Free utilities

Tools

Small, self-contained utilities built to solve real problems on real machines. Every tool is free to download, and each one carries its own description and changelog so you can see exactly what you are running.

Recovery Available

User Profile Migrator

A single-file Windows application that handles the two jobs a technician usually hits on the same machine visit: moving a user’s data into a different account, and working out what all those unknown devices in Device Manager actually are.

Windows 10 / 11 64-bit v2.2.1 No installer Free
Download for Windows · 60 MB
UserAccountMigrator-2.2.1-win-x64.zip
SHA-256 bc9fd6f2f5a8873e7f0b01f3985b91a2e15c281b7dbe607753704f5d3f09bd05

The ZIP contains the application and its manual. No installer, and no .NET runtime is required on the target PC. The application requests administrator rights when it starts; if you decline, it opens read-only.

The executable is Authenticode signed by CN=MyTechie, O=MyTechie, L=North Sydney, S=New South Wales, C=AU and RFC 3161 timestamped. Right-click the file, choose Properties → Digital Signatures to check it, or open About inside the application, which verifies its own signature and shows this checksum.

What it does

Profiles & programs

Copies or merges the contents of one Windows user profile into another — documents, desktop, pictures, browser data and the rest — then catalogues the programs that were installed on the source machine so they can be reinstalled deliberately rather than from memory. Profiles on a disk pulled out of another PC are supported, so a dead machine’s drive can be read directly.

Drivers & unknown devices

Identifies the yellow triangles in Device Manager from their raw hardware IDs and asks Windows Update which newer drivers are on offer for the machine. Scanning, decoding and reporting are entirely read-only.

Why it is safe to run

  • The source profile is never modified. The engine only reads it — there is no move or delete path.
  • Nothing runs without a preview. A live migration stays disabled until a dry run has completed for the exact settings you are about to use.
  • Nothing is overwritten by default. Everything lands in a new sub-folder, so collisions cannot happen. When you deliberately merge in place, replaced files are backed up first.
  • Every run can be undone. Each run writes a full log and a CSV manifest of every action, and the undo replays that manifest backwards.
  • Dangerous configurations are refused — same source and destination, identical paths, or nested profiles are blocked outright.
  • Copies are verified by size, with optional SHA-256 deep verification.
Changelog
2.2.1

The Windows build is now Authenticode-signed with a real code-signing certificate, so the About window's signature check reports it as signed rather than unsigned. No functional change.

2.2.0

Restyled to the shared InstaHost desktop look, with Help and About windows that work without a network. About now checks the running executable with the same signature API Windows uses and reports whether it is signed, invalid or unsigned, alongside the publisher and the SHA-256 of the exact file being run.

2.1.0

Catalogues the programs installed under the source profile during a migration, so they can be reinstalled on the new machine, and adds author and donation links to both tabs.

2.0.0

Merged the profile migrator and the driver finder into one executable with a single tab strip, and added profiles on a disk pulled from another PC as a migration source.

1.x

Profile copy and merge with preview, exclusions, conflict policy and verification; per-user registry export and import; full logging, CSV manifests and undo.

Documents Available

Simple Scanner

A small, private scanning app for turning paper into PDF, JPG or PNG. It remembers your save location and scan settings, supports flatbeds and document feeders, and can open a ready-to-send email with the scan attached.

Windows 10 / 11 · v1.1.1 macOS 13+ · v1.1.0 No account No telemetry Free

macOS · v1.1.0

Universal build for Apple silicon and Intel. Requires macOS 13 Ventura or later.

Download for macOS · 1.7 MB
SimpleScanner-1.1.0-macos-universal.zip
SHA-256 beeedaf2fa63323af1292181ebc9a1dd857c17d54a0f670dc5d1e65d847e4a26

Signed by Developer ID Application: Patrick Hamid (E4DUZ8FY37), notarised by Apple and stapled. macOS verifies the ticket and Developer ID signature when the application opens.

Windows · v1.1.1

Standalone x64 build for Windows 10 and 11. No separate runtime is required.

Download for Windows · 64 MB
SimpleScanner-1.1.1-win-x64.zip
SHA-256 811597593aa946912dc9b18d878e01e5a89aed47a749949d0e2d21bbf7811f44

The executable is Authenticode signed by CN=MyTechie, O=MyTechie, L=North Sydney, S=New South Wales, C=AU and RFC 3161 timestamped. Right-click the file, choose Properties → Digital Signatures to check it, or open About inside the application, which verifies its own signature and shows this checksum.

