Apple content caching, managed

Download every update once. Serve it to every device.

Cachard is the command center for the Mac content caches in your schools or offices. See every cache live, configure the whole fleet in one step, roll out macOS updates safely, and know the moment a site stops being served. It runs on your own server.

All features in the trial · No agent on the Macs · Up and running in about ten minutes

From Apple0.0 GBServed to devices0.0 GB
from Appleparent → site cachecache → devicesillustration
Cachard network map: caches arranged by site with live traffic from Apple, between caches and to devices, and an AI analysis panel
AgentlessNothing to install on the MacsAn SSH key and one narrow sudoers rule. Works alongside Jamf, Mosyle, Intune or any MDM.
Self-hostedYour data stays on your networkOne small Linux VM or a container. No vendor cloud; license keys are checked offline.
Fast setupInstaller plus a guided wizardFinds your caching Macs on the network and prepares them all in one step.
Built in productionMade by a K-12 network adminBorn running a district fleet of caching Mac minis, then built out for any organization.
Interactive tour

Click through the console

These are real screens from Cachard's demo mode, with a fictional school district and simulated Macs. Choose a stop, then tap the green markers.

cachard.fairhaven-usd.example/

Prefer to click everything yourself? The demo ships with every download:./run.sh --demothen open localhost:8080 (password demo).
What's inside

Everything a caching fleet needs, in one place

Live fleet view

Online, caching, cache used, served to devices, serving now and bandwidth saved for every Mac, refreshed every 15 seconds.

Network map & TV mode

Traffic flows from Apple to parent caches, site caches and individual devices, as rings or on a street map of your area. Put it on the NOC wall.

Configure many Macs at once

Cache size, parents, peers, listen and public IP ranges. Preview every change, apply in parallel, and Cachard re-reads each Mac to verify it stuck.

Device update tracking

What's being downloaded, cache hit rates, iOS and macOS rollout per site, and devices stuck re-downloading the same update.

macOS updates for the caches

Scan, schedule and roll out updates a few Macs at a time, never two at the same site, so devices are never left without a cache.

AI insights (optional)

With your Anthropic API key, Claude reads the whole fleet and explains what's happening in plain English, with prioritised fixes and a place to ask questions.

Site checks

Are devices at each site actually finding their cache? Internet speed per site. Mac health, disk and power settings.

History & replay

Daily totals kept for 13 months, a weekly report by email, and a replay of any day's traffic on the map.

Alerts that respect your day

Email and Microsoft Teams alerts for offline caches, lost parents and low disk, with quiet hours and all-clear messages.

Standard settings & drift

Define how every cache, or every cache at one site, should be set up. Cachard flags drift and MDM profiles that override local settings.

Accounts, SSO, two-step

Viewer, operator and admin roles, email invitations, Microsoft Entra ID or Google sign-in, and required two-step sign-in.

Terminal & fleet terminal

A shell on any Mac in the browser, or one command across many Macs with matching output grouped. Admin-only and fully audited.

See the network

Your caches, on your streets

Set each site's address and Cachard builds a street map of your area from OpenStreetMap once, then keeps it on the server. Wall displays and locked-down networks never load map tiles.

  • Follow the bytes. Amber from Apple, blue between caches, green to devices, with the busiest links labeled.
  • Zoom into a site to see every iPad, iPhone, Mac and Apple TV it served, and what each one downloaded.
  • Problems show where they are. An offline cache pulses red; a parent that's set but unused is drawn dashed.
Street-map view of a fictional town with caches at each school and live traffic
TV mode: full-screen map with large totals and the live analysis
TV mode

Made for the wall in the NOC

Full-screen and hands-off. It tours each site, shows what's being served right now, and keeps the live analysis on screen. A read-only link works on any display without signing in.

