Discovery Edition

Your remote workforce runs on networks your security stack can't see

EDR sees the work laptop. MDM sees the work laptop. The router, the NAS, the smart TV, the IoT camera, the kid's tablet on the same Wi-Fi as that laptop, none of them. Discovery finds every device on every remote network your team touches, scores the risk, and tells you what to fix first.

From $20 per user / month. Up to 10 users.

The blind spot

Your security stack sees the work device. It does not see the network around it.

Every remote employee sits on a network full of devices nobody on the security team has ever inventoried. A router the employee never patched. A NAS in the corner. A USB hub with a network chip. A smart TV. An IoT camera. A family tablet on the same Wi-Fi. Each one is a potential foothold to the work device.

EDR and MDM see the corporate laptop. They see nothing else on the network. Discovery sees every device on every remote network your team touches, scores the risk, and tells you which devices need attention first.

What EDR and MDM see
Work laptop
1 device
What's on the remote network
Laptop
Phone
Router
Speaker
Printer
TV
IoT
NAS
8+ devices

What's included

The full platform, capped at ten remote users

Discovery is the same core platform every 4Remote customer uses, sized for B2B small businesses with up to ten remote employees. Not a stripped-down version.

Auto device discovery

Every device on every remote network your employees connect from. Computers, networking, phones, audio, TVs, gaming, printers, IoT, peripherals, and the unmanaged stack on the same Wi-Fi.

Software scanner

Continuous visibility into active, connected devices. No agent rollout required to start.

Per-device and per-user risk scoring

A 0 to 10 score for every device and every user, with trend over time.

CVE-level vulnerability tracking

Full CVSS 3.1 breakdown, CWE classification, attack vector, and authoritative references on every CVE.

CISA Known Exploited Vulnerabilities

Cross-referenced against the CISA KEV catalog. The vulnerabilities attackers are actively using, surfaced first.

Blast Radius

18+ named CVE chains, including the MOVEit chain used by Clop, ProxyShell, Log4Shell, WannaCry, and PrintNightmare.

Five remediation strategies

CISA Critical First, CISA Most Affected, Worst Devices, Bad Device Owners, Worst Users. Pick the strategy that fits your constraints.

Ten-state Zero Trust posture

Trusted, Privileged, Standard, Restricted, Limited, Monitored, Quarantined, Suspended, Blocked, Denied. Applied to both devices and users.

Maxwell AI remediation

Plain-English, step-by-step update guidance tailored to each device and OS. Drops first-line ticket volume.

16+ compliance frameworks

CMMC 2.0, NIST SP 800-171 and 800-53 Rev 5, PCI-DSS v4.0, ISO 27001:2022, FedRAMP, SOC 2, HIPAA, NIS2, DORA, and more, continuously evaluated.

FCC Covered Devices detection

Hikvision, Huawei, and other prohibited hardware automatically identified.

Zero Trust Network Access

Identity, device posture, and contextual access. Included in every plan.

Self-serve at speed

Up and running in under ten minutes

Sign up online. Scan a remote employee's network. See the risk. The first three steps take less time than a coffee break.

Two minutes

Sign up

Pay by card. No quote. No procurement cycle. No sales call. Get straight into the platform.

Five minutes

Run a scan

The software scanner installs on any Windows or macOS work device. It maps every device on the remote network around that device automatically. No configuration required.

Immediate

See your risk

Devices populate as they are detected. Risk scores, CISA KEV flags, and Maxwell remediation guides appear as soon as scanning starts.

Maxwell AI

Your remote employees become their own first-line IT support

Most security tools tell IT what is wrong and leave IT to translate it for the user. With a remote workforce, that translation is the bottleneck. Maxwell skips it.

Maxwell generates step-by-step update instructions tailored to each employee's exact device and OS. Plain English. Backups before updates. Rollback paths included. The 80% of users who would never read a CVE advisory will read a Maxwell guide.

For a small business running on remote employees and no dedicated security person, this is the difference between Discovery working and Discovery sitting unused.

M
Maxwell
AI remediation assistant
MacOS 26.3 update guide for beginners
  1. 1Back up your MacConnect your Time Machine drive and run a backup. Takes 10 to 30 minutes.
  2. 2Check compatibilityOpen System Settings, then General, then About. Confirm your Mac model supports macOS 26.3.
  3. 3Run the updateSystem Settings, General, Software Update. Click Update Now. The Mac will restart twice.
  4. 4Verify the installAfter restart, the About panel should show macOS 26.3. Your security baseline is restored.
CVE-2023-34362
CVE-2023-35036
CVE-2023-35708
Clop ransomware chain Blast Radius 8.52
Edge device
File server
Data

Blast Radius

Eighteen ransomware chains, included at twenty dollars

Every recent breach started on an unmanaged device near the target. LastPass cost $53M and started with an unpatched media server on a senior engineer's network. CVE-2020-5741. The corporate stack never saw it.

Discovery includes the full Blast Radius engine. Eighteen confirmed exploit chains, including the MOVEit chain used by Clop, ProxyShell, Log4Shell, WannaCry, PrintNightmare, and the Cisco IOS XE zero-day chain. Each chain is named, attributed to the threat actor that used it, and scored against the devices on your remote workforce's networks.