Already have the .NET 8 Desktop Runtime? Download the smaller 4.4 MB build (f3b5964303500192facf0bf881402e9801bc27702a82049629e2a0f25b34b0a5).

The executable is Authenticode signed by CN=MyTechie, O=MyTechie, L=North Sydney, S=New South Wales, C=AU and RFC 3161 timestamped. Right-click the file, choose Properties → Digital Signatures to check it, or open About inside the application, which verifies its own signature and shows this checksum.

What it does

Scan the way you work

Choose flatbed or feeder, colour mode, resolution, page size and output format. Multi-page scans appear as thumbnails that can be reordered, rotated or removed before saving as one PDF or separate image files.

Private by design

  • No cloud account, analytics or telemetry. Scans stay on your computer unless you choose to email them.
  • No installer. Unzip the download and open the application.
  • Existing files are never overwritten. A safe numbered name is chosen automatically.
  • Saved defaults speed up repeat jobs. Folder, format, quality, source and naming pattern are remembered.
Changelog
1.1.1

Both Windows builds are now Authenticode-signed with a real code-signing certificate, so the About window's signature check reports them as signed rather than unsigned. No functional change. The macOS build remains Developer ID signed and notarised by Apple, unchanged.

1.1.0

Restyled to the shared InstaHost desktop look used by the other tools: the header bar, the dark palette, cards with the brand rule, flat buttons, and a permanent footer carrying the author and donation links. On macOS the dark appearance is forced so the app looks the same on every machine. Nothing about scanning, output, email or saved settings changed, and the macOS build remains Developer ID signed and notarised by Apple.

1.0.0

First public release for macOS and Windows: multi-page scanning from flatbeds and feeders, PDF, JPG and PNG output, remembered defaults, file-name patterns, and email through the desktop mail client or a configured SMTP server. SMTP passwords are stored in the system credential store, and the About window reports the version, publisher, signature state and the SHA-256 of the running binary.

Deployment Available

PackPilot

Set up a new computer in one pass. Tick the software you want from a built-in catalogue of 124 free applications, then install the lot in one go — or save the selection and reuse it on every machine you build. Nothing is bundled or repackaged: on Windows it asks the Microsoft package manager, and on macOS it asks Homebrew.

Windows 10 / 11 · v2.0.2 macOS 13+ · v1.0.1 124 applications No adware Free

Windows · v2.0.2

Standalone x64 build for Windows 10 and 11. No installer and no .NET runtime are required.

Download for Windows · 60 MB
PackPilot-2.0.2-win-x64.zip
SHA-256 75f1b3b9a2f8989bff27de689680fbe877b4111c8c8dbae8abf474311808b860

The executable is Authenticode signed by CN=MyTechie, O=MyTechie, L=North Sydney, S=New South Wales, C=AU and RFC 3161 timestamped. Right-click the file, choose Properties → Digital Signatures to check it, or open About inside the application, which verifies its own signature and shows this checksum.

macOS · v1.0.1

Universal build for Apple silicon and Intel, signed and notarised. Requires macOS 13 Ventura or later, and Homebrew.

Download for macOS · 1.4 MB
PackPilot-1.0.1-macos-universal.zip
SHA-256 9589fc5d3c7fcd3e9ff0eca45b12be4ea88e193ed1a3fe4d3db2627603827821

Signed by Developer ID Application: Patrick Hamid (E4DUZ8FY37), notarised by Apple and stapled. macOS verifies the ticket and Developer ID signature when the application opens.

What it does

Pick once, install everywhere

Tick the applications you want and press install. PackPilot works through them one at a time, showing what it is doing and what happened to each one. Click a category heading to select or clear the whole group, and search by name, package identifier or licence.

The same selection can be saved as a profile, exported as a PowerShell script, a batch file or a winget import file on Windows, or as a shell script or Brewfile on macOS — so it can be driven from an RMM, Intune, a GPO startup script or a task sequence. On Windows it can also build a single deployment executable that carries your selection inside it.

