Protection lifecycle

Protection is an operating process, not a checkbox.

Every covered panel receives a documented baseline, recoverable artifacts, controlled maintenance, and an explicit response path when critical vulnerabilities apply.

01

Protected backups

Preserve native application artifacts and supporting configuration with integrity checks, controlled access, retention, and recovery review.

02

Two scheduled update reviews

Review the supported software stack twice each year, test supported updates, and deploy compatible changes after authorization through preflight, backup, verification, and rollback criteria.

03

Critical response

Evaluate applicable critical vulnerabilities between scheduled reviews and deploy a tested vendor patch or documented mitigation when a supportable response exists.

Controlled workflow

Every change follows the same review boundary.

  1. 01

    Inventory

    Record application, operating system, modules, drivers, dependencies, credentials ownership, and recovery artifacts.

  2. 02

    Plan

    Prepare a versioned update plan with impact, test evidence, maintenance-window requirements, rollback criteria, and expected results.

  3. 03

    Authorize

    A qualified person reviews and approves the exact operation before the connected AgentLab can retrieve it.

  4. 04

    Verify

    The AgentLab captures preflight and backup evidence, executes the allowlisted change, validates the outcome, and preserves the audit record.

Source-available foundation

The same AgentLab, carried into panel operations.

PanelLock does not introduce a separate black box. It uses the same inspectable AgentLab workbench, configured and operated by qualified personnel for the covered environment.

Customer controlInfrastructure and source remain inspectable.

Qualified operationConfiguration and maintenance knowledge is required.

Human authorityAgents build plans; authorized people approve; AgentLabs execute.

Explore AgentLabs

Security posture

CISA-aligned practices, precisely stated.

PanelLock is designed to support practices aligned with applicable CISA Cybersecurity Performance Goals and vulnerability-management guidance, including inventory, protected recovery, controlled access, logging, and Known Exploited Vulnerabilities review.

PanelLock does not claim a blanket CISA certification. Stronger assurance requires a named scope, documented controls, retained evidence, and independent assessment.

Annual coverage

$850per panel / year

Includes two scheduled update reviews, protected backups, notifications, and applicable critical vulnerability response.

Add PanelLock Protect

Service boundary

Safe deployment depends on the supported environment.

Coverage requires supported components, usable recovery artifacts, a qualified AgentLab operator, an approved maintenance window, and a tested patch or mitigation. PanelLock Protect does not guarantee uninterrupted operation or an unconditional repair deadline.