The kind of threat intelligence usually priced at enterprise tier, on a self-serve plan capped at ten users.

Compliance from day one

Sixteen-plus compliance frameworks, evaluated continuously

Small businesses with remote workforces get hit with the same compliance pressure as large ones. A HIPAA audit, a SOC 2 deadline, a customer asking for ISO 27001 evidence covering every device a remote employee uses. Discovery evaluates against 16+ frameworks continuously, with per-control mapping and failing-device counts.

Audit evidence is a live state of the platform, not a quarter-end scramble.

4Remote
24/7

Hardware Scanner

24/7 monitoring for higher-value remote employees

The software scanner only sees the remote network when the work device is powered on and connected. For an executive, an engineer, a finance lead, or anyone in a regulated role, that gap matters. The Hardware Scanner is a persistent sensor that ships to the remote employee, plugs into their network, and runs 24/7 regardless of whether the work device is on. It sees every device on the network, including the ones nobody remembers are connected.

Available as an add-on per remote employee with any Discovery plan. Use it on the people whose access matters most.

Talk to us about the Hardware Scanner →

Discovery pricing

Discovery

Up to 10 remote users. Zero Trust network access plus full visibility into every device on every remote network your team touches.

Monthly Yearly Save 15%
$23.53 $20
per user / month
Billed annually. Save 15%.

What's included

  • Zero Trust Network Access
  • Software scanner across every remote network
  • Blast Radius (18+ named CVE chains)
  • Maxwell AI remediation guidance
  • 16+ compliance frameworks
  • Community and ticketing support

Sign up online. No sales call required. Cancel any time.

Try Discovery

Three ways to see Discovery before you sign up

Lowest commitment

View live demo data

Sign in to a populated demo environment and click through dashboards, blast radius chains, compliance views, and Maxwell remediation guides. Real data, no install, no conversation required.

Time. Two minutes.

View live demo data
Hands-on

Start a free trial

Install the software scanner on one of your remote employees' work devices. See the real devices on that remote network, the real CVEs, the real Blast Radius exposure. No payment required to start.

Time. Results in the first scan.

Start your free trial
Have a specific question

Talk to us

Five-minute call with a real person, no slideware. For questions about pricing, deployment, or whether Discovery fits your remote workforce.

Time. Same-day response.

Talk to us

FAQ

Common questions

What if I have fewer than 10 remote employees? Do I still pay the full price?
Discovery is priced per user. Pay only for the remote employees you onboard. A team of four pays for four users, not ten.
Can I buy Discovery without a sales call?
Yes. Discovery is fully self-serve. You can sign up, pay by card, install the scanner on a remote employee's work device, and run your first scan without speaking to anyone at 4Remote. Sales calls are available if you want one, but they are not part of the buying flow.
Can I upgrade to Business later if we grow past 10 remote employees?
Yes. Discovery customers migrate to Business with the same data and configuration. No re-onboarding. Business adds Cisco Meraki integration, multi-location asset discovery, REST API, MCP, and Slack/Teams integrations on top of everything Discovery already includes.
What does Discovery actually see on a remote employee's network?
Every device on the same Wi-Fi as the work device. The router, the NAS, the smart TV, the IoT camera, the printer, the family tablet, the gaming console, the USB hub with a network chip. Every device gets a 0 to 10 risk score and a CVE breakdown. EDR and MDM see only the work device. Discovery sees everything around it.
Does this feel intrusive to my remote employees?
No. The software scanner inspects the network, not the contents of personal devices. It identifies what devices exist and whether they are patched. It does not access photos, messages, files, or any user data on those devices. Maxwell explains every scan result to the employee in plain English so they understand what is being checked and why.
Do I need a security team to use Discovery?
No. The platform is built so remote employees can fix their own devices via Maxwell AI. Most Discovery customers operate the platform with one or two part-time admins, not a dedicated security person.
Does Discovery really include the same Blast Radius and compliance features as Enterprise?
Yes. The core platform is the same. Discovery differs from Business and Enterprise in user cap, support level, and advanced integrations such as SIEM, REST API access, and the MCP connector.
What support do I get on Discovery?
Community support, online help, and ticketing. Phone support and dedicated account managers are on higher plans.
How long does setup take?
Most teams are scanning their first remote network within ten minutes of signing up. Sign up takes about two minutes. Installing the software scanner on a remote employee's work device and running the first scan takes another five to seven. Results appear immediately as devices are detected.

Work with Us

Talk to our team

Whether you want to see 4Remote in your own environment, talk through pricing, explore a partnership, or ask us something else entirely, we're ready to respond. Tell us what you need and the right person will come back to you directly.

  • Request a demo. Deployed into your real environment with results visible in the first scan
  • Talk to sales. Straight answers on pricing, editions, and what fits your organization
  • Partner enquiry. Routed to our channel team to discuss reseller, MSP, MSSP, or white-label options
  • Contact us. Any other question, answered by someone who knows the product
  • UK and US coverage. Real people responding across both time zones

Ten remote users. Every network they touch. Up and running in ten minutes.