Self-hosted Mac fleet management

Own your Mac fleet. Every device, every byte.

Deploy software, enforce compliance, and support every Mac in your organisation from one console you host yourself.

Built onMunkiToolsDockerPostgreSQLSelf-hosted edition · FSL-1.1-ALv2
ownmdm.com/dashboard
ownMDM cross-tenant dashboard with fleet canvas, tenant health and 14-day trends
$0per-seat fees, ever
100%your data, on your servers
10 minfrom docker compose up to a running console
The platform

Everything modern Mac management needs.

Four chapters — deploy, monitor, scale, prove. Every screen on this page is the shipping product, annotated as you scroll.

Deploy · 01

Your whole library, one click from your catalog.

The marketplace counts everything for you: 1 title already in this tenant's catalog, 10 more available to request, nothing pending. MunkiTools does the installing — the console does the deciding.

  • MunkiTools agent — Swift-compiled, no Python runtime on the client
  • Production and testing catalogs, side by side
  • Munki installs; the console decides
Deploy · 02

Your catalog, or the whole library.

Admins browse the shared library and request titles into their own tenant. Requests land in an approval queue, not a shared spreadsheet.

  • Approval queue with named approver
  • Scoped per tenant and per department
  • Every request written to the audit log
Deploy · 03

Versioned, categorised, ready to push.

1Password 8.10, Figma 124.6, Google Chrome 131 — every title carries its version, vendor and category, then flows into production and testing catalogs.

  • Smart groups auto-assign by criteria
  • Per-department & per-device manifests
  • Signed, notarized PKG pipeline
ownMDM app marketplace
App marketplacetenant: northwind
0In catalog
0Available
0Pending
0Library
Global library syncedjust now
autopkg recipe run4 new versions
Browse the libraryavailable to request
Your catalogAvailable to Request (10)
1P
1Password
v8.10.50 · Security
Request
Af
Figma
v124.6.2 · Design
Request
Ad
Google Chrome
v131.0.6778.86 · Browsers
Request
Push to devicesproduction catalog
Sl
Slack 4.39.0
production · site_default
42 devices
makecatalogsrebuilt
manifest updatedmanaged_installs
Live walkthrough ·
Monitor · 01

Open a Mac. See all of it.

Chip, model, memory, storage and battery on one card; hostname, macOS 15.2, Munki 6.6.1 and last check-in on the next. Assigned to i.rossi in Design.

  • Hardware, OS, Munki and network on one sheet
  • Inventory refreshed at every check-in
  • Assigned user, department and site tracked
Monitor · 02

Security posture, evaluated every check-in.

FileVault is off on this Mac, so it is flagged Non-compliant on the device page with the reason written out — “FileVault disk encryption is turned off” — not left for an auditor to find.

  • FileVault, SIP and firewall evaluated at every check-in
  • Failures flagged red, never buried
  • Remediation pushed as a managed policy
Monitor · 03

Trust that expires on purpose.

Each device holds a rotating trust token — trusted, 29 days left, revocable in one click. The same token gates check-in, helpdesk and the self-service portal.

  • CPU, RAM, storage and battery trended per device
  • FileVault, Gatekeeper, SIP, firewall, SSH, auto-login
  • One revoke kills check-in, helpdesk and portal access
Monitor · 04

Then act, without leaving the page.

Start a remote session, open a terminal, or push an install from the same device page — RustDesk with a native VNC fallback, and a browser terminal that reaches the Mac over your own overlay network. Actions queue and run at the device’s next check-in.

  • One-click remote control, VNC fallback built in
  • Browser terminal over your overlay — no port forwarding
  • Every action written to the append-only audit log
ownMDM device drawer
Ivy’s MacBook Prodevice overview
SerialC02PT6Y1VM5C
macOS15.2
Munki6.6.1
Last seen5 days ago
Storage765 GB of 1 TB · 100%
Security & healthevaluated at check-in
GatekeeperEnabled
SIPEnabled
!FileVaultDisabled
!FirewallDisabled
!Remote login (SSH)On
Device trustrotating token
29d
Trusted
expires in 29 days · auto-rotates
Revoke
Check-inauthorised
Helpdesk sessionauthorised
Self-service portalauthorised
Remote supportfrom the device page
Remote controlRustDesk · VNC fallback
›_Browser terminalover the overlay
Push installqueued · next check-in
Recover trust tokenre-issue
Live walkthrough ·
Scale · 01

Six preflight checks, per tenant.

