Bastion pangolin

Endpoint security
for schools and hospitals.

EDR with HIPAA and FERPA compliance built in. One agent, one console, $5/endpoint/month.

14-day free trial · 25 endpoints · No credit card required

Compliance-native

Your HIPAA audit is in 3 weeks.
The report is already done.

Every other EDR vendor gives you raw log exports and says "good luck." Bastion generates the compliance evidence directly, because the controls are built into the product, not bolted on afterward.

  • HIPAA compliance dashboard

    Live compliance score, control checklist with remediation steps, PHI access timeline. One screen, everything an auditor needs.

  • FERPA control checklist

    14+ FERPA controls tracked with live status. PII detection timeline showing every student record access event, filtered, searchable, exportable.

  • PHI encrypted at rest

    AES-256-GCM encryption for all PHI with key rotation. Not a config option. Satisfies HIPAA §164.312(a)(2)(iv) out of the box.

  • Tamper-evident audit trail

    Hash-chained audit logs. Every admin action is signed, linked, and verifiable. Satisfies HIPAA §164.312(b). Export for auditors in one click.

  • Breach notification workflow

    Generate a draft breach notification report from within the console. No consultant required for the first draft.

The industry standard
"Compliance is a shared responsibility. You are responsible for configuring controls, maintaining audit workflows, and producing compliance evidence for your regulatory framework."
Paraphrased from typical EDR vendor shared responsibility documentation
Compliance burden stays on your team
Bastion EDR

HIPAA score is on your dashboard the moment you log in. FERPA PII detections are logged, tagged, and ready to export. Compliance is a feature, not an integration project.

Compliance built into the product
The gap

The tools that could protect you weren't built for your budget.

79% of higher-ed institutions were hit by ransomware last year. The average healthcare breach costs $10.9 million. The security tools that stop this are priced for Fortune 500 companies.

100
Device cap
Affordable tiers cap you out

Legacy EDR vendors cap their affordable tiers at 100 devices. Every school district and small hospital runs 500-2,000 endpoints. The next tier up: $100-$185/device/year. A 1,000-endpoint district: $100,000/year.

$180
Per endpoint / year
Full EDR costs full enterprise pricing

Entry-tier plans don't include real EDR. For detection, response, and forensics, you need the premium tier. 1,500-endpoint community hospital: $270,000/year. Compliance dashboards are still your problem.

0
Native compliance dashboards
Compliance is always out of scope

No major EDR vendor ships a HIPAA compliance score, a FERPA control checklist, or a breach notification workflow. They sell you security. Compliance reports are a consulting engagement, $8,000-$24,000/year extra.

Full platform

One agent. One console. One bill.

Replaces your separate AV, SIEM connector, compliance tool, and audit log solution.

Rust-native agent

Less than 0.5% CPU at idle. No JVM, no Electron, no Python runtime. Runs on 2016 hardware your students are already pushing hard.

Real-time threat detection

YARA rule scanning, behavioral analytics, memory injection detection, script analysis. MITRE ATT&CK coverage mapped live.

Auto-response playbooks

Detect ransomware, isolate endpoint, quarantine file, kill process, notify IT, open Jira ticket. Automated for known threats.

Native SIEM integration

Splunk HEC, Elasticsearch, and Microsoft Sentinel connectors built in and tested. No middleware, no custom scripts.

Network isolation & USB control

Isolate a compromised endpoint with one click. Block USB writes by policy. Recoverable, audited, reversible.

Software inventory & shadow IT

Every installed application across your fleet, updated in real time. Unapproved software flagged against your policy automatically.

The console

What your IT admin actually sees.

Native desktop app on Windows, macOS, and Linux. Not a browser tab.

Why this exists

Enterprise EDR vendors built their products for Fortune 500 security teams. The pricing, the staffing assumptions, the product complexity — all of it assumes a dedicated SOC and a seven-figure security budget.

School districts and community hospitals don't have that. They have two IT staff, aging hardware, and a compliance officer who's also the technology coordinator. They need the same protection. They can't afford the same products.

We wrote Bastion in Rust so it runs on the hardware these organizations actually own. We built HIPAA and FERPA dashboards into the product so compliance doesn't require a $25,000/year consultant. We priced it at $5-7/endpoint because that's what a 1,200-endpoint school district can actually budget for.

The source code is available under BSL 1.1 (converts to Apache 2.0 after 4 years), built with Rust 2024, and source-available on GitHub. We think the organizations most vulnerable to breach should be able to inspect the software protecting them.

How Bastion compares
Vendor Price/yr HIPAA FERPA
Enterprise EDR (entry tier) $60 No No
Enterprise EDR (full tier) $180 No No
Bundled platform EDR $36/user No No
Managed EDR ~$108 No No
Bastion EDR Professional $84 Built-in Built-in

Pricing based on publicly listed rates as of March 2025. Annual billing. Bastion Professional at $7/mo = $84/yr.

Pricing

No hidden tiers. No compliance add-ons.

Annual billing saves 20%.

Starter

Core EDR for smaller fleets

$5 /endpoint/mo

or $48/endpoint billed annually

  • Up to 500 endpoints
  • Full EDR — detection, response, MITRE coverage
  • Real-time alerts & notifications
  • Software inventory & shadow IT detection
  • Basic compliance reporting
  • Email support
Start free trial
Recommended for K-12 & Healthcare

Professional

For K-12 and community healthcare

$7 /endpoint/mo

or $67/endpoint billed annually

  • Up to 2,000 endpoints
  • Everything in Starter
  • HIPAA compliance dashboard
  • FERPA compliance dashboard
  • SIEM integration (Splunk · Elastic · Sentinel)
  • Auto-response playbooks
  • Tamper-evident audit logs
  • Breach notification workflow
  • PHI encryption at rest (AES-256-GCM)
Start free trial

Enterprise

Large districts, health systems, MSPs

Custom

Contact sales for volume pricing

  • Unlimited endpoints
  • Everything in Professional
  • Custom SLA & uptime guarantee
  • On-premises deployment option
  • Dedicated onboarding engineer
  • White-glove setup & staff training
  • MSP multi-tenant management
Contact sales

Try it on 25 endpoints. 14 days. Free.

Every Professional feature included. We send your download link and trial license within 1 business day.

We respond within 1 business day with your download link and trial license key. No sales call required. No credit card.

Need a BAA or security questionnaire? [email protected]