Attestree vs Patch My PC
Patch My PC is a commercial third-party application catalog that packages and publishes applications and updates into your existing ConfigMgr, Intune or WSUS infrastructure. It is not a package repository — it uses your existing management infrastructure as the delivery channel. Its catalog covers several thousand applications, and it is widely deployed.
Verified against vendor documentation, September 2026
When Patch My PC is the better answer.
This is the most capable product on this list at the job it does, and two of its features are genuinely ahead of where a lot of tooling sits. Patch My PC Cloud has real Update Rings — up to ten per deployment, with delayed and immediate ring types — which is more staged-rollout capability than Intune offers natively. And it explicitly supports user-based installs for ConfigMgr and Intune apps, which is more than most of this category. Its published catalog security process is also unusually transparent: vendor-mirror sourcing, hash verification against the vendor digest, multi-engine VirusTotal scanning, and code-signing of its own catalog file with a hardware-based certificate.
Where the two part company.
The difference is the nature of the evidence rather than the diligence. Patch My PC verifies that the bytes match the digest the vendor published and that no antivirus engine objects — integrity of transfer plus reputation. Neither answers what the installer does when it runs, and neither is a bill of materials. Attestree detonates the installer in a sandbox, records the observed behaviour, generates a CycloneDX SBOM, and signs a verdict you can hand to an auditor. There is also a scope difference: Patch My PC curates a vendor catalog, so your coverage is what they package, whereas an ingest gate applies to anything you choose to admit.
Only what we could verify.
We did not find Patch My PC pricing from a primary source and will not repeat a figure we cannot cite. One correction to an earlier version of this page: we previously implied phased rollout was a Cloud-only capability. The on-premises Publisher documentation does describe phased deployments — building rings by staggering Intune assignment deadlines, for example three, ten and seventeen days. It is presented as illustrative configuration guidance rather than an orchestration feature, and stopping a bad rollout is explicitly a manual action, but it exists and we were wrong to leave that unsaid.
Capabilities are taken from each vendor’s own documentation, and we say “not documented” rather than “not supported” where a vendor is simply silent. If something here is wrong or has changed, tell us and we will correct it — that is a cheaper outcome for everyone than an inaccurate comparison.
Check the claim yourself.
The detonation, the SBOM and the signed attestation all run in the free Community Edition, on your own hardware, for up to 50 endpoints.