Your cart 0 items
Your cart is empty.
Searching the site...
No matches. Try another word.
Computers & devices

Office desktops

A managed desktop fleet that runs CalyOS Desktop, joins your directory on first boot, and arrives already imaged, encrypted and locked to your security baseline. Every seat is the same known machine, and you manage all of them from one place.

The problem

No two machines are the same.

Most offices grow their desktops one purchase at a time. Someone buys a consumer PC from a shop, sets it up by hand, installs whatever the last person asked for, and hands it over. Six months later no two machines are alike. Windows versions drift, half of them have a local admin account nobody tracks, drives are unencrypted, and when a laptop goes missing there is no way to wipe it. Patching is whatever each user clicks. When a machine breaks, rebuilding it is a full afternoon because there is no image to fall back to. The fix is not more IT hours. It is treating desktops as a fleet: one signed image, one directory, one console, and a rule that every seat looks identical the day it ships and every day after.

Design targets
< 20 min Network reimage to known-good
XTS-AES-256 Full-disk encryption, TPM sealed
CIS L1 Security baseline out of the box
5 yr Support and parts on the fleet
The system

One image, one directory, one console.

Three layers do the work. The sealed image makes every desk identical, the directory join gives one identity, and the management plane keeps it that way. Open a layer for how it works.

Sealed and signed
Imagery in production

The standard image

What every desk ships with

One golden image per role CalyOS Desktop, apps and profiles baked in Deploys in under 20 min
Sealed and signed
Imagery in production

The standard image

What every desk ships with

One golden image per role CalyOS Desktop, apps and profiles baked in Deploys in under 20 min

Every desktop leaves staging with the same sealed image: CalyOS Desktop, your office application set, printer and VPN profiles, and the security baseline already applied. Nothing is hand-built at the desk, so nothing drifts. The image is content-addressed and signed. A machine whose checksum does not match the record never joins the fleet, which stops a tampered or half-built build reaching a user. A reimage over the network takes under 20 minutes and returns any seat to a known-good state. You can hold more than one image, for example a standard office role and a design role, and pick which one a machine gets by its directory group.

Domain join
Imagery in production

The directory join

One identity, applied before first login

Joins your directory on first boot One sign-in, no local accounts Policy applied before the user lands
Domain join
Imagery in production

The directory join

One identity, applied before first login

Joins your directory on first boot One sign-in, no local accounts Policy applied before the user lands

On first boot the desktop joins your CalyOS directory the way a Windows machine joins a domain. The user signs in with the same account they use for mail and files. There is no separate local password to reset and no orphaned local admin account left behind. Group membership decides what the machine looks like. A finance desk and a reception desk get different applications, different drive mappings and different rules without anyone touching either one by hand. Policy lands before the first login, so the seat is compliant the moment it is switched on. When someone leaves, disabling their directory account locks every desktop they could reach. There is nothing local to clean up.

One console
Imagery in production

The management plane

How you keep the fleet honest

Agent checks in every 15 min Remote lock, wipe and reimage Live inventory and patch state
One console
Imagery in production

The management plane

How you keep the fleet honest

Agent checks in every 15 min Remote lock, wipe and reimage Live inventory and patch state

A lightweight agent on each desktop checks in with the console every 15 minutes and reports hardware, installed software, encryption status and patch level. You see the whole fleet on one screen instead of asking people what they are running. From the same console you push updates in a controlled window, lock a screen, wipe a lost machine, or trigger a full network reimage. Actions are logged with who did them and when, which is what an auditor asks for. The plane runs on your CalyOS Server or as a managed service we operate for you. Either way the data stays under your directory and your control.

Solution optimized products

The seats we configure.

Two desktop bodies and the peripherals that ship with them, all imaged and joined before they leave us.

Imagery in production
Compact

Vale Desk Mini

1L chassis, 8 core, 16 to 64 GB, 512 GB to 2 TB NVMe, 2.5 GbE, TPM 2.0

A one-litre desktop that hides behind a monitor or clips to the VESA arm. Right for reception, call desks and hot-desk banks where space is tight and the load is office work.

Imagery in production
Tower

Vale Desk Tower

Micro-ATX, 12 core, 32 to 128 GB ECC, dual NVMe, discrete GPU option, 500 W 80 Plus

An expandable tower for finance, engineering and design seats that need memory, a graphics card or a second drive. Tool-free access so a part swap is minutes, not a rebuild.

Imagery in production
Peripherals

Vale Display 24

24 inch, 1920 x 1200, 100 Hz, USB-C 65 W power delivery, height and pivot stand

A single USB-C cable carries video, power and USB to the Mini, so the desk has one wire. Matte panel and a stand that raises, tilts and pivots for a compliant sitting position.

