Xavier enrolls, configures, secures, and monitors Mac, iPhone, iPad, Apple TV, Android, and Windows devices, all from a single admin console built on each platform's native management protocol.
Manages
Xavier speaks each platform's native management protocol, so you can enroll, configure, and secure your whole fleet from a single console.
The full Apple MDM protocol: Automated Device Enrollment, supervision, Declarative Device Management, configuration profiles, and volume app licensing.
A standalone Device Owner agent provisioned by QR code, with no Google account required and full policy control over the device. Or connect Managed Google Play and Samsung Knox zero-touch when you want them.
Enroll over the native OMA-DM protocol, then push policy from a visual profile builder: password rules, BitLocker, Defender antivirus, firewall, and Windows Update rings, with inventory and remote commands from the same console.
Applications, websites, AI tools, and USB drives are four different questions with one answer: a rule you write once, scoped to the whole fleet or to a device group, that the device itself enforces.
Name an application your organization does not permit and it never opens. A Mac refuses the launch outright, so no window appears and there is nothing to clean up afterwards; an Android device suspends the package and tells the person holding the phone why. Rules match a Mac app by its code signature, so renaming a copy or moving it to Downloads does not get around one.
Name the destinations a Mac may not reach, and a filter on the device refuses the connection, browser tabs included. A rule covers a host and its subdomains, and can be narrowed to particular applications, so "nothing may reach this service except the tools we approved" is two rules rather than a list of every exception.
Block an AI tool once and both levers are pulled: the application stops launching and its website is blocked too, so it cannot simply be used in a browser tab instead. Deny an AI provider outright, or deny it to everything except the tools you deliberately approved. Anthropic, OpenAI, Google, Perplexity, Mistral, Cohere, Groq, and GitHub Copilot are recognised out of the box.
One rule decides what happens when somebody plugs a USB drive into a Mac or a Windows PC. Start in audit, where nothing is blocked and every drive that appears is recorded, so you can see what your fleet actually uses before you take anything away. Then switch to block, with an allowlist for the drives your teams legitimately need.
Every one of these needs something in place on the device before it can do anything, so Xavier reports how many machines are actually enforcing rather than assuming a rule took effect everywhere. A Mac that is missing the piece is named, not averaged away.
All of it fails open on purpose. Nothing is enforced until you write a rule, and a policy that cannot be read is a policy that blocks nothing, because a machine that cannot start its own programs or mount its own disks is a far worse outcome than something briefly running that should not have.
Xavier manages packages across Homebrew, npm, Python pip, and Ruby Gems on every Mac in your fleet. See exactly what is installed, push installs and updates, and keep software current from one console, because outdated packages are a security problem.
Point Xavier at where an app publishes its releases and it watches for new versions, downloads them, verifies their integrity, and imports them into your Munki repository, so your fleet stays current without anyone repackaging a thing.
Xavier exposes a Model Context Protocol server, so AI assistants like Claude Desktop, VoxyAI, and Cursor can query your fleet in natural language. The AI can see inventory, compliance, software, and activity. It can never change anything or read secrets.
Devices configure themselves out of the box: Automated Device Enrollment for Apple, QR provisioning and Samsung Knox for Android, and guided enrollment for Windows. Users power on and get to work already secured to policy.
Push Wi-Fi, VPN, restrictions, and FileVault on Apple with a visual profile builder, plus modern Declarative Device Management, and the same builder pushes password, BitLocker, Defender, and firewall policy to Windows.
Deploy App Store and volume-purchased apps, publish through Managed Google Play, and push custom packages to Mac, Windows, and Android devices, all remotely.
A lightweight menu bar app reports inventory, security state, and installed packages in real time. It runs without root by default, with an optional root agent only when privileged tasks need it.
Lock, wipe, restart, install, and inventory on demand. Commands stream to devices and report back their results.
See which devices meet your policies at a glance. Compliance and activity reports surface drift before it becomes a problem.
Write scripts in bash, zsh, Python, Ruby, Perl, or Node in a built-in editor, run them on any Mac in the fleet, and keep the history of every run. Root execution is opt-in.
Group devices by hand or by rule. Condition-based groups update their own membership and drive profile assignment, app deployment, Munki manifests, and signage.
Turn managed iPads, Apple TVs, Macs, and Android tablets into signage displays with the Megaphone app, pushing content and schedules to screens from the same console you use for everything else.
Discover the local models, coding agents, and AI connectors running on your Macs, decide which of them your organization allows, and enforce that decision. Collection is off until you switch it on, and prompts are never collected.
One rule covers Macs and Windows PCs: record every drive that is plugged in, block the ones you have not approved, and keep an inventory of what your fleet actually uses.
A device falling out of compliance, a new app version waiting to be promoted, a certificate about to expire: choose which events are worth interrupting someone for, and route them to Slack, Teams, Google Chat, email, or your own webhook.
Run Xavier dedicated to one organization, or in shared mode where every tenant gets its own subdomain and isolated database, managed from an operator console.
From a device powering on for the first time to ongoing day-to-day management, Xavier handles the full lifecycle.
A device enrolls through Automated Device Enrollment, a QR code, or a profile. Xavier issues its identity certificate and registers it.
Profiles, restrictions, and apps deploy automatically, so the device reaches the user already set up to policy.
Encryption turns on, keys are escrowed, and posture checks confirm the device meets your security baseline.
Devices report inventory and security status on a schedule. You watch compliance, run commands, and push changes as needed.