Every Windows capability Swayline can deliver
A complete, customizable checklist of OS-level features on every Swayline-built image. Priority A items are core; B and C are commonly added by deployment scenario.
Hide Windows Branding
Replace all Windows boot logos, lock screens and OOBE screens with your brand assets. The device boots straight into your application with no Windows shell or explorer.exe.
Power-Loss Protection (PLP)
After a sudden AC power outage the device boots straight back into the operating system. No blue screen, no recovery prompt, no manual repair.
Disk Write Protection (UWF)
Built on Microsoft’s Unified Write Filter. The system returns to a known-good state on every reboot. Specific folders and partitions can be whitelisted for writes.
Disable Hotkeys & Shortcuts
All Windows hotkeys and key combinations are disabled. Users can only launch the programs you approve. Input-method switching shortcuts are preserved.
Watchdog Process Monitoring
The system monitors designated application processes. If a watched process is closed unexpectedly, the system automatically restarts it.
Remove Forced Windows Updates
Either keep the Windows Update component but disable it permanently, or remove it entirely. Either way, the device will never download or install a forced update in the field.
Remove Windows Defender
The Windows Defender module is removed from the image, eliminating background scans and conflicts with application-level security.
Nessus Vulnerability Report
A Nessus scan is run against the customized image. Reports typically show 0 high, 0 medium and 0 low findings. The full report is available on request.
HORM Fast Boot (Hibernate Once, Resume Many)
Built on the Windows Embedded HORM standard. A pre-hibernated memory image is restored on each cold boot, compressing a 30-60 second boot to under 5 seconds.
Hard Drive Encryption (BitLocker)
BitLocker is enabled to encrypt the hard drive, making the data inaccessible without the recovery key. Essential for medical, financial and government deployments.
Automatic Logon (AutoLogon)
The configured user is automatically signed in on boot. No login screen, no credential prompt. Standard for kiosk and signage deployments.
Disable UAC
User Account Control is set to “Never notify”. When an application requests elevation, it is granted silently with no confirmation dialog or secure desktop.
Pre-installed Runtime
The .NET Framework and Visual C++ Redistributable packages are baked into the image. No first-boot installers, no dependency errors.
Run as Administrator
Designated applications always launch with administrator privileges. No right-click, no manifest editing required.
High-Performance Power Profile
Sleep, hibernate, screen saver and display turn-off are all disabled. The device always operates at maximum performance, suitable for always-on terminals.
Multi-Language UI (MUI)
Multiple language packs can be embedded in the image and switched at boot or runtime, supporting global fleet deployments.
Hardware Binding (BIOS Fingerprint)
The image checks the motherboard BIOS at boot. If the BIOS signature does not match the authorized fingerprint, the system will not start.
Disable Edge Swipe Gestures
Touch swipe gestures from the screen edges are disabled, preventing accidental invocation of system menus in touch-based kiosks.
Disable AutoPlay
USB drive auto-launch is disabled, preventing automatic execution of external media on the device.
Disable OneDrive
OneDrive is disabled and removed from the image, removing background sync and accidental data upload on industrial devices.
Trim Background Processes
Approximately 30% of non-essential Windows services and processes are removed, lowering CPU and memory overhead on low-end hardware.
Auditable Security Baseline
High-security hardening aligned with strict, multi-level security frameworks. Suitable for regulated environments including healthcare, finance and government.