Imagery in production
Peripherals

Vale Input Set

Quiet membrane keyboard and 4000 dpi mouse, USB-A receiver, replaceable AA cells

A wireless keyboard and mouse paired to one receiver at staging, so a user has nothing to configure. AA cells rather than a sealed battery means the set lasts as long as the desktop.

“The day the desktops arrived we plugged them in and people signed in with their normal accounts. No build sheets, no local passwords, no afternoon per machine. That was the whole point.”
IT manager, professional services firm
What is included

Everything the desk needs.

A seat is not just a box. It is the machine, the image, the applications your people actually use, and the paperwork to keep it running for years. All of it is set before it ships.

In the box

What each seat carries.

Ready to sign in

Imaged

The desktop arrives with CalyOS Desktop, your office suite, browser, mail and line-of-business apps installed from the sealed image. Printer and VPN profiles are already in place. The user switches it on, signs in with their directory account, and works.

Imagery in production

The machine

A Vale Desk Mini or Tower configured to the role, with TPM 2.0, Secure Boot and full-disk encryption set from the factory.

The image

One signed CalyOS Desktop image per role, so the design seat and the reception seat differ by policy, not by a hand build.

The baseline

CIS Level 1 hardening, no local admin, disk encryption on and BitLocker-style recovery keys escrowed to your directory.

The cover

Five years of parts and next-business-day support, plus asset tags and a serial register handed over on day one.

How each seat is supplied

1 Sealed image applied
0 Local admin accounts
< 15 W Idle draw, Mini
5 yr Parts and support
Pick by role

Three ways we build a seat.

Same image and management on all three. The difference is the body and what runs on it.

Desk

Standard office

Vale Desk Mini, 16 GB, 512 GB. Mail, browser, office suite and your line-of-business apps. The volume seat for most of a building.

Power

Finance and engineering

Vale Desk Tower, 32 to 64 GB ECC, dual monitors. Spreadsheets that never end, drawing packages and local databases.

Shared

Hot desk and kiosk

Vale Desk Mini locked to a shared account, auto-wiped between sessions, no data left at rest. For touchdown benches and shared rooms.

Specify it with us

Build your standard seat.

Tell us your roles and your apps and we will define the images and the bill of materials. You approve one seat, we ship the fleet.

Under the hood

Managed, not trusted.

Imagery in production
Identity

One account, no local doors

Every desktop joins your CalyOS directory and users sign in with their central account. There are no standing local admin accounts and no shared passwords on a sticky note. Rights come from directory groups, so promoting or removing access is one change in one place. Disable a leaver once and every machine they could reach locks with them.

Imagery in production
Encryption

Sealed to the machine

Full-disk encryption uses XTS-AES-256 and the key is sealed to the desktop's TPM 2.0, so a drive pulled out and put in another body reads as noise. Recovery keys are escrowed to your directory, not to the user, so a forgotten passphrase is a two-minute unlock for IT and not a lost machine. Secure Boot blocks an unsigned operating system from starting on the hardware.

Imagery in production
Control

Patch, lock, wipe from here

The management console shows live patch state across the fleet and pushes updates in a window you choose, so a bad update never hits everyone at once. A lost or stolen desktop is locked or wiped remotely on its next check-in. Software installs come from an approved catalogue rather than a user download, and every administrative action is logged with a name and a timestamp.

Assessed against

The standards it meets.

The baseline maps to the frameworks an auditor and an insurer actually ask about.

Hardening

CIS Benchmark L1

The default image ships hardened to CIS Level 1 for the desktop OS, with the settings documented so you can show what was applied and why.

Attestation

Cyber Essentials

No local admin, patching in policy, disk encryption on and a managed firewall line up with the Cyber Essentials controls, which cuts the certification paperwork.

Data

GDPR at rest

Drives are encrypted to XTS-AES-256 and wipe on command, so a lost desktop is a hardware loss and not a reportable data breach under UK GDPR.

Security posture
TPM 2.0 Hardware root of trust
100% Drives encrypted at rest
< 24 h Window for critical patches
0 Standing local admin rights
Engineering questions

The details IT checks.

Can we keep our existing directory and identity provider?

Yes. CalyOS Desktop joins your directory the way a Windows machine joins a domain, and it can federate to your existing identity provider for single sign-on. You do not replace what you have.

What happens to a stolen laptop before it connects again?

The disk is already encrypted and sealed to that machine's TPM, so the data is unreadable offline. The remote wipe fires the next time it touches any network, and until then the encryption is the protection.

Do users get local admin for the odd install?

No standing local admin. Approved software comes from the managed catalogue, and a one-off elevated task can be granted for a set time and logged, so nobody carries permanent admin they forget about.

“Our insurer wanted encryption at rest, patch evidence and no local admin. The fleet gave us all three on one report instead of a spreadsheet we maintained by hand.”
Head of security, mid-market insurer
How we land it

A rollout without an afternoon per desk.