Setup

From a fresh VM to a watched fleet in about ten minutes

$ tar xzf cachard-1.1.0.tar.gz && cd cachard-1.1.0
$ sudo ./install.sh
▸ Checking this server
  ✓ Ubuntu 24.04 LTS · 4 GB memory · port 8080 is free
▸ Installing the service
  ✓ Service 'cachard' enabled (starts on boot)
▸ Starting
  ✓ Cachard is running

  Open:        http://10.10.0.15:8080/setup
  Setup code:  7F3A-91C2-0B6D
Ubuntu 22.04/24.04 or Debian 12 · Docker image included
  1. Run the installer

    It checks the server, installs a hardened service and prints a one-time setup code. Offline bundles work on air-gapped networks.

  2. Follow the wizard

    Name your organization, start the trial or paste a license key, then scan your subnets. Cachard finds the Macs with Remote Login on.

  3. Prepare every Mac at once

    Enter a Mac admin password once. Cachard pins each host key, installs its key and a narrow sudoers rule, and confirms each Mac is ready. The password is never stored.

  4. Place your sites and turn on alerts

    Search an address for each site, build the street map, and point alerts at Teams or email.

Setup wizard preparing six Macs, each showing its name, model, macOS version and host key
Prepare. One password, every Mac identified and connected, with a clear reason when one isn't.
Setup wizard step for site locations with an address search
Sites & map. Address search or coordinates; the street map builds itself.
Who it's for

Anywhere hundreds of Apple devices share one Internet connection

K-12 school districts

iPad carts and Mac labs all pulling the same iPadOS update at 8:05 on a Monday.

  • One cache per school, a parent at the district office
  • Knows the school day: urgent during class, quiet overnight
  • Per-school reports for the technology director

Colleges & universities

Residence halls, labs and libraries across a campus, with student devices you don't manage.

  • Serve unmanaged devices on campus subnets
  • Listen and public IP ranges checked against reality
  • Roles for help-desk staff and network engineers

Businesses

Offices, stores or plants with Mac and iPhone fleets and expensive or thin WAN links.

  • Keep macOS and app downloads off the WAN
  • Works with any MDM, no agent to approve
  • SSO, audit log and on-premises data for compliance
The console rebranded as Northwind CacheView for Lakeview School District, with a purple accent and its own logo
Branded sign-in page with a custom background, logo and help message
White-label

Your name on the console, not ours

Managed service providers, resellers and central IT teams can present Cachard as their own product. Set it once under Settings → Branding, or ship a branding pack with the installer so the very first setup screen is already yours.

Product name & taglineLogo & dark-mode logoApp iconAccent colourSign-in page & backgroundSupport contactRenewal linkEmail sender & footerHide “Powered by”

Any accent colour stays readable: text shades are adjusted automatically for contrast in light and dark mode. Weekly reports, alerts, two-step sign-in apps and the AI analyst all use your product name. Included with Enterprise and Partner licenses, and you can preview it during the trial.

Shown: “Northwind CacheView”, a fictional reseller brand.

Automatic updates

Stays current without a maintenance weekend

Cachard checks for new versions daily. Install with one click, or let it update itself overnight in your maintenance window.

  • Signed and verified

    Every release is signed and checked on your server before anything is installed.

  • Your schedule

    Notify only, install patches automatically, or install everything, on the days and hours you choose. Never while the caches are updating macOS.

  • Backed up, with automatic rollback

    Data is backed up first. If the new version doesn't start, the previous version and data come back on their own.

  • Air-gapped too

    Offline update files for networks without Internet access, and cachard update on the command line.

  • Built-in support

    Help & support in the console, and a one-click support bundle with passwords, keys and secrets removed.

Settings, Updates: up to date, with install policy, channel and notification options
Settings → Updates. Release notes, history and policy in one place, shown here on a white-labeled console.
Help and support page showing the support contact, documentation and a support bundle button
Help & support. Your support contact, the guides and a diagnostics bundle.
Security & privacy

Built to pass the security review

A full security overview (SECURITY.md) ships with every download for your IT and procurement teams.

On your network

Self-hosted on Linux or Docker. No vendor cloud and no telemetry. Update checks send only the version and license ID, and can be turned off.

Least privilege on Macs

A dedicated SSH key and a validated sudoers rule limited to content caching and software update commands.