Repo directory, 26 manifests, site_default present, client-resources ZIP built, check-in freshness, plan capacity. Tenant health is a status, not a hunch.

  • Six preflight checks run per tenant
  • Repo, manifests and client resources verified
  • Plan capacity and check-in freshness watched
Scale · 02

Isolation you can read off the screen.

Own subdomain, own Munki repo path, own catalog, own auto-enroll policy, own package count — row-level isolation on every model behind it.

  • Wildcard SSL with subdomain routing
  • Per-tenant catalog and auto-enroll policy
  • Row-level isolation on every model
Scale · 03

A branded installer, built on demand.

Build a signed .pkg or a plain .sh for any tenant or department, with client resources rebuilt from the template — templates, banners and CSS included.

  • Row-level tenant isolation, cross-validated JWTs
  • Subdomain routing with wildcard SSL and SSO
  • Self-hosted edge nodes cache packages near each site
ownMDM tenant drawer
Tenant healthdefault.ownmdm.com
Tenant repo directory/munki_repo
Manifests directory26 manifests
site_default manifestpresent
Client resources ZIP1547 KB
!Check-in freshnessno devices yet
Plan capacityUnlimited
Configurationrow-level isolation
Subdomaindefault.ownmdm.com
Repo path/munki_repo
CatalogChoudhary
Enrollmentauto-enroll on
Packages4
ActiveAuto-enrollWildcard SSL
Tenant installerbuild on demand
Building signed .pkgarm64 + x86_64
Build completeDownload .pkg
Client resources rebuilttemplates · banners · CSS
Live walkthrough ·
Prove · 01

30 events nobody can edit.

“Immutable record of administrative actions.” The append-only guarantee is enforced by the database, not by good intentions in the UI.

  • Append-only enforced by a DB constraint
  • 30 events, retained and exportable
  • No UI path can rewrite history
Prove · 02

Filter the way auditors ask.

By resource — requests, packages, manifests, devices, users — by actor username, by tenant slug, by action, over any window. Then export CSV.

  • Filter by resource, actor, tenant or action
  • Any time window, down to the minute
  • CSV export straight into your GRC pipeline
Prove · 03

Typed actions, graded severity.

device.action.restart, request.approved, package.promoted — machine-readable names with before→after diffs, each on a four-step severity ladder.

  • DB-enforced immutability, 365-day retention
  • Actor, tenant, resource and target on every row
  • CSV export straight into your GRC pipeline
ownMDM audit log
Audit logappend-only
0Events
0Day retention
0Edits possible
device.action.restart1 day ago
request.approved5 days ago
package.promoted5 days ago
Filtersask like an auditor
AllRequestsPackagesManifestsDevicesUsers
Actordemo-admin
Tenantnorthwind
WindowLast 30 days
Export CSVExport
Typed actionsseverity + diff
device.action.restart
request.approved
package.promoted
Before → after
department: Design · actor demo-admin
Live walkthrough ·
Deploy

One command. Production ready.

Docker Compose brings the whole stack up on any Linux host you already own.

Terminal — zsh
$ curl -fsSL https://get.ownmdm.com/stack | sh   # fetches compose.yml
$ cp .env.example .env   # domain · DB password · JWT secret
$ docker compose up -d

 postgres        healthy
 redis           healthy
 api             healthy   :8000
 admin           healthy   :3000
 munki-repo      serving   /munki_repo · munkitools.pkg
 rustdesk-relay  listening
 prometheus · grafana · loki  up

→ open https://default.ownmdm.com  · enroll your first Mac
Security & compliance

Built to pass your security review.

Seven security audits and counting. The controls your security team asks about are built in — not bolted on.

Tenant isolation

Row-level isolation on every model. JWTs cross-validated against tenant context on every request.

Granular RBAC

Six roles with per-scope manage and view, department scoping, and cross-tenant predicate gates.

Device trust tokens

Rotating tokens authenticate check-in, helpdesk and portal. One revoke kills all three.

Append-only audit log

Database-enforced immutable trail with before→after diffs and 365-day retention.

SSO & SAML 2.0

LDAP, SAML and local auth with lockout, backoff and must-change-password flows.

