Platform
A single security data model behind every dashboard
Guardian ingests findings from scanners, agents, cloud providers and SaaS platforms, normalizes them, scores them against your business context and drives them to closure.
Core modules
Asset inventory
Network, infrastructure, application, cloud, SaaS, code and container assets with ownership, criticality and compliance scope.
Guardian Agent
Windows, macOS and Linux agents enroll with a one-time token, rotate to device credentials and check in outbound over HTTPS only.
Scan orchestration
Jobs are queued in the platform and executed by isolated, containerized scanner workers — never inside the app itself.
Security intelligence engine
Every source normalizes into one findings model, so cloud misconfigurations and CVEs are prioritized on the same scale.
Automation rules
Route findings by severity, asset criticality and compliance scope into tickets, owners, due dates and notifications.
Remediation and ticketing
Built-in ticketing with SLA tracking, plus bi-directional Jira and ServiceNow synchronization.
Reporting
Executive, technical, penetration test, compliance and POA&M reports generated from stored findings.
Notifications
Email, Microsoft Teams, Slack, webhooks and in-app alerts for new critical risk, scan failures and overdue remediation.
Audit logging
Immutable audit trail of logins, role changes, scans, risk acceptance, suppressions and report downloads.
Architecture
From raw signal to verified fix
Scanning never runs inside the application. Jobs are queued, claimed by hardened containerized workers, and results are written back through an authenticated results API.
- 01Scanners, agents, cloud and SaaS connectors
- 02Security Intelligence Engine (normalization)
- 03Unified findings
- 04Risk prioritization (0–100)
- 05Tickets and owners
- 06Remediation
- 07Automated verification
Security
Built for customers who audit their vendors
Tenant isolation is enforced in the database, not the interface.
Tenant isolation
- Row level security on every table
- Organization scoping enforced server-side
- Separate platform administration layer
Credential handling
- Encrypted secret storage
- Short-lived integration credentials where supported
- No scanner or cloud credentials in the browser
Authorization controls
- Granular role based access control
- Documented target authorization before testing
- Immutable audit logging