No stored Mac passwords

The admin password is used once during setup, in memory only. Host keys are pinned and verified.

Accounts

PBKDF2-hashed passwords, roles, TOTP two-step sign-in, Microsoft or Google single sign-on.

Audited

Every change, action, update and terminal session is recorded with who, when, where and the exact commands.

Signed updates

Releases are signed with a dedicated key, checked by a root-owned updater, and rolled back automatically if they fail.

Hardened service

Runs unprivileged under systemd sandboxing, writing only to its own data folder. HTTPS with your certificate.

Pricing

Priced per caching Mac, not per device

Every plan includes every feature, automatic updates and email support. Start with a 30-day trial; no card needed.

Education

Schools & colleges

$99 per caching Mac / year
  • K-12, higher education and nonprofits
  • All features, unlimited devices
  • Automatic updates and email support
  • Purchase orders welcome
Start free trialRequest a quote or PO
Business

Companies

$149 per caching Mac / year
  • All features, unlimited devices
  • Microsoft and Google single sign-on
  • Automatic updates and email support
  • Annual invoicing
Start free trialRequest a quote
Enterprise

Large fleets

Let's talk 50+ caching Macs
  • White-label branding included
  • Volume pricing and multi-year terms
  • Guided onboarding and priority support
  • Security questionnaire help
Contact sales
Partner

MSPs & resellers

Wholesale for every customer you manage
  • Full white-label: your name, logo and support
  • Branding packs for branded installs
  • Wholesale per-cache pricing
  • Partner support line
Become a partner
12 MacsEducation $1,188/yrBusiness $1,788/yr
Questions

Asked by network admins

Do I need to install anything on the Macs?

No agent. The setup wizard installs an SSH key and a sudoers rule that allows only the content-caching and software-update commands. Remote Login must be on. Macs where password sign-in over SSH is disabled can be prepared with a script or your MDM.

Does it replace our MDM?

No, it works next to Jamf, Mosyle, Kandji, Intune or any other MDM. When an MDM profile manages a caching setting, Cachard shows it and warns before you change it locally.

Which macOS versions are supported?

Any Mac that runs Apple's content caching and the AssetCacheManagerUtil tool, on Apple silicon or Intel. The console reads each Mac's version and adapts.

What does the server need?

Ubuntu 22.04 or 24.04, or Debian 12, on a small VM (1 vCPU, 1 GB RAM, 2 GB disk), or Docker. It needs to reach the Macs on port 22. Internet access is only needed to install, to build the street map once, and for automatic updates, optional AI insights and Teams alerts. Air-gapped servers can update from offline files.

What happens when the trial or license ends?

Cachard keeps monitoring, mapping and alerting. It stops making changes to the Macs until a license key is entered, so your caches are never left unwatched.

Is AI insights required, and what does it send?

It's optional and off by default. With your own Anthropic API key, Cachard sends an aggregate snapshot (Mac names, sites, states, settings, traffic totals and findings) and shows you exactly what's sent. Device IP addresses and identities, passwords and keys are never sent.

Can we put our own name and logo on it?

Yes. Enterprise and Partner licenses include white-label branding: product name, logos, icon, accent colour, sign-in page, support contact, renewal link and email sender, with the option to hide “Powered by Cachard”. Every plan can show your organization's name and logo next to the product name.

How do updates work?

Cachard checks a signed release feed once a day. You choose to be notified, to install patches automatically, or to install everything, within a maintenance window. Each update backs up your data first and rolls back on its own if the new version doesn't start. Updates are included while your license's support term is active.

Can we try it without touching our network?

Yes. ./run.sh --demo runs a fictional district with 14 simulated Macs on any machine with Python.

30-day trial

Try Cachard on your own caches

Tell us a little about your network and we'll email the download link and setup guide right away. Need a quote or want to resell Cachard? Choose that below and we'll reply within one business day. Prefer email? Write to sales@cachard.app.

We use your details only to send what you asked for and to follow up about Cachard. Privacy