Your infrastructure

Self-hosted via Docker Compose on hardware you control. Your data never leaves your network.

Capabilities

Everything you need.

Smart groups

Dynamic segments by OS, serial, department or custom attributes.

SSO

SAML 2.0 today, bring your own IdP. Okta, Azure AD and Google Workspace presets on the roadmap.

Branding

White-label the portal with your organisation's identity.

Webhooks

Real-time event streams to any downstream system.

AI assistant

Ask questions about your fleet and your runbook, answered from your own docs.

Compliance

FileVault, SIP, Gatekeeper and firewall checks, with per-device remediation.

Self-service catalog

Managed Software Center — customisable sidebar, and the macOS 26 look on macOS 26.

Remote control

RustDesk sessions with a native VNC fallback.

Edge distribution

Self-hosted edge nodes cache packages close to each site.

REST API

Automate every resource programmatically.

Monitoring

Prometheus, Grafana and health dashboards in the box.

OS upgrades

Munki’s stage_os_installer, on Intel and Apple silicon, staged per group.

Pricing

Plans launching soon.

Free up to 5 devices, self-hosted, forever. Paid tiers are being finalised — no per-seat fees on any of them.

Starter · free

Free forever

up to 5 devices
  • Munki catalog
  • RBAC + audit log
  • Self-hosted on your hardware
  • No card, no time limit
  • Community support
Read the self-hosting guide
Business · popular

Coming soon

up to 25 devices
  • SSO (SAML 2.0)
  • Compliance policy engine
  • Remote sessions (RustDesk)
  • Webhooks & API keys
  • Founder-led support
Request access
Enterprise

Coming soon

up to 50 devices
  • Multi-tenant management
  • White-label branding
  • Per-tenant RBAC
  • Tenant 2FA enforcement
  • Customer-visible audit log
Request access
Enterprise Plus

Coming soon

50+ devices
  • Custom integrations
  • On-premise option
  • Migration support
  • Custom SLA terms
  • Everything in Enterprise
Talk to us
Beta — design partner program open

Be one of our first design partners.

ownMDM is pre-launch. We're looking for three to five Mac IT shops — 25 to 50 devices each, one per industry — to use the platform daily and shape v1 with us.

Free year one, then half price for life

The 50-device tier, free for twelve months. When pricing launches you pay 50% of it — for as long as you stay a customer, not just year two. We do the install for you, remotely.

Direct line to the founder

A 30-minute call every week for the first month, fortnightly after that. Slack or email reply the same business day.

Your voice on the roadmap

Design-partner bug reports and feature requests ship before anything else.

Referenceable — if you want

After six months, opt in to be quoted here, or stay private. Your call.

15-minute intro call · three to five partners · one per industry.

Frequently asked.

How does ownMDM compare to Jamf Pro?+

ownMDM is self-hosted with predictable flat pricing, and its package management is built on MunkiTools — which many teams already rely on. Jamf has a bigger feature surface; we trade some of that breadth for control, cost and data ownership.

How long does setup actually take?+

With Docker Compose, a working instance is typically online in 10–15 minutes. Enrolling your first device adds roughly another 20 minutes.

Can I run it fully on-premises?+

Yes. ownMDM runs on any Linux host with Docker. Device management is agent-based, built on Munki, so it does not depend on Apple's MDM or APNs infrastructure — the only outbound traffic is whatever you point it at for software sources.

Which macOS versions are supported?+

macOS 12 Monterey and newer. The agent is MunkiTools, Swift-compiled with a macOS 10.15 deployment target — upstream testing focuses on macOS 14 and later. Apple’s Declarative Device Management is on our roadmap, not shipped today.

Does it support SSO?+

Yes — SAML 2.0 on the Business and Enterprise plans. Pre-wired integrations for Okta, Azure AD and Google Workspace are on the roadmap; bring-your-own-IdP via SAML works today.

How do I get started today?+

ownMDM is pre-launch. We’re looking for three to five Mac IT shops as founding design partners, one per industry: the 50-device tier free for twelve months, then 50% off the launch price for life, white-glove onboarding, and a call every week for the first month then fortnightly. Email hello@ownmdm.com.

Ready to own your fleet?

Pre-launch. Free for a year, then half price for life. Your instance, your data.