Skip to main content

Requirements

Check that your endpoints meet these requirements before you deploy the QuilrAI Endpoint Agent.

OS
macOS 13+ (Ventura)
Windows 10 1903+ / Server 2019+
64-bit only
Access
macOS: root (LaunchDaemon)
Windows: SYSTEM (service)
MDM / GPO deployment
Network
Outbound 443 only
No inbound ports
Proxy passthrough if needed
Platform
macOS: MDM profiles + CA
Windows: WinDivert driver
Certificate store write
QuilrAI

Operating system​

PlatformMinimum versionNotes
macOS13.0 (Ventura)The Network Extension requires Ventura or later.
Windows10 (1903+) or Server 201964-bit only; the WinDivert driver requires 64-bit.

Access​

PlatformRequired accessUsed for
macOSrootLaunchDaemon, system extension install, keychain write.
WindowsSYSTEM / AdministratorWindows service, WinDivert driver, certificate store write. UAC is needed for the first install; later updates run as SYSTEM.

Deploy the agent with MDM (for example Jamf, Intune, or Kandji) or GPO. See Deployment and status for the install recipes.

Network​

The agent makes outbound HTTPS connections on port 443 only. No inbound ports are needed.

DestinationPurpose
QuilrAI discovery, backend and DLP hosts for your regionTenant lookup at install and update, registration and check-ins (including the kill switch), policy sync, and DLP decisions. See Backend connectivity. Your QuilrAI representative provides the exact hostnames to allow.
QuilrAI update hostsUpdate checks and package downloads. Included in the list your representative provides.
login.microsoftonline.com or oauth2.googleapis.comUser sign-in that links the device to a person.

Get the full list of hosts to allow from your QuilrAI representative. If endpoints go through a corporate proxy, let these destinations pass through without TLS inspection of the agent's own traffic.

Platform specifics​

macOS

RequirementDetails
System extensionBundle ID ai.quilr.agent.sentinel.extension, Team ID W8FHSH4RM5. Approve it with the system extension profile supplied with the package, before the package installs. Without MDM, the user approves it in System Settings › Privacy & Security.
Network extensionAllowed by the same supplied profile.
Full Disk AccessGranted by the supplied Full Disk Access (privacy preferences) profile.
Root CA trustThe QuilrAI root and intermediate CA certificates are supplied with the package. Deploy them as an MDM certificate payload before the package; the installer waits and retries until trust is in place.

Windows

RequirementDetails
WinDivert driverBundled with the agent package.
Certificate store writeNeeded to trust the agent's root CA in the local machine store.
Windows serviceQuilrAIAgent ("QuilrAI Endpoint Agent"), runs as LocalSystem and starts automatically.
Updater taskScheduled task QuilrAI-Endpoint-Update, every 30 minutes.

Disk space​

ComponentApproximate size
Agent binaries~50 MB
Certificate and key< 1 KB
Configuration and templates< 5 MB
Logs (rolling)Configurable; 100 MB cap by default

What gets installed​

PlatformPathContents
macOS/Applications/QuilrAIProxy.appAgent binaries and system extension
macOS/Library/Application Support/QuilrAI/Configuration, tenant ID, uninstaller
macOS/Library/LaunchDaemons/com.quilrai.agent.plistAgent service
macOS/Library/LaunchDaemons/com.quilrai.endpoint.updater.plistUpdater, every 30 minutes
macOS/Library/Logs/QuilrAI/Agent logs
WindowsC:\Program Files\QuilrAI\Agent binaries (quilrai.exe and helpers)
WindowsC:\ProgramData\QuilrAI\Tenant ID and service logs
WindowsQuilrAIAgentWindows service

Security and updates​

  • Signed binaries and chain of trust. A bootstrap process verifies its own signature and the main agent binary before starting it. The agent refuses to run if it was not started by the bootstrap, so a tampered or directly launched binary does not run.
  • Self-update. The updater checks for a new version every 30 minutes, starts the new version, and waits for it to run stably. If it does not, the updater restores the previous version.