Every Windows capability Swayline can deliver

A complete, customizable checklist of OS-level features on every Swayline-built image. Priority A items are core; B and C are commonly added by deployment scenario.

A · CORE

Hide Windows Branding

Replace all Windows boot logos, lock screens and OOBE screens with your brand assets. The device boots straight into your application with no Windows shell or explorer.exe.

BrandingOOBEBoot logo
A · CORE

Power-Loss Protection (PLP)

After a sudden AC power outage the device boots straight back into the operating system. No blue screen, no recovery prompt, no manual repair.

Unclean shutdownReliability
A · CORE

Disk Write Protection (UWF)

Built on Microsoft’s Unified Write Filter. The system returns to a known-good state on every reboot. Specific folders and partitions can be whitelisted for writes.

UWFWhitelistAuto-restore
A · CORE

Disable Hotkeys & Shortcuts

All Windows hotkeys and key combinations are disabled. Users can only launch the programs you approve. Input-method switching shortcuts are preserved.

LockdownKiosk
A · CORE

Watchdog Process Monitoring

The system monitors designated application processes. If a watched process is closed unexpectedly, the system automatically restarts it.

WatchdogAuto-restart
A · CORE

Remove Forced Windows Updates

Either keep the Windows Update component but disable it permanently, or remove it entirely. Either way, the device will never download or install a forced update in the field.

Update controlStability
A · CORE

Remove Windows Defender

The Windows Defender module is removed from the image, eliminating background scans and conflicts with application-level security.

AntimalwarePerformance
B · HARDENING

Nessus Vulnerability Report

A Nessus scan is run against the customized image. Reports typically show 0 high, 0 medium and 0 low findings. The full report is available on request.

NessusAuditCompliance
B · HARDENING

HORM Fast Boot (Hibernate Once, Resume Many)

Built on the Windows Embedded HORM standard. A pre-hibernated memory image is restored on each cold boot, compressing a 30-60 second boot to under 5 seconds.

HORMBoot timeEmbedded
B · HARDENING

Hard Drive Encryption (BitLocker)

BitLocker is enabled to encrypt the hard drive, making the data inaccessible without the recovery key. Essential for medical, financial and government deployments.

BitLockerEncryptionTPM
C · TUNING

Automatic Logon (AutoLogon)

The configured user is automatically signed in on boot. No login screen, no credential prompt. Standard for kiosk and signage deployments.

AutoLogonKiosk
C · TUNING

Disable UAC

User Account Control is set to “Never notify”. When an application requests elevation, it is granted silently with no confirmation dialog or secure desktop.

UACSilent elevate
C · TUNING

Pre-installed Runtime

The .NET Framework and Visual C++ Redistributable packages are baked into the image. No first-boot installers, no dependency errors.

.NETVC++Runtime
C · TUNING

Run as Administrator

Designated applications always launch with administrator privileges. No right-click, no manifest editing required.

Always elevated
C · TUNING

High-Performance Power Profile

Sleep, hibernate, screen saver and display turn-off are all disabled. The device always operates at maximum performance, suitable for always-on terminals.

Always-onPower
C · TUNING

Multi-Language UI (MUI)

Multiple language packs can be embedded in the image and switched at boot or runtime, supporting global fleet deployments.

MUIi18n
C · TUNING

Hardware Binding (BIOS Fingerprint)

The image checks the motherboard BIOS at boot. If the BIOS signature does not match the authorized fingerprint, the system will not start.

Anti-piracyBinding
C · TUNING

Disable Edge Swipe Gestures

Touch swipe gestures from the screen edges are disabled, preventing accidental invocation of system menus in touch-based kiosks.

TouchKiosk
C · TUNING

Disable AutoPlay

USB drive auto-launch is disabled, preventing automatic execution of external media on the device.

USBSecurity
C · TUNING

Disable OneDrive

OneDrive is disabled and removed from the image, removing background sync and accidental data upload on industrial devices.

OneDrivePrivacy
C · TUNING

Trim Background Processes

Approximately 30% of non-essential Windows services and processes are removed, lowering CPU and memory overhead on low-end hardware.

PerformanceDebloat
C · TUNING

Auditable Security Baseline

High-security hardening aligned with strict, multi-level security frameworks. Suitable for regulated environments including healthcare, finance and government.

ComplianceBaseline