SLM Stratum is a read-only, offline Windows endpoint auditor that surfaces hidden credentials, SSH keys, developer backdoors, and data exposure risks that antivirus, EDR, and vulnerability scanners are not designed to surface.
We're not aware of another tool that combines read-only, air-gapped, offline endpoint auditing with this depth of data exposure detection in a single portable executable — no installation, no network connection, no configuration.
Patent Pending GB2610997.5 · SLM-AI Solutions Ltd · United Kingdom
Multiple detection modules. Findings are genuine and triaged by severity. Minimal false-positive noise.
Reveals the USB storage devices that have been connected to the endpoint — device name, serial number, last connection time, and whether it was connected outside business hours. Flags unknown or unauthorised devices. Critical for data loss prevention and compliance audits.
Locates unprotected SSH private keys stored on endpoints — a direct route to servers and infrastructure.
Detects orphaned scripts with hardcoded credentials, authentication bypasses, and obfuscated execution — left by contractors years ago.
Finds hardcoded passwords, API keys, and cloud credentials written directly into configuration files and scripts.
Detects ngrok, frp, chisel, and other tools that create hidden outbound tunnels bypassing firewalls.
Identifies TCP ports actively listening on non-standard ports that don't belong to any known legitimate service.
Detects unknown root CAs installed in the Windows trust store — enabling silent SSL interception of all traffic.
Hunts for private keys, certificate bundles, .pfx files, .env files, and cloud credential files left on endpoints.
Detects fileless WMI event subscriptions — a favourite persistence technique that survives reboots without files on disk.
No installation. No network access. No configuration. Just run it. Typically completes in under 10 minutes.
Purchase online. Your licence key and executable arrive by email instantly.
No installation required. Copy the exe to your endpoint.
Right-click, run as administrator. The audit typically completes in under 10 minutes.
PDF, HTML, Excel and JSON reports generated automatically. Hand the PDF straight to your client.
Stratum retrieves the USB device connection history from the Windows registry — each storage device on record, its serial number, device name, and the exact date and time it was last used.
Connections made outside normal business hours are automatically flagged. If an employee is copying data at 11pm on a Sunday, Stratum will find it. Essential for GDPR compliance, data loss prevention, and insider threat investigations.
One licence. One device. 30 days. Buy as many as you need.
£250 per licence regardless of quantity.
A subscription option is in development for MSPs who'd rather pay monthly than per licence.
Register your interest →We'll let you know the moment it's live.
The process is identical to your previous purchase. Simply complete the checkout above and your renewal key will be delivered automatically to your registered email address within minutes — no software re-download required. Your device is already configured; just paste the new key at the activation prompt and you are ready to go.
Stratum never modifies, deletes, or alters any file on the scanned device. Completely safe to run on live production systems.
Runs entirely offline after a one-time activation. No internet connection needed on the target device. Suitable for air-gapped environments.
SLM Stratum is a proprietary forensic architecture developed by SLM-AI Solutions Ltd. Patent Pending GB2610997.5.
SLM Stratum is Extended Validation (EV) code signed by SLM-AI Solutions Ltd. The publisher is cryptographically verified, so Windows shows the signed company name rather than an "unknown publisher" warning. As with any newly issued certificate, SmartScreen reputation builds over time, and any initial prompt clears as the signature becomes established.
No. Stratum is a single portable executable. Copy it to a USB drive, plug in, run as administrator. Nothing is installed on the target machine.
Stratum is read-only and uses no offensive techniques. It reads files and registry keys the same way any administrator would. Because it inspects security-sensitive areas, some AV or EDR products may flag it on first run, which is expected for forensic tools. It is EV code signed by SLM-AI Solutions Ltd, so you can verify the publisher, and any initial SmartScreen prompt clears as the certificate’s reputation builds.
No. The audit runs entirely offline. The only network call is a one-time licence activation when you first run it. No scan data, file contents, or findings are ever transmitted.
Each licence covers one device for 30 days, starting from the moment it is first activated on that device. The key is single-use and device-locked. You can purchase licences in bulk and hold them in reserve — the 30-day clock only starts when the key is first used. Unused keys do not expire.
After the audit, four report files are saved to the same folder as the executable — PDF (client-facing executive summary), HTML (full technical detail), Excel (filterable data), and JSON (for integration). Email the PDF to your client.
Licence delivered by email. Running in minutes.
Get Your Licence →