The slow part of new desktops is never the hardware. It is the human hours of building each machine, chasing licences, and standing over a user while they sign in. We move that work off the desk and into staging. You approve one standard seat. We image the fleet against it, join each machine to your directory, tag and register every asset, and ship them boxed by floor or by team. On the day, a machine comes out of the box, goes on the desk, and the user signs in with the account they already have. A technician is not needed at each seat. If a machine ever fails, a network reimage returns it to the same known-good state in under twenty minutes, so a broken desktop is a swap and not a rebuild.

Rollout

From order to desk.

  1. Define the seat

    We sit with IT, agree the roles, the applications and the baseline, and build one image per role. You sign off a single standard machine.

  2. Image and join

    Every desktop is imaged against the approved build, joined to your directory, encrypted, asset-tagged and entered on the serial register in staging.

  3. Ship by team

    Machines arrive boxed and labelled by floor or department, with peripherals paired, so unpacking follows your seating plan and not a pile in reception.

  4. Sign in and go

    The user powers on, signs in with their directory account, and policy is already applied. No local setup, no build sheet, no technician at the desk.

  5. Run and refresh

    The console keeps the fleet patched and inventoried. When a machine fails or a hire starts, a reimage or a spare from stock returns a known-good seat the same day.

The difference

Fleet, not a pile of PCs.

Calyraen managed fleetShop-bought PCs
Setup per machine Imaged in staging, signed in at the desk Built by hand, an afternoon each
Identity Directory join, one central account Local accounts and shared passwords
Encryption On by default, key escrowed to IT Off unless someone remembers
Patching Controlled window from one console Whatever each user clicks
Lost machine Remote lock and wipe on next check-in No way to reach it
Rebuild Network reimage in under 20 min Reinstall from scratch
Specify it with us

Plan your rollout.

Give us the seat count and the floor plan and we will scope the images, the staging and the delivery. You get a date and a fixed price per seat.

Resources

Read it before you buy it.

The briefs, the baseline and the cases behind the fleet. Open any card for the detail, or request the files for your own review.

Reading room

Briefs and real rollouts.

What we hand IT and procurement when they evaluate the fleet. Open a card for the summary.

Two-page brief
Imagery in production

The managed desktop brief

How the fleet model works

Image, directory, console What ships and what it costs For IT and procurement
Two-page brief
Imagery in production

The managed desktop brief

How the fleet model works

Image, directory, console What ships and what it costs For IT and procurement

A two-page explainer of the fleet model: the sealed image, the directory join, the management console, and how they remove the per-machine build. Written for an IT lead and a procurement lead to read in one sitting. It sets out what is fixed on every seat, what varies by role, and where the five-year support cover starts and stops. The last page is a per-seat cost breakdown so a budget line is easy to build.

Baseline sheet
Imagery in production

The security baseline

Every setting, documented

CIS L1 mapping Encryption and TPM detail Cyber Essentials cross-reference
Baseline sheet
Imagery in production

The security baseline

Every setting, documented

CIS L1 mapping Encryption and TPM detail Cyber Essentials cross-reference

The full list of hardening settings in the default image, mapped to CIS Level 1, with a short note on each of why it is set the way it is. It covers the encryption scheme, the TPM sealing, Secure Boot, the removal of local admin, and how recovery keys are escrowed. A cross-reference table lines each control up against Cyber Essentials, which shortens an attestation. Your security team can review it before a single machine is ordered.

Use case
Imagery in production

120 seats in one weekend

Professional services rollout

120 desks, three floors Deployed over a weekend Zero technician time at desks
Use case
Imagery in production

120 seats in one weekend

Professional services rollout

120 desks, three floors Deployed over a weekend Zero technician time at desks

A professional services firm replaced 120 ageing desktops across three floors. Every machine was imaged and directory-joined in staging and delivered boxed by team. Over a weekend the old machines came out and the new ones went in. On Monday people signed in with their normal accounts and worked. No technician stood at a desk, no local passwords were set, and the only day-one tickets were about where the coffee machine had moved.

Use case
Imagery in production

A laptop went missing

Lost device, no breach report

Device lost off-site Encrypted, sealed to TPM Wiped on next connection
Use case
Imagery in production

A laptop went missing

Lost device, no breach report

Device lost off-site Encrypted, sealed to TPM Wiped on next connection

A staff member left a managed machine on a train. The drive was already encrypted with XTS-AES-256 and sealed to that machine's TPM, so the data was unreadable to whoever found it. IT flagged it in the console and the remote wipe fired the moment the device next reached a network. Because the data was protected at rest, the loss was recorded as hardware only and did not become a reportable data breach. The replacement was a spare from stock, reimaged and on the desk the same day.

Request the files

Take it to your team.

We send these on request so we can point you at the right build for your seat count and your directory.

Specify it with us

Standardise your desks.

Send us your seat count and your apps and we will come back with the images, the bill of materials and a price per seat. One approval, one fleet.