Connections and flows
Who talked to whom, for how long, in which direction, and how much moved. Flow accounting is maintained in both directions, so a quiet upload is as visible as a noisy download.
Guardian
The Guardian is an appliance you place on a network you operate. It observes the traffic you have authorised it to observe, evaluates it continuously, and preserves what matters — without sending anything anywhere.
Capability
The Guardian reconstructs activity from the traffic it is authorised to see. It does not break encryption, and it does not need to in order to be useful.
Who talked to whom, for how long, in which direction, and how much moved. Flow accounting is maintained in both directions, so a quiet upload is as visible as a noisy download.
Domain lookups as they appeared on the wire — the name asked for, and the address returned for answered lookups. This is the record that ties a numeric destination back to a name a human can reason about. Failed lookups and encrypted resolution are recorded as visibility gaps rather than presented as answers.
Characteristics that are visible without decryption: the server name a client asked for, and a fingerprint of how it negotiated the session. Encrypted traffic is not entirely opaque traffic — but nothing is decrypted, and what stays encrypted stays encrypted.
Repetition, regularity and timing. Activity that repeats on a schedule looks different from activity a person caused, and that difference is measurable. Statistical and machine-learning methods flag activity that departs from what a device has established as its own normal.
Observations are evaluated against indicator sets held by your deployment, including indicators associated with commercial surveillance tooling drawn from published research.
Destinations are enriched with network intelligence — ownership, hosting and geography — so an unfamiliar address can be placed in context during triage rather than after it.
Operating modes
The Guardian distinguishes between watching an environment and working a case, and the distinction is enforced in the data rather than only in the interface. An engagement has a defined start and end, and its evidence does not absorb activity from outside that boundary.
Continuous observation of an authorised environment, with live detection and alerting. Used to understand a network's normal behaviour and to notice when something departs from it.
A bounded engagement attached to a specific case. Everything collected inside the boundary belongs to that case; everything outside it does not. The boundary is part of the evidential record.
Identity
An appliance that cannot prove which appliance it is undermines the evidence it produces. Identity is built into the Guardian rather than configured onto it.
The mechanisms behind these are described in full on the Security & Trust page.
Deployment
The Guardian is delivered as a self-contained appliance. It observes the network segment it is attached to, under the authorisation you have established for that environment.
The limits
Being clear about limits is part of being credible about capability.
A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.