Guardian

Authorised network observation, on your own ground

The Guardian is an appliance you place on a network you operate. It observes the traffic you have authorised it to observe, evaluates it continuously, and preserves what matters — without sending anything anywhere.

The ForensicsGuard Wi-Fi sensor appliance beside a mobile handset running the Mobile Sensor

Capability

What the Guardian observes

The Guardian reconstructs activity from the traffic it is authorised to see. It does not break encryption, and it does not need to in order to be useful.

Connections and flows

Who talked to whom, for how long, in which direction, and how much moved. Flow accounting is maintained in both directions, so a quiet upload is as visible as a noisy download.

Name resolution

Domain lookups as they appeared on the wire — the name asked for, and the address returned for answered lookups. This is the record that ties a numeric destination back to a name a human can reason about. Failed lookups and encrypted resolution are recorded as visibility gaps rather than presented as answers.

Encrypted sessions

Characteristics that are visible without decryption: the server name a client asked for, and a fingerprint of how it negotiated the session. Encrypted traffic is not entirely opaque traffic — but nothing is decrypted, and what stays encrypted stays encrypted.

Behaviour and anomaly analysis

Repetition, regularity and timing. Activity that repeats on a schedule looks different from activity a person caused, and that difference is measurable. Statistical and machine-learning methods flag activity that departs from what a device has established as its own normal.

Indicator matching

Observations are evaluated against indicator sets held by your deployment, including indicators associated with commercial surveillance tooling drawn from published research.

Network context

Destinations are enriched with network intelligence — ownership, hosting and geography — so an unfamiliar address can be placed in context during triage rather than after it.

Operating modes

Two ways to run it

The Guardian distinguishes between watching an environment and working a case, and the distinction is enforced in the data rather than only in the interface. An engagement has a defined start and end, and its evidence does not absorb activity from outside that boundary.

General Monitoring

Continuous observation of an authorised environment, with live detection and alerting. Used to understand a network's normal behaviour and to notice when something departs from it.

Case acquisition

A bounded engagement attached to a specific case. Everything collected inside the boundary belongs to that case; everything outside it does not. The boundary is part of the evidential record.

Identity

Every Guardian is a specific Guardian

An appliance that cannot prove which appliance it is undermines the evidence it produces. Identity is built into the Guardian rather than configured onto it.

Guardian ID
Each appliance carries a stable identifier derived from its own hardware identity. It is what a licence is issued against and what evidence is attributed to.
Hardware-bound licensing
Licences are cryptographically signed and bound to a specific Guardian ID. A licence issued for one appliance does not operate another.
Signed software integrity
Releases ship with a signed manifest covering the software components. The Guardian verifies itself against it and reports the result honestly — including reporting that it does not know, when it does not.
Evidence sealing
Material taken as evidence is hashed and sealed, with its origin, time and case attached. Later tampering is detectable rather than assumed away.
Offline verification
Verification is a signature check against a published key. It works without contacting us and without an internet connection.

The mechanisms behind these are described in full on the Security & Trust page.

Deployment

Placed where you decide, run how you decide

The Guardian is delivered as a self-contained appliance. It observes the network segment it is attached to, under the authorisation you have established for that environment.

  • No external dependency for core operation Capture, detection, storage and case work continue without internet access.
  • Local storage under your control Observations and captures are written to storage inside the appliance.
  • Enrolled to a Lab Station Guardians are discovered, identity-confirmed and administered from the Lab Station.
  • Health that reports honestly The appliance monitors its own condition and surfaces degradation rather than hiding it.

The limits

What the Guardian is not

Being clear about limits is part of being credible about capability.

Not an interception product for networks you do not control
It is designed to observe an environment you operate and have authorised. It is not built or sold for covert interception of third-party communications.
It does not decrypt anything
It works with what is observable without decryption. Where a session is encrypted, the content stays encrypted. Where name resolution is itself encrypted, the Guardian records that it could not see it rather than implying it could.
It does not replace examination tooling
Established acquisition and examination platforms remain necessary. The Guardian adds the behaviour-over-time dimension they do not cover.
It does not make the finding
Detection prioritises analyst attention. The conclusion is the analyst's, and the platform is built to support that judgement rather than substitute for it.
No detection is guaranteed
Observation is bounded by what is visible on the network segment it is attached to, during the period it was running. An absence of findings is a statement about that window, not about the device.

See it on your own network

A pilot puts a Guardian and a Lab Station into your environment, on a network you control, with your own team running the workflow.