Security & deploymentSingle-tenant, alwaysOutbound TLS only

Built for the networks that don’t allow much

Guardian Plus runs on your infrastructure, one tenant per deployment, with agents that never accept an inbound connection. If your auditor asks where the data lives, the answer is short.

There is no shared cloud instance

Every customer gets their own deployment — on your hardware, in your cloud account, or hosted by us on infrastructure dedicated to you. Your Suite pairs only with your own product instances and your own secrets.

Self-hosted

Install on your own servers with the OS installers, or run the container images in your own environment. Nothing phones home except a daily licence check.

Hosted by us, dedicated

We’ll run it for you — but on infrastructure dedicated to your organisation. It is still your deployment, not a slot in a shared one.

Single-tenant, always

There is no multi-tenant mode. Your database, your keys, your instance. No other customer’s data has ever been in it.

Three ways to place it on your network

Most platforms give you one topology and expect your network to accommodate it. We document three, including one where the management plane sits behind a single inbound rule you can close entirely.

One trusted network

Everything on one trusted network. The simplest deployment, appropriate when your management plane and your endpoints already share a security boundary. Fastest to stand up; no inbound rules on endpoints; suited to a single office or data centre.

Roaming workforce

Endpoints anywhere — home, hotel, client site — while the management console itself stays restricted to your office network or VPN. Agents reach in from any network; console access stays behind your perimeter; no endpoint ever exposed to the internet.

Isolated management network

The monitoring plane sits on a private network with exactly one inbound rule. Close even that, and you trade nothing but a delay of up to an hour before a revoked session stops working. Built for segmented and regulated environments.

The agent never accepts a connection

Every managed endpoint dials out over TLS and keeps one authenticated socket open. Nothing listens. There is no firewall rule to add, no port to forward, no VPN to maintain — and browser-based terminal and remote desktop both ride that same outbound connection.

Windows, macOS on Intel and Apple Silicon, and 64-bit Ubuntu, Rocky, CentOS Stream and SUSE. Devices you can’t install on — switches, firewalls, printers, appliances — are reached from the outside by a collector.

Where a port does open

Each is optional and scoped to a machine you choose.

A collector — an agent promoted to reach devices that can’t run one — binds a local port to proxy for them.

A trap receiver you designate listens for SNMP traps from your network devices.

Remote desktop on macOS and Linux uses the operating system’s own screen-sharing service on loopback, relayed out over the agent’s existing connection.

Outbound TLS onlySigned installers per platformSurvives sleep, wake and bad Wi-Fi

Encryption with a key per scope

Credentials, documents, ticket contents and integration secrets are encrypted at rest with AES-256-GCM. Keys aren’t shared across the platform — each company, and each individual’s private vault, gets its own key derived from the master. If the service can’t decrypt with the key it was given at boot, it refuses to start rather than run half-blind.

AES-256-GCM at rest

Authenticated encryption with a fresh initialisation vector per record. A tampered record fails to decrypt rather than returning garbage.

A key per scope

Derived per company — and per person for private vaults — so one company’s key can never open another’s data.

Refuses to start blind

On boot the service proves it can decrypt with the key it was handed. If it can’t, it exits instead of running.

Secrets never in the browser

Credentials injected into a remote session are resolved server-side. The operator’s browser is never sent the plaintext.

No third-party AI vendor.

Guardian Plus runs open-weight models on infrastructure we operate — or on your own, if you’d rather host them. There is no OpenAI account, no Anthropic account, no Azure OpenAI endpoint anywhere in the platform. Your command output, your ticket contents and your monitoring data are never handed to a model vendor.

It asks before it acts

Approve every step, approve the plan once, or let it run. Destructive commands stop for a human even on unattended mode.

It inherits your permissions

Every tool the assistant calls re-derives the permissions of whoever asked. It cannot see a record you cannot see.

It is kept away from your secrets

Write actions are hidden from the assistant entirely and need a person to confirm. Your most sensitive documents are never fed to a model at all.

Access control, and what gets recorded

Single sign-on across every module

One identity provider with multi-factor authentication. Deactivate someone once and every product session ends immediately. Federate to Microsoft Entra or Okta over OpenID Connect, or sync users from Active Directory.

Permissions by action, not by page

Dozens of individually grantable actions, assigned through your groups, with grants that can carry an expiry date. If a permission check errors, access is denied — a degraded service does not become an open one.

Private stays private

A person’s private vault cannot be opened by any administrator, including a super admin — and the attempt is recorded.

Every sign-in, permanently

The authentication log cannot be edited or deleted, by anyone, through any interface.

Every ticket change

Service desk history is append-only, enforced by the database itself rather than by application code that could be bypassed.

Every credential reveal

Who, when, from where, and which permission allowed it — including whether it came from an administrator override.

Every suppressed alert

When a notification is withheld, the reason is recorded. You can always answer why something didn’t page.

What we do not do

Security teams have to verify claims, and vague ones cost everybody a week. So here is what Guardian Plus does not do — plainly enough that you can rule us in or out before you book a call.

Send us your security questionnaire

We’d rather answer it early than at the end. Deployment documentation, the threat model and the network posture guides are available during evaluation, not after signature.