Only from official sources

  • No bundled installers and no adware wrappers. Windows installs go through the Windows Package Manager (winget), falling back to Chocolatey and then to the vendor’s own download. macOS installs go through Homebrew.
  • Every package identifier is checked against the vendor’s own index before each release. The Windows list is validated against the winget community source index that winget itself downloads, and the macOS list against the official Homebrew cask and formula API. A name that does not resolve fails the build rather than the technician’s machine.
  • Every application says how it is free. A badge marks each one as open source, freeware, free for personal use, or a free tier of a commercial product, so you know what you are putting on a client’s computer.
  • One catalogue, both editions. The Windows and macOS builds read the same list, and the build fails if the copy inside either one has drifted from it.

What is in the catalogue

124 applications in 13 categories — browsers, messaging, media, runtimes, imaging, documents, security, cloud storage, file sharing, compression, utilities, remote access and developer tools. 110 can be installed on Windows, 90 on macOS, and 76 on both. You can add anything else by pasting its winget identifier or Homebrew token, or replace the list entirely with your own catalog.json.

Checking what you downloaded

About inside the application reports the version, build date, publisher, signature state and the SHA-256 of the running executable, so it can be compared with the checksum published above without a network connection.

Changelog
2.0.2 / 1.0.1

The Windows build is now Authenticode signed by MyTechie and RFC 3161 timestamped, using the same InstaHost Trusted Signing certificate as the other Windows tools; SmartScreen no longer warns on first run. No application behaviour changed. The macOS edition is unaffected and remains at 1.0.1.

2.0.1 / 1.0.1

First public release, and the first with a macOS edition. Both editions share one catalogue of 124 applications, and every package identifier in it is now verified against the official winget and Homebrew indexes before the build is allowed to finish — which caught eight entries that named packages that do not exist and would have failed silently partway through a deployment. Each application carries a licence badge saying whether it is open source, freeware, free for personal use, or a free tier. Both editions were restyled to the shared InstaHost desktop look, gained an About window reporting the SHA-256 and signature state of the running file, and can now install a Microsoft Store package by identifier. The macOS build is Developer ID signed and notarised by Apple, so it opens without a Gatekeeper warning. Deployment status colours that were unreadable on the dark theme, and a filter that hid a tick box but not its row, are fixed.

Creative Available

Lumen

A photo editor for your raw files that replaces a Lightroom subscription. Open the files straight off the card, correct the lens, develop the picture, and send the finished export to every backup you keep — all without ever changing the original file.

macOS 14+ · v1.2.0 Raw and JPEG Non-destructive No subscription Free

macOS · v1.2.0

Universal build for Apple silicon and Intel, signed and notarised. Requires macOS 14 Sonoma or later.

Download for macOS · 5.4 MB
Lumen-1.2.0-macos-universal.zip
SHA-256 ac560e0ce682aa4e4dbef4e5031c86a3050dd9e072962bb5239fed04bbb63e15

Signed by Developer ID Application: Patrick Hamid (E4DUZ8FY37), notarised by Apple and stapled. macOS verifies the ticket and Developer ID signature when the application opens.

What it does

Your originals are never touched

Everything you do is stored as a recipe beside the photograph, not baked into it. The file that came off your camera stays byte-for-byte as it was, and you can go back to it, or to any earlier point, at any time. Delete Lumen and every photograph you own is exactly where you left it.

Reads the raw files your camera makes

Lumen decodes raw through the same imaging engine macOS itself uses, so it opens Sony, Canon, Nikon, Fujifilm, Olympus and OM, Panasonic, Pentax, Leica, Hasselblad, Phase One, Sigma, GoPro and DNG files, alongside JPEG, HEIF, PNG and TIFF. Exposure recovery and highlight recovery happen while the sensor data still has room in it, which is detail no slider can get back later.

Fixes what the lens did

Lumen uses the camera maker’s own correction when your file carries one, matches a profile from its own database when it does not, and gives you manual control over distortion, corner darkening, colour fringing and perspective when nothing has ever measured your glass. It tells you plainly which of those three it is doing, rather than showing a tick box that quietly does nothing — and if it cannot identify your lens with confidence it says so instead of guessing, because the wrong correction is worse than none.

