PrayPatch

End-to-End Patch Management — Windows, Linux, macOS & Network Devices

One console for discovery, CVE prioritization, patch policy, approvals, deployment, verification, and compliance reporting — deployed on your infrastructure. Ansible as the execution engine; Praytec handles install & support.

🛡️

Not cloud SaaS — client-owned on-premise platform — patch state and audit trails stay on your servers. Integrates with PrayWatch, PrayMesh, and the rest of the Praytec stack.

Core capabilities

Full Patch Lifecycle — Not Just Ansible Scripts

From knowing which hosts are vulnerable to audit evidence for ISO — all in one operational platform.

📡

Discovery & Inventory

Outbound-only agents for Windows, Linux, and macOS — plus network device import from NetBox or Ansible inventory.

🔴

CVE Prioritization

NVD feed sync — see which patches are urgent, which hosts are affected, and prioritize remediation by business risk.

📋

Policy & Scheduling

Per-group rules: prod vs dev, auto vs approval required, maintenance windows, reboot rules — one model for the whole fleet.

Dry-Run & Approval

Preview impact before execution — approvers see change summaries, comments, and a full audit trail.

⚙️

Ansible Orchestration

Praytec-curated playbooks for apt/dnf, Windows Update, and vendor firmware — scheduled jobs, stored logs, automatic retries.

🔌

Network Devices

Juniper, Cisco, and multi-vendor upgrade templates via Ansible — pre-check, staged rollout, post-check for high-risk changes.

🔍

Verification & Rollback

Post-patch version checks, health probes, and rollback hooks — failed hosts stay visible, not lost.

🧾

Compliance Reports

Patch SLA dashboards, CSV/PDF export for auditors — proof of who approved, who ran, and the outcome.

🏢

Multi-Site & RBAC

HQ, branches, and DMZ — operators, approvers, and viewers with role-matched access.

Supported platforms

One Policy — Many Targets

Target Method Example use case
Linux (deb/rpm/apk)Agent + AnsibleWeekly security updates on PrayERP & database servers
Windows Server & ClientAgent + win_updatesCritical KB patches without a separate WSUS stack
macOSAgent + Munki integrationOffice app patches; OS updates via MDM (later phase)
Router / Switch / FirewallAnsible vendor modulesJuniper/Cisco firmware in maintenance windows
FreeBSDAgent pkgEdge & proxy servers
Use cases

For IT, Security, and Network Ops Teams

⏱️

CVE Patch SLA

7/14/30-day targets after CVE publish — dashboard shows SLA violations before auditors arrive.

🌙

Maintenance Windows

Patch prod Tuesday 02:00, dev auto — no surprise midday reboots.

🔗

PrayWatch Integration

Failed job webhooks → monitoring alerts — correlate patch events with infrastructure logs.

🔐

Air-Gap Friendly

Offline CVE bundles & Ansible collection sync — suited for isolated environments.

📉

Reduce Tool Sprawl

Replace WSUS + SSH scripts + spreadsheets with one operational console.

🤝

Praytec Deploy & Support

We install the control plane, harden it, ship initial playbooks, and train your team — same as PraySmart & PrayWatch.

Explore further

Related Services in the Praytec Ecosystem

👁️

PrayWatch

Alert on failed patch jobs; monitor host health after post-patch reboots.

🔐

PrayMesh

Secure access to agents & Ansible runners at branches without inbound ports.

📊

PrayERP

Patch business application servers on schedules aligned with ERP operations.

PrayPatch plans

Patch Management Pricing

Scaled by endpoint count & network devices. Setup & onboarding by the Praytec team.

Starter

Up to 25 endpoints · small business

Rp3.500.000/month

Setup Rp 8 million

  • Linux & Windows patch visibility + deploy
  • Policy & maintenance windows
  • Basic CVE dashboard
  • Approval workflow
  • Business-hours support
Consult on Plan

Scale

150+ endpoints · enterprise / air-gap

Rpcustom scope

Setup custom scope

  • Unlimited fleet & HA control plane
  • Air-gap CVE sync & custom playbooks
  • SSO & granular RBAC
  • 99.9% SLA · 24/7 support
Contact Us

Centralized Patch Management — Without Spreadsheets & SSH Marathons

Tell us about your IT fleet — we'll design patch policy, deploy PrayPatch on-premise, and train your ops team.

Lowest Price Guarantee

Found a Lower Price Online? We'll Match It.

Praytec guarantees the best subscription pricing for ERP, cloud phone, and PrayInbox. Find a lower public offer for comparable scope — send proof, and we'll adjust our price.

  • Search & compare prices online (comparable service & scope)
  • Send the link or price proof to the Praytec team
  • We review — if valid, we adjust your subscription price
Claim Price Guarantee
Risk-Free

Try First · Production First · Then Subscribe

No upfront subscription fees. Tell us your needs — we set everything up. You test, run in production, and only start subscribing when everything meets your expectations.

See the full process →