Endpoint & Network Security, Licensed and Ordered From One Catalog
Every seat and every endpoint needs something watching it. This is what's stocked in the order-taking portal: the security software platforms that protect browsers, endpoints, and the network behind them, each billed as a recurring license.
How an Order Moves Through the Portal
The catalog below is what you're browsing. Placing an order follows the same path whether it's five seats or a five-hundred-endpoint rollout.
Browse & Configure
Pick a platform and license tier, and set your endpoint or user count. Tiers are pre-configured to avoid buying a level that doesn't cover what you need.
Quote & Approve
The portal returns current per-endpoint or per-user pricing. Orders above your account's threshold route to an approver before they're placed.
Provision or Ship
Licenses activate against your tenant automatically — no shipping, no staging bench. Deployment to existing devices is scheduled as part of the same order.
Install & Support
The order links to a support ticket from day one, so alerts and questions have somewhere to go immediately, not after a separate onboarding step.
Endpoint & Network Security Software
Four platforms in the catalog, each covering a different layer of the attack surface — the browser, the endpoint, or the network.
DefensX
BROWSER-LAYER ZERO TRUST
Turns the browser itself into the security boundary rather than protecting the device after a threat lands. Built for the reality that most work — and most risk — now happens inside SaaS apps and browser-based AI tools.
- Remote browser isolation for risky web content
- Zero-trust file and credential protection
- DNS-layer and Microsoft 365 protection
- AI Cloud Connector: governs and isolates browser-based AI traffic
Licensed: per user/month, in Core, Core Plus, and Premium tiers. Fit: businesses whose staff live in a browser all day and are adopting AI tools faster than policy can keep up.
SentinelOne Singularity
Autonomous EPP + EDR + XDR
AI-driven endpoint protection that doesn't wait for an analyst to act — it can detect, contain, and roll back a ransomware event on its own, across Windows, macOS, and Linux.
- Behavioral, signature-less threat prevention
- Full attack-path tracing with automated correlation
- Optional Vigilance MDR: SentinelOne analysts triage alerts for you
- Broad compliance coverage: SOC 2, HIPAA, FedRAMP
Licensed: per endpoint/month across Core, Control, and Complete tiers — Core is prevention only, Complete adds the full EDR investigation layer. Fit: businesses that want the strongest autonomous response and can size the tier to their compliance needs.
Webroot (OpenText)
Lightweight Cloud Antivirus
Cloud-native antivirus built to be small on the endpoint and simple to manage across many clients — the long-standing MSP default when the requirement is solid protection without a heavy console.
- Cloud-based scanning with minimal local footprint
- Centralized web console for bulk deployment and policy
- Native integrations with common RMM and PSA platforms
Licensed: per endpoint/year, sold under OpenText since Webroot's acquisition. Fit: cost-conscious environments and older hardware where a heavier EDR agent isn't practical.
WatchGuard EPDR
Endpoint protection, detection & response
Combines traditional antivirus with a Zero-Trust Application Service that classifies every process before it's allowed to run, plus a WatchGuard-managed threat hunting layer watching for what slips through.
- 100% application classification — nothing runs unverified
- Built-in IDS, device control, and URL/content filtering
- Tier ladder: EPP → EDR → EPDR → Advanced EPDR
- Shares WatchGuard Cloud's console with Firebox firewalls
Licensed: per endpoint/year, cloud-delivered. Fit: businesses already running WatchGuard firewalls, since network and endpoint security land in the same dashboard.
Worth pairing: if a WatchGuard Firebox is on order from the Network Products & Services page, adding EPDR licenses puts network and endpoint security in the same WatchGuard Cloud console — one login instead of two, and correlated alerts instead of two separate ones.
Side by Side
All four are commonly deployed together in layers — browser protection, endpoint protection, and network security each cover a different part of the attack surface.
| DefensX | SentinelOne | Webroot (OpenText) | WatchGuard EPDR | |
|---|---|---|---|---|
| Protects | The browser and SaaS access | The endpoint, deeply | The endpoint, lightly | The endpoint, tied to network |
| Detection style | Isolation before threats land | Autonomous AI behavioral detection | Cloud signature & heuristic scan | Zero-trust process classification |
| Response | Blocks/isolates at the browser | Auto-contain and rollback | Quarantine and remediate | Automated containment + human threat hunting |
| Console footprint | Browser extension, cloud policy | Full agent, cloud console | Minimal agent, cloud console | Cloud agent, shared with Firebox |
| Best paired with | Any EDR below — different layer entirely | Businesses wanting the least manual response | Budget-sensitive or legacy hardware fleets | An existing WatchGuard firewall |
Terms You'll See in the Catalog
EPP
Endpoint Protection Platform
The prevention layer — antivirus, behavioral blocking, application control. Stops known and many unknown threats before they execute.
EDR
Endpoint Detection & Response
Sits above EPP: records endpoint activity, detects what prevention missed, and gives tools to investigate and contain it after the fact.
EPDR
Endpoint Protection, Detection & Response
WatchGuard's term for a bundled EPP+EDR product — prevention and investigation licensed and managed as one package.
XDR
Extended Detection & Response
EDR's telemetry extended beyond the endpoint — correlating signals from network, email, and cloud sources into one investigation.
MDR
Managed Detection & Response
A human analyst team, usually the vendor's own, watching the alerts your EDR generates and acting on them — an add-on, not a replacement for the platform.
RBI
Remote Browser Isolation
Risky web content is rendered in an isolated cloud session rather than the local browser, so nothing malicious ever reaches the actual device.
Zero Trust
A security model that verifies every request rather than assuming anything inside the network perimeter is safe by default. Underlies DefensX, SentinelOne, and WatchGuard's approaches, each at a different layer.
Before You License a Large Rollout
Compliance Drives the Tier
If you're bound by HIPAA, PCI, or a cyber-insurance questionnaire, that usually decides which security tier you need before price does. Tell us the requirement and we'll quote the tier that actually satisfies it.
Minimums and Terms Vary
Some platforms carry a minimum seat count or a multi-year term that changes the effective per-endpoint cost more than the sticker tier does. We size this against your actual count before quoting.
License Terms Get Retired
Vendors periodically discontinue a specific license term or SKU in favor of a newer one. If a renewal quote looks different from last year's, that's usually why — ask and we'll confirm the replacement.
Get a Security Licensing Quote
Tell us your endpoint or user count and any compliance requirement you're working against, and we'll quote the platform and tier that fits.