All the usual corrections, where you expect them

  • Light. White balance, exposure, contrast, highlights, shadows, whites and blacks, with tone curves for each channel.
  • Colour. An eight-band mixer for hue, saturation and brightness, colour grading for shadows, midtones and highlights, and camera calibration.
  • Detail. Sharpening that leaves flat areas such as sky alone, plus noise reduction for both grain and colour speckle.
  • Presence. Texture, clarity, dehaze, vibrance and saturation.
  • Shape. Crop, straighten, rotate, flip and perspective correction for leaning buildings.
  • Finish. Post-crop vignette and film grain.

Change one part of a picture

Darken a sky, lift a face, warm a foreground. Use a gradient, a brush, or a colour or brightness range — or let your Mac find the subject, the sky, the people or the background for you. That recognition runs on your own machine and the photograph never leaves it.

Optional help from AI, switched off until you want it

If you connect your own AI service, Lumen can suggest a starting develop for a picture, write keywords, titles, captions and alt text, offer a critique, help rate a shoot, and let you search your library by describing what you are looking for. It is off by default, asks separately before any photograph is sent, strips all metadata including location from anything it does send, and ships with no key of its own.

Export to everywhere at once

Send a finished export to a folder, a NAS, WebDAV, SFTP, Google Drive, OneDrive and S3-compatible storage in a single action. If one destination is unreachable the others still receive the file, because that is the whole point of keeping more than one copy. Location data is removed from exports unless you ask for it.

Coming from Lightroom

Lumen reads Adobe XMP sidecar files, so your ratings, colour labels, keywords and much of your existing develop work come across — and it tells you honestly which settings it could not carry over rather than approximating them silently.

Honest about what it cannot do

  • No DNG or WebP export. macOS cannot write WebP, and a correct DNG needs a component Lumen does not carry. It refuses rather than hand you a file with the wrong contents inside.
  • SFTP needs a key, not a password, because a password cannot be supplied safely without shipping an extra helper.
  • Google Drive and OneDrive need your own client ID, because Lumen ships no credentials of its own.
  • The lens profile database is a starter set. Unlisted lenses fall back to your camera maker’s correction, or to the manual sliders.
Changelog
1.2.0

Reaches the rest of the engine. A white-balance eyedropper arrives at last: click a neutral and the cast goes, answered from the sensor data itself on a raw file rather than guessed from the rendered pixels, with the result landing in the ordinary temperature and tint sliders so you can see it, nudge it and undo it. Virtual copies let a colour and a black-and-white version of one frame live side by side at no disk cost, and named snapshots let you freeze a recipe and come back to it. Smart collections can finally have their rules edited rather than deleted and rebuilt, and any filter you have built can be saved as one. Importing now asks first: rename with the same tokens as export and a live preview, add everything to a collection, and choose a develop preset for the run — though Lumen will only ever rename a copy it made itself, never your originals where they sit. Culling with AI rates a whole shoot in one request so the frames are judged against each other, and writes nothing to your catalogue until you have looked at every suggestion and accepted it. Colour and luminance range masks are now adjustable. Two faults were caught before release by a new self-check that runs inside the application itself: the eyedropper had been solving the white balance in the wrong colour space and returning a confident, wrong answer, and a photograph with one virtual copy claimed to have none.

1.1.0

Makes the engine reachable. Zoom and pan arrive — fit, fill, 1:1 and free zoom to 1600% — so you can finally judge sharpening and noise reduction at true size. A library sidebar shows the folders, collections, smart collections and hierarchical keywords that were already in the catalogue, and an information panel shows everything the file says about itself alongside editable title, caption, copyright and artist. Crop gains aspect presets and a straighten gesture, masks can now be placed on the photograph with handles instead of created blind, and heal and clone finally have a tool. Develop settings can be copied and pasted across a selection, and photographs can be filtered by camera, lens, ISO and date. Under the surface, a base-image cache that never once hit — every render had been decoding the raw file again from scratch — now hits 87.5% of the time when browsing a shoot, and Core Image renders on a command queue Lumen owns, worth another 15–20% on the interactive render. A thumbnail that could spin forever, sliders that stored more precision than they displayed, and an import preset setting that was never read are all fixed.

1.0.1

Fixes two faults found by using the first build rather than testing it. Photographs could not be selected by clicking in the grid or filmstrip, because the cell was not a real button. Portrait photographs rendered on their side in the develop view, because the raw decoder was not told the orientation the camera had recorded.

