We design and build practical applications that close the gap between business needs and the tools people actually use.
Every StreamSoft data management tool helps you discover, secure, move, or govern your organization's data - built and maintained by StreamSoft, ready to deploy in your environment.
Discover, inspect, and classify sensitive data across file servers, NAS devices, and cloud storage - PII/PCI detection with OCR, risk scoring, ownership insights, quarantine, and full compliance reporting.
Enterprise file server migration made seamless - parallel copies, ongoing mirroring and monitoring, MD5 verification, and full audit reporting for moving data between NAS/SMB servers.
Per-file envelope encryption for data at rest - unique AES-256 keys per file, Windows DPAPI protection with a recovery-key backup path, recursive folder support, and Explorer/CLI integration.
Complete visibility into storage utilization - duplicate files, stale and orphaned data, large files, and file age - with analytics, forecasting, and recommendations to optimize storage costs.
Detailed reports on NTFS and SMB permissions, inheritance, and ownership - compliance-ready documentation that identifies excessive permissions and simplifies permission reviews and audits.
Secure internal and external file sharing with encryption, access controls, expiring links, password protection, audit logging, and activity tracking - a secure alternative to consumer file-sharing platforms.
Analyzes and assesses file and folder permissions to identify security risk - excessive access, broken inheritance, orphaned SIDs, inactive accounts, and privilege escalation - with least-privilege remediation and ongoing governance tracking.
Captures a user's data, personalization, browser bookmarks, application settings, and select credentials into an encrypted package - or transfers them live, machine-to-machine over the network - onto a new or rebuilt PC.
Evaluates files on scanned file-server/NAS paths against retention/lifecycle policies and acts on matches - archive to a configurable location, or permanently delete - with named policies, scheduled unattended runs, and a full audit trail.
Validate - and, over time, discover, issue, and renew - your organization's certificates, from one focused product line.
Scans your network for TLS certificates in use - live endpoints, whole subnets (CIDR), and IP ranges - and builds a single, de-duplicated inventory of every certificate with its issuer, expiry, key strength, SANs, and every location it's deployed on. The discovery step upstream of Validator and Manager, with CSV export, scheduled discovery, and a headless CLI.
Validates certificates from remote TLS endpoints, the Windows Certificate Store, and certificate files - expiry, trust chain, revocation status, key strength, SAN/hostname matching, and policy compliance, with batch validation, scheduled scans, and a headless CLI.
Generates CSRs, completes them once a CA issues the certificate, imports/exports certificates, and diagnoses/repairs broken private-key links in the Windows Certificate Store - with batch CSR generation, custom policy profiles, request history, scheduled key-health scans, and a headless CLI.
Visibility and control over your organization's Active Directory environment - discovery, hygiene, and governance tools built to the same standard as StreamSoft's data and certificate management products.
Domain and forest visibility in one window - FSMO role holders, Domain Controllers, Sites & Subnets, Trusts, OU tree, password policy, schema, and replication health, plus a CJWDEV-style object-reporting browser across Users, Groups, Computers, Contacts, Printers, and Group Policy Objects with custom queries, multi-format export, and scheduled/emailed reports.
See exactly who has what rights on every AD object - Users, Groups, Computers, Containers & OUs, and Group Policy Objects - one row per access control entry, with the trustee, Allow/Deny, rights granted, and whether it's inherited or explicit, plus custom queries, multi-format export, and scheduled/emailed reports.
See who changed what in AD, and when - account lifecycle events, group membership changes (including privileged groups), and Directory Service Changes with the real old and new attribute value, read straight from your domain controllers' own Security event log, plus custom queries, multi-format export, and scheduled/emailed reports.
Find the misconfigurations attackers actually exploit - Kerberoastable and AS-REP-roastable accounts, dangerous delegation, DCSync rights outside Tier 0, and ACL-based escalation paths to Domain Admins - risk-scored (0-100, graded A-F), plus custom queries, multi-format export, and scheduled/emailed reports.
The flagship attack-path scanner - builds a real graph from your domain's own group memberships and ACLs and searches it (up to 6 hops, not a fixed 2-hop check) for every route to Domain Admins, plus a broader Purple Knight-style indicator set (ADCS, GPO delegation, krbtgt age, LAPS) - risk-scored (0-100, graded A-F), plus custom queries, multi-format export, and scheduled/emailed reports.
See what every GPO actually does, where it applies, and fix it - safely. Reads real SYSVOL settings and gPLink link topology nothing else in our suite touches, plus - the first write-capable tool we've built - create/link/edit GPOs through a staged review-before-apply workflow with a full audit trail.
Visibility and control over your organization's network - discovery, access, change auditing, posture, and configuration tools built to the same standard as StreamSoft's data, certificate, and Active Directory management products.
Finds every device on your network - a ping/ARP sweep of a given subnet (or the local one) that resolves hostnames, identifies vendors from MAC OUIs, and probes common ports to build a live host inventory, plus custom queries, multi-format export, and scheduled/emailed reports.
Reports on what your network's Windows Firewall rules actually let in and out - one row per rule, with direction, action, profile, ports, and addresses - and flags the risky combinations (overly permissive rules, no program restriction), plus custom queries, multi-format export, and scheduled/emailed reports.
See who changed your network configuration and when - firewall rule added/modified/deleted, adapter connected/disconnected, IP configuration changes - read straight from your Windows Firewall and System event logs, plus custom queries, multi-format export, and scheduled/emailed reports.
Find the network misconfigurations attackers actually exploit - SMBv1 still enabled, a Telnet server running, RDP without Network Level Authentication, weak public-profile firewall rules, high-risk ports exposed - risk-scored (0-100, graded A-F), plus custom queries, multi-format export, and scheduled/emailed reports.
The flagship network attack-path scanner - builds a real graph from live host reachability (open management ports, subnet/routing topology) and searches it (up to 6 hops) for every route to your critical assets - risk-scored (0-100, graded A-F), plus custom queries, multi-format export, and scheduled/emailed reports.
See what a target machine's network is actually configured to do, and fix it - safely. Reads real firewall rules, IP configuration, routes, and DNS servers, plus - the first write-capable tool in this line - create/edit rules and IP/DNS/routes through a staged review-before-apply workflow with a full audit trail.
Tell us what you're trying to solve and we'll help you figure out the right approach.
Contact us