no user migration and no change to the connection the user sees.
- 4
Watch the status
Each endpoint reports its XPC-Plus state: protection enrolled, patch level, pending remediation and execution-control policy applied.
Per-endpoint status
What the portal shows you
- XPC-Plus enabled or not, per endpoint
- Patch level and outstanding remediation
- Execution-control policy applied and version
- Recent denied-execution activity
- Approval requests awaiting decision
XPC-Plus is provisioned per organisation from the XPC Cloud Portal. Talk to us to enable it on your tenant and we will confirm lead time and onboarding for your endpoints.
XPC and XPC-Plus
Which tier fits the endpoint in front of you
Standard XPC assumes you already run patching and endpoint security and simply want the experience layer. XPC-Plus is for the endpoints where you would rather that work were handled for you.
| Capability | XPC — $2 | XPC-Plus — $17 |
|---|---|---|
| Locked, brandable access screen | Included | Included |
| Any remote platform (Citrix, RDP, AVD, W365, Horizon, WorkSpaces, RAS) | Included | Included |
| Central management in the XPC Cloud Portal | Included | Included |
| Windows kept, patched and managed underneath | Yes — using your existing tooling | Yes — patching managed by us |
| Windows and third-party patch remediation | Your existing RMM or patch tooling | Fully managed (Action1) |
| Software and vulnerability discovery | Your existing tooling | Continuous, included |
| Deny-by-default application control | Not included | Fully managed (ThreatLocker) |
| Ringfencing of approved applications | Not included | Included |
| Policy authoring and ongoing tuning | Your team | Run as a managed service |
| Price | $2 per PC / month | $17 per endpoint / month |
Where it earns its place
The endpoints that benefit most
Regulated and audited environments
Finance, health, legal and government teams that must show patch currency and demonstrate that only approved software executes.
Shared and unattended endpoints
Shift-worked desks, clinical rooms, classrooms, kiosks and reception PCs where nobody owns the machine and nobody notices drift.
Small teams with no security staff
Organisations that need the outcome of a patching programme and an application-control programme without hiring for either.
MSPs standardising a security posture
One upgrade, applied per customer organisation, giving every managed estate the same patching and execution-control baseline.
XPC-Plus questions
Straight answers
The Plus capabilities run on either XPC architecture
Managed patching and deny-by-default application control are independent of how the endpoint presents Windows, so you choose the architecture the endpoint needs and add the Plus layer on top.

$17
per endpoint / month
The Plus security and management layer on the standard XPC architecture, where the traditional Windows desktop is replaced for maximum lockdown.

$19
per endpoint / month
The same Plus layer on the XPC Lite compatibility architecture, where the underlying Windows environment keeps operating — hidden from the user — for applications and services that require it.
Three layers. One endpoint. $17 per month.
Keep Windows, keep your peripherals, keep your team’s skills — and stop carrying patching and application control as recurring work.