1.0.0

First public release. A complete non-destructive darkroom for macOS: raw decoding through Apple’s own imaging engine, real lens correction from the maker’s profile or Lumen’s own database, the full set of light, colour, detail, presence, shape and finish controls, and local adjustments using gradients, brushes, ranges, or subject, sky, people and background recognition performed on your own Mac. Edits are stored as recipes with full history, snapshots and presets, and Adobe XMP sidecars are read so an existing Lightroom library can come across. Export delivers to a folder, WebDAV, SFTP, Google Drive, OneDrive or S3 in one action, with location data stripped by default. Optional AI features run through a gateway you configure and are switched off until you enable them. The build is Developer ID signed and notarised by Apple, so it opens without a Gatekeeper warning.

Recovery Available

APFS Reader for Windows

A portable, read-only browser for opening APFS partition images or physical disks on Windows, browsing their folders and extracting selected files. It supports Windows 7 SP1 and newer, including software-encrypted APFS volumes.

Windows 7 SP1+ 32-bit / 64-bit v1.2.2 Portable Read-only Free

Windows 64-bit

Recommended for most PCs. Requires .NET Framework 4.0, included with modern Windows.

Download 64-bit · 1.2 MB
APFSReader-1.2.2-win-x64.zip
SHA-256 66af38067860fa59493b13d0a5b3695ab1da5c075841dd61b2bb9ca9c5333929

The executable is Authenticode signed by CN=MyTechie, O=MyTechie, L=North Sydney, S=New South Wales, C=AU and RFC 3161 timestamped. Right-click the file, choose Properties → Digital Signatures to check it, or open About inside the application, which verifies its own signature and shows this checksum.

Windows 32-bit

For legacy x86 systems. This build can access only the first APFS sub-volume.

Download 32-bit · 1.0 MB
APFSReader-1.2.2-win-x86.zip
SHA-256 700054818351322394fbd0fa80fcc683d84ba808ef2fcc001489a7d9196b0c81

The executable is Authenticode signed by CN=MyTechie, O=MyTechie, L=North Sydney, S=New South Wales, C=AU and RFC 3161 timestamped. Right-click the file, choose Properties → Digital Signatures to check it, or open About inside the application, which verifies its own signature and shows this checksum.

What it does

Recovery without writing to the source

  • APFS write operations are not implemented. The native backend is compiled read-only and opens the source without write access.
  • Existing destination files are never overwritten. Extracted data is written to a unique partial file and moved into place only after a successful read.
  • Passwords stay local. A FileVault password is passed to the local backend through standard input, not exposed in command-line arguments.
  • Known limits are explicit. T2 or hardware-encrypted volumes are unsupported, and the 32-bit build can access only the first APFS sub-volume.

Checking what you downloaded

The About button in the application reports the version, build date, publisher and the SHA-256 of the running executable, so it can be compared with the checksum published above without a network connection.

Changelog
1.2.2

Replaced the app's own hand-rounded palette with the shared InstaHost desktop theme also used by Simple Scanner and PackPilot, so scroll bars, the file list header and the title bar are now dark like the rest of the estate's tools rather than staying native light. Also fixed cramped spacing in the About window. No functional change to APFS reading or extraction.

1.2.1

Both the GUI and the native read-only backend are now Authenticode-signed with a real code-signing certificate, so the About window's signature check reports them as signed rather than unsigned. Signing now happens inside the GitHub Actions release build using Azure Artifact Signing, authenticated by workload identity federation rather than a stored secret. No functional change.

1.2.0

Added an About window reporting the version, build date, publisher and the SHA-256 of the running executable, together with author, free tools, privacy and donation links, and a permanent freeware footer on the main window. Copyright is attributed to Patrick Hamid, and a tagged build now stamps its own informational version.

1.1.0

Applied the InstaHost desktop theme to the browser window and shipped the complete dependency licences with every portable package.

1.0.1

Corrected the Windows parser test paths and the .NET Framework 4 reference assemblies used by the release build.

1.0.0

First public release: portable, read-only APFS browsing and extraction for Windows 7 SP1 and newer, in 32-bit and 64-bit builds.

Source and upstream release notes: github.com/phamid/apfs-reader .

