SECURITY & PRIVACY BY DESIGN

Trust starts with a boundary.

Guardian performs analysis inside the customer’s environment by design. No required repository upload. Local operation without an internet connection.

LOCAL-FIRST FOUNDATION

Your source stays
in your environment.

Analysis runs against a local project path. Nothing about your project is transmitted to run a scan.

Source & builds

Source code and build artifacts stay local by default. You do not need to upload a repository to use the local product.

Secrets & signing

Secrets, credentials and signing material stay in your environment. They are outside any sharing contract, present or planned.

Production data

Production database rows stay local. No connected feature may give a cloud service direct access to a production database.

Local analysis trust boundary

YOUR ENVIRONMENT PRIVATE BOUNDARY

Private project

Source · builds · secrets

Guardian local engine

Analysis · coverage · policy

Local findings & reports

Inspect · fix · re-run

A local scan completes without a network connection.

Connected safeguards · Planned

You control what
leaves your machine.

The following are requirements for future connected functionality. They are not shipping controls demonstrated by this website.

01 / Default-deny sharing

Cloud synchronization is optional and disabled by default in the architecture. No finding may be sent without explicit user approval.

02 / Inspect the exact payload

Users must see the normalized, redacted outbound findings before sharing. The approved preview must match the transmitted content.

03 / Versioned, signed envelopes

Planned findings envelopes carry a schema version and verifiable signature. Validation, redaction and authorization need implementation and testing before release.

04 / Local work stays independent

A cloud failure must never prevent a local scan from completing. Any optional integration stays a separate product with separate deployments and databases.

Security review is a practice.
Not a guarantee.

No formal certifications or guarantees are claimed. Analysis scope, evidence freshness and configured policy affect the results. Guardian complements engineering and security judgment.

Responsible vulnerability reporting

A verified private reporting channel has not yet been published. Please do not post secrets, customer code, credentials or exploit details through public channels. The product team must establish a private contact before public production launch.

When that channel is available, reports should include the affected version, a minimal sanitized reproduction and potential impact. Coordinated review should keep sensitive material private.

This website’s boundary

This is a static capability website. It does not scan projects, request files or load analytics. If early-access registration is connected, the form posts directly to the named provider and this site stores nothing. The only value kept in your browser is the light or dark theme you choose.

Read the draft website privacy notice
A CLEARER PATH TO RELEASE

Make the next release
an informed decision.

Register interest and we will get in touch when there is a build worth your time.

Get early access