Guardian Plus runs on your infrastructure, one tenant per deployment, with agents that never accept an inbound connection. If your auditor asks where the data lives, the answer is short.
Every customer gets their own deployment — on your hardware, in your cloud account, or hosted by us on infrastructure dedicated to you. Your Suite pairs only with your own product instances and your own secrets.
Install on your own servers with the OS installers, or run the container images in your own environment. Nothing phones home except a daily licence check.
We’ll run it for you — but on infrastructure dedicated to your organisation. It is still your deployment, not a slot in a shared one.
There is no multi-tenant mode. Your database, your keys, your instance. No other customer’s data has ever been in it.
Most platforms give you one topology and expect your network to accommodate it. We document three, including one where the management plane sits behind a single inbound rule you can close entirely.
Everything on one trusted network. The simplest deployment, appropriate when your management plane and your endpoints already share a security boundary. Fastest to stand up; no inbound rules on endpoints; suited to a single office or data centre.
Endpoints anywhere — home, hotel, client site — while the management console itself stays restricted to your office network or VPN. Agents reach in from any network; console access stays behind your perimeter; no endpoint ever exposed to the internet.
The monitoring plane sits on a private network with exactly one inbound rule. Close even that, and you trade nothing but a delay of up to an hour before a revoked session stops working. Built for segmented and regulated environments.
Every managed endpoint dials out over TLS and keeps one authenticated socket open. Nothing listens. There is no firewall rule to add, no port to forward, no VPN to maintain — and browser-based terminal and remote desktop both ride that same outbound connection.
Windows, macOS on Intel and Apple Silicon, and 64-bit Ubuntu, Rocky, CentOS Stream and SUSE. Devices you can’t install on — switches, firewalls, printers, appliances — are reached from the outside by a collector.
Each is optional and scoped to a machine you choose.
A collector — an agent promoted to reach devices that can’t run one — binds a local port to proxy for them.
A trap receiver you designate listens for SNMP traps from your network devices.
Remote desktop on macOS and Linux uses the operating system’s own screen-sharing service on loopback, relayed out over the agent’s existing connection.
Credentials, documents, ticket contents and integration secrets are encrypted at rest with AES-256-GCM. Keys aren’t shared across the platform — each company, and each individual’s private vault, gets its own key derived from the master. If the service can’t decrypt with the key it was given at boot, it refuses to start rather than run half-blind.
Authenticated encryption with a fresh initialisation vector per record. A tampered record fails to decrypt rather than returning garbage.
Derived per company — and per person for private vaults — so one company’s key can never open another’s data.
On boot the service proves it can decrypt with the key it was handed. If it can’t, it exits instead of running.
Credentials injected into a remote session are resolved server-side. The operator’s browser is never sent the plaintext.
Guardian Plus runs open-weight models on infrastructure we operate — or on your own, if you’d rather host them. There is no OpenAI account, no Anthropic account, no Azure OpenAI endpoint anywhere in the platform. Your command output, your ticket contents and your monitoring data are never handed to a model vendor.
Approve every step, approve the plan once, or let it run. Destructive commands stop for a human even on unattended mode.
Every tool the assistant calls re-derives the permissions of whoever asked. It cannot see a record you cannot see.
Write actions are hidden from the assistant entirely and need a person to confirm. Your most sensitive documents are never fed to a model at all.
One identity provider with multi-factor authentication. Deactivate someone once and every product session ends immediately. Federate to Microsoft Entra or Okta over OpenID Connect, or sync users from Active Directory.
Dozens of individually grantable actions, assigned through your groups, with grants that can carry an expiry date. If a permission check errors, access is denied — a degraded service does not become an open one.
A person’s private vault cannot be opened by any administrator, including a super admin — and the attempt is recorded.
The authentication log cannot be edited or deleted, by anyone, through any interface.
Service desk history is append-only, enforced by the database itself rather than by application code that could be bypassed.
Who, when, from where, and which permission allowed it — including whether it came from an administrator override.
When a notification is withheld, the reason is recorded. You can always answer why something didn’t page.
Security teams have to verify claims, and vague ones cost everybody a week. So here is what Guardian Plus does not do — plainly enough that you can rule us in or out before you book a call.
We’d rather answer it early than at the end. Deployment documentation, the threat model and the network posture guides are available during evaluation, not after signature.