Developer Available

Repo Review

A command-line reviewer for git repositories. It runs 36 checks across documentation, testing, CI, dependencies, secrets and git hygiene, then writes a report where every finding cites the evidence it came from and a plan that says what to do first and how you will know it is done.

macOS, Linux, Windows · v1.0.0 Python 3.9+ and git Runs offline Read-only Free

Source archive · v1.0.0

Shell and Python scripts. Unzip it anywhere and run scripts/preflight.sh. Works on macOS, Linux, and Windows through WSL or Git Bash.

Download · 67 KB
RepoReview-1.0.0-cli.zip
SHA-256 b8ca136c40b0fb0fd46600a5ede8df5ef2681707c1dff6ea1e29ac8880c55c03

This is a readable source archive of shell and Python scripts, not a compiled application, so there is no code signature to verify. Check the SHA-256 above after downloading, and read the scripts before running them — they are meant to be read.

What it does

Three files, not a score

Point it at a repository and it writes evidence, findings and a plan. The findings name the file each conclusion came from, so you can check any of them without running it again. The plan sorts the work by severity and effort, says which items must be done before others, and gives every action a condition that proves it is finished.

It tells you what it could not check

A check with no evidence behind it reports not checked — never passed. If no vulnerability scanner is installed, the report says your exposure is unknown rather than quietly awarding a clean bill of health. Every report ends with a log of what ran and what did not, and the scorecard shows coverage next to score so a high mark on thin evidence is impossible to misread.

What it looks at

  • Documentation. README substance, licence, security policy, changelog, design notes.
  • Testing and CI. Whether tests exist, whether CI runs them, whether it lints and scans.
  • Dependencies. Lockfiles, known advisories, automated updates, floating versions.
  • Secrets and hygiene. Committed keys and .env files, large blobs in history, stale branches.
  • People and change. Bus factor, commit quality, and the files that change most — where regressions actually happen.

Safe to point at anything

  • It never modifies the repository it reviews. Even dependency audits run against a copy in a temporary folder, because some package managers write a lockfile into the project they are auditing.
  • Nothing leaves your machine. No account, no API key, no telemetry, and no network call of its own.
  • Reports are written outside the repository so they cannot be committed by accident, and secret candidates are shortened before being written to disk.
Changelog
1.0.0

First public release. Thirty-six checks across ten dimensions, five read-only collectors, and three outputs: the evidence itself, a report whose findings each cite a file, and a sequenced plan with acceptance criteria and gates to clear before a repository is made public. Checks that cannot be evaluated report as not checked rather than passing, and the scorecard reports coverage alongside score so an incomplete review looks incomplete. Secret detection is guarded by a regression test built from real false positives — an early build reported an ordinary line of JavaScript as an exposed credential, and one wrong critical finding costs more trust than ten missed small ones.

Requires Python 3.9 or newer and git. Optional scanners (gitleaks, osv-scanner, pip-audit, trivy) unlock further checks; without them those checks report as not checked rather than passing.

Compliance Live demo

Vantage

A compliance platform you can actually click through. Vantage continuously tests security controls against live configuration, maps the results onto SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, NIST CSF and ISO 42001, and turns them into audit evidence, questionnaire answers and a public Trust Center. Nothing to install — it runs in your browser, free.

Web · v1.2.0 7 frameworks 49 automated tests Self-hostable MIT licence Free

Open the live demo

No signup and no download. The workspace is shared, filled with fictional data, and resets to its starting state every day, so you can change anything in it without consequence.

Open Vantage · free
Sign in with [email protected] · vantage123
Details are filled in for you, and nothing you type is stored

Read more, or run your own

The full story of what it does and how the monitoring engine works, plus the source under an MIT licence if you would rather host a private copy.

About Vantage
What it does

It tests, rather than asks

Most compliance tools are questionnaires with a database behind them. Vantage evaluates 49 automated tests against the actual configuration of cloud resources, identity accounts, endpoints and people — every hour, and on demand. A failing test opens a remediation task with a deadline set by its severity: three days for critical, thirty for low.

One control set, seven frameworks

159 requirements across SOC 2 Type II, ISO/IEC 27001:2022, the HIPAA Security Rule, GDPR, PCI DSS v4.0, NIST CSF 2.0 and ISO/IEC 42001 map onto a single set of 62 controls, so evidence gathered once counts everywhere it applies. Readiness is control-weighted, the way auditors actually score it.

