Nebula RMM is now in private pilot for IT teams. Request a slot →
RMM for businesses & IT teams

Manage your IT in one place.

Monitor, patch, back up and secure every device.

No inbound ports Passkey-signed actions Self-host or managed

One agent, every platform

WindowsmacOSLinuxProxmoxVMwareCiscoFortinet
1
agent for Windows, Linux & macOS
40+
health checks out of the box
0
inbound firewall ports to open
100%
of actions logged & auditable
The platform

From laptops to firewalls to hypervisors.

One lightweight agent and one console, instead of a stack of point tools.

Monitor, patch and remediate endpoints

Inventory, 40+ health checks and automated remediation, from one agent.

  • Hardware, software and logged-in users, continuously
  • Patch in rings with a canary and automatic fail-safe
  • Remediation as typed actions, never a shell
Patch rollout · October3 rings
Ring 1 · Canary
Ring 2 · Standard
Ring 3 · ServersAwaiting approval
Security model

Security built into every action.

Every action is signed, scoped to one tenant and verified on the device. Control of the server never means control of your machines.

Mutual TLS, pinned per device

Each agent carries its own certificate and pins Nebula's CA, so nothing can impersonate the server.

Typed jobs, never a shell

A fixed set of typed actions behind a local allowlist. No arbitrary commands, ever.

Passkey-signed approvals

Risky actions need a passkey signature, verified on the device itself.

Tenant isolation, server-side

Every request is re-checked against the signed-in tenant. Cross-tenant access returns "not found".

Immutable backups

Backups land in Object Lock storage that can't be deleted before its retention date.

Own the source, host it yourself

Run it on your own infrastructure and hold your own keys. Nothing phones home.

Why Nebula

Built for the team that runs its own IT.

One inventory, one console, one bill for everything you run.

Everything in one view

Laptops, servers, switches, firewalls and hypervisors, side by side. No tool-hopping.

Secure by design

mTLS, typed jobs and passkey-signed approvals mean a breach of the server can't be turned on your machines.

Pay for what you switch on

A per-device core with monitoring, patching, network and virtualization built in. Backup and remote access are yours to add.

Self-host or managed

Run Nebula on your own infrastructure and hold your own keys, or let us host it for you. SSO and SCIM either way.

Pricing

Start with the RMM. Add what you need.

A per-device platform. Add backup and remote access only if you need them.

Core platform Nebula RMM

Per device

Per device/ month

Everything you need to monitor and run your IT.

  • Monitoring, alerts & patching
  • Remediation & automation
  • Network & virtualization
  • Service desk & reporting
Get a quote
Add-on

Nebula Backup

Per device/ month · storage included

Priced by what it protects, with pooled storage included.

  • Tiered for workstations & servers
  • Microsoft 365 billed per user
  • Pooled storage, no per-GB overages
  • Immutable image & file backup, boot-verified
Add to quote
Add-on

Nebula Remote

Per tech/ month

Remote access, licensed per technician.

  • Web terminal & file transfer
  • Remote view with on-device consent
  • End-to-end encrypted
  • Full session audit
Add to quote

Volume pricing on request. Network devices and hypervisors are licensed per managed node. Self-host or managed.

Questions

Good to know

Do I have to open firewall ports for the agent?

No. Agents and the probe dial outbound over mutual TLS, so nothing is exposed inbound at a managed site.

What's in the base RMM versus the add-ons?

The per-device platform covers monitoring, patching, automation, network, virtualization, the service desk and reporting. Backup and remote access are separate products, so you only pay for what you turn on.

What can Nebula manage besides Windows laptops?

One agent covers Windows, Linux and macOS. Beyond endpoints, Nebula also manages network gear and hypervisor clusters, and backs up Microsoft 365.

Can we host Nebula ourselves?

Yes. Run the server and the remote-access relay on your own infrastructure, so you hold your own keys and data. A managed option is available too.

How is this different from a traditional RMM?

The security model. The agent only runs typed jobs behind a local allowlist, risky actions need passkey-signed approvals verified on the device, and every tenant boundary is re-checked server-side, so control of the server never means control of your endpoints.

See Nebula in action.

Book a live walkthrough on real Windows, Linux, network and hypervisor devices.