Built as one systemGoverned AIOutbound-only agentSingle-tenant

One system, not four acquisitions

Monitoring, remote management, service desk and credentials in one system, with an AI that diagnoses and repairs across all of it. Approve every step, approve the plan once, or let it run — destructive actions always stop for a human.

No credit card. No feature tiers. Single-tenant, self-hosted or hosted by us.

web-03 — "out of disk, sort it out"
$ du -xh /var --max-depth=2 | sort -rh | head -3
3.1G /var/log/journal
412M /var/cache/apt
plan: vacuum journal to 200M · risk: low · approve?
$ journalctl --vacuum-size=200M
Vacuuming done, freed 2.9G
verify: / at 61% — check disk_root OK
58
detection plugins
a check per real resource, bound to a fix
0
inbound ports
the agent dials out over TLS and stays out
0
passwords shown
credentials injected server-side
1
audit trail
across every module, not four to correlate

Records know each other

Not synced overnight. Not matched on a hostname string and hoped for. Linked — so a technician holding a ticket can see the machine it came from, connect to it with the right credential, and check what the client is contracted for, without leaving the page or knowing a password. Change someone’s group once and their access changes in every module at the same moment.

Guardian RMM

Install it and it already knows: discovery builds the checks, each bound to an action that can repair it, and asks before it does. Browser terminal and remote desktop with no inbound ports. Monitor and manage →

Guardian PSA

A service desk that already knows: tickets routed on the check that actually failed, SLAs on real business hours, contracts that watch their renewals, time that bills itself. Run the business →

Guardian Vault

The password, the runbook and the machine in one place. Knowledge base, credential vault and document storage under one permission model and one audit trail. Remember everything →

Guardian Comms — team chat with the platform AI, private notes, and channels your alerts can post into — is included with any licence, at no extra cost.

Automation you would actually switch on

Most teams buy automation and leave it off because they do not trust it. Guardian Plus shows you the plan, the risk of each step and the exact command before anything runs — and destructive commands stop for a human even on unattended mode.

Most automation
Guardian Plus
A toggle you switch on and hope
Three approval modes you set per conversation
Runs as a service account
Runs under your permissions — it cannot open what you cannot
Sends your data to an AI vendor
Open-weight models we or you control. No OpenAI, Anthropic or Azure OpenAI
Fails and restarts from zero
Skip a step, reorder, redirect or stop mid-run

What we won’t tell you

Comparison charts are written by whoever wins them. Here is where our answer is a no, so you can rule us in or out before you book a call.

Not SOC 2 certified

There is a workflow that collects SOC 2 control evidence from your estate. That is a tool for your audit, not a certification of ours.

Not zero-knowledge

Shared credentials must be decryptable server-side for injection, break-glass and recovery to work. Private items are protected by policy and audit, not cryptography.

No recurring agreement billing yet

Time-and-materials and project billing work today. Automated monthly agreement invoicing is on the roadmap — if it is the centre of your month-end, weigh it heavily.

Bring us the workflow that annoys you most

The one that touches four systems. A 30-minute walkthrough on your own worst ticket — no slides unless you ask for them.