Fixing something changes the numbers

Press Fix on a failing test and Vantage applies the compliant configuration, re-runs the test, and recomputes the control, the framework readiness and the public Trust Center in front of you. It is a working system, not a slide deck — which is why the demo is worth ten minutes.

The rest of the workflow

  • Policies. 22 versioned policies with approval, annual review dates and per-person acceptance.
  • People and devices. Security training, background checks, offboarding, disk encryption, screen lock, OS currency.
  • Vendors and risk. Risk tiering, sub-processors, assurance reports, a residual risk heat map.
  • Audit hub. Auditor details, observation windows, an evidence request list and an evidence library.
  • Questionnaires. Answers drafted from your live controls and approved policies, scored for confidence, with anything below 70% flagged for a human rather than asserted.
  • Trust Center. A public page generated from live monitoring, with NDA-gated documents and an access-request queue.

What the demo is, honestly

It is one shared workspace of entirely fictional data. Everyone signs in with the same published password, so anything you change is visible to everyone else until the daily reset. Do not put anything real into it — and if you want a private instance, the source is on GitHub and the server has no runtime dependencies at all.

Changelog
1.2.0

Made the hosted instance behave like the demonstration it is. It now resets daily, measured from the last reset and remembered across restarts so a redeploy cannot quietly postpone it. It also stops asking to remember you: the sign-in details are filled in already, the page asks your browser not to save or autofill credentials against it, your session ends with the tab, and the abuse counters keep a keyed digest rather than the address you typed.

1.1.0

Opened Vantage to everyone, free, with no sign-up gate, and published the source under an MIT licence. Because nothing sits in front of it any more, the application gained the guards that make that safe: per-client rate limits, browser security headers, anonymised access requests, a Trust Center that publishes coverage without revealing which controls are failing, and a workspace that restores itself.

1.0.0

First release: the monitoring engine, seven frameworks over one control set, one-click remediation, policies, personnel, devices, vendors, the risk register, the audit hub, questionnaire auto-answering and the public Trust Center.

A demonstration, not a service you should rely on: it is one small instance, it carries no availability commitment, and its data is wiped daily by design.

What changed on this page Site release history
1.11.0

Rebuilt the catalogue as a two-column grid with a filter bar, because six tools stacked in one column had become a page you had to scroll rather than one you could read. Tools can now be filtered by platform and category or searched by name, platform and what they do, and the count says how many of the six are showing. The filter bar only appears when scripting is available, so it can never become a control that does nothing, and every card keeps its description and changelog exactly where they were.

1.10.0

Published Repo Review 1.0.0, the first tool here that is a readable source archive rather than a compiled application. The download panel now states why such an archive has no signature to verify, instead of inheriting the warning written for unsigned Windows executables and naming a protection that never applies to it.

1.7.0

Published User Profile Migrator 2.2.0 and Simple Scanner 1.1.0 for both Windows and macOS, the first downloads carrying the shared InstaHost desktop look, and labelled each Simple Scanner download with the version it serves.

1.6.0

Gave every tool its own collapsible description and changelog, published APFS Reader for Windows 1.2.0, and withdrew the APFS Reader for TrueNAS operator release from the catalogue.

1.5.0

Published APFS Reader for Windows 1.1.0 as portable 64-bit and 32-bit downloads while retaining the separate TrueNAS operator release.

1.4.0

Added APFS Reader for TrueNAS as a read-only, network-isolated operator tool with explicit deployment and parser-risk guidance.

1.3.2

Version-keyed every download link so stale edge cache entries cannot replace ZIP files with an older website response.

1.3.1

Published Simple Scanner through the active nas1 routing, preserving InstaHost and MyTechie branding across page, asset, API and download paths.

1.3.0

Added Simple Scanner for macOS and Windows, platform-accurate trust notices, Coffee and LinkedIn actions, and expanded privacy details.

1.2.0

Added the privacy policy and made signing statements follow each artifact's manifest metadata.

1.1.0

Rebuilt the catalogue and donation experience in the InstaHost design language with responsive mounted-path support.

Found this useful?

These tools are free and self-funded. If one saved you a couple of hours, you can buy me a coffee or connect with me on LinkedIn.