The Guardian Sentinel platform

One platform for every attack surface, autonomous from first signal to containment

Guardian Sentinel replaces a shelf of disconnected point products with a single agent, a single data layer and a single console. Telemetry from endpoint, network, cloud, identity and data is normalised once, reasoned over by the same models, and acted on in a median of 3.8 seconds — without an analyst having to stitch four tools together first.

Deployed in 142 countries · 6,800+ organisations · 43 of the Fortune 100

4.2T Security events ingested and scored every week across the Guardian fleet
3.8s Median time from malicious signal to automated containment action
99.99% Measured control-plane availability across 14 regions, trailing 12 months
92% Average reduction in analyst-facing alert volume after 90 days
1 Agent, schema, policy engine and console for all five surfaces

Architecture

Built as one system, not a suite assembled after the acquisitions

Most security “platforms” are four products in a shared invoice: four agents, four schemas, four consoles, and a correlation problem the customer inherits. Guardian Sentinel is a single vertically integrated pipeline — collection, normalisation, reasoning and response are stages of one system, written by one engineering organisation, shipped on one release train.

Endpoint Network Cloud Identity Data servers · laptops · VDI north-south & east-west VMs · containers · PaaS IdP · AD · PAM stores · SaaS · email Sentinel agent & sensor mesh Kernel-level collection · enrichment at source · 87% average volume reduction before egress Sentinel Data Fabric One OCSF-normalised schema · entity resolution across all five surfaces · 365-day hot retention Assets Identities Sessions Process lineage Data objects Behavioural analytics Correlation & attack graph Intelligence & AI Analyst Per-entity baselines Sequence & lineage models On-device inference Cross-surface stitching Blast-radius scoring MITRE ATT&CK mapping Adversary attribution Automated triage narrative Evidence assembly Autonomous response engine Isolate host · kill process tree · quarantine object · revoke session · block indicator · roll back changes Sentinel console Open API & webhooks 400+ integrations Investigate, hunt, report Everything the UI can do SIEM, ITSM, IdP, ticketing

Scroll horizontally to see the full diagram on a small screen.

Guardian Sentinel reference architecture. Every stage shares one identity model, one policy engine and one release train.

One agent, not four

A single 42 MB binary delivers prevention, EDR, device control, vulnerability assessment and network sensing. No plug-in chains, no conflicting drivers, no second reboot cycle.

Inside the agent

One schema, not four

Every event — a process launch, a TLS handshake, an AssumeRole, a mailbox rule — lands in the same OCSF-aligned record shape with the same entity keys. Joins are free.

See the data layer

One decision loop

Detection and response are not separate products handing each other tickets. The engine that scores the behaviour is the engine that authorises containment, under one policy grammar.

Response & automation

Unified data layer

The data layer is the product

Detection quality is bounded by how well your telemetry joins. Guardian Sentinel resolves every observation to a durable entity — a person, a device, a workload, a data object — the moment it is written, so a question that used to take four consoles and a spreadsheet becomes one query against one graph.

  • Normalised at the edge. The agent and sensors emit OCSF-aligned records, so nothing depends on brittle parsing rules downstream.
  • Entity resolution on write. A laptop, its logged-in identity, the SSO session, the cloud role it assumed and the object it read become one connected subgraph.
  • 365 days hot, seven years cold. Year-long hunts run at interactive speed; archives rehydrate into the same schema without a migration project.
  • Priced per endpoint, not per gigabyte. Ingest volume never becomes a budget conversation, so teams stop deleting the telemetry they will need later.
  • Open on both ends. Stream the normalised fabric into your existing SIEM or lake, and pull third-party telemetry in through 400+ connectors.
agent telemetry OAuth token assumed role object read TLS session ENDPOINT IDENTITY CLOUD DATA NETWORK LT-4471 SSO 8f2c eks-prod-7 s3://ledger 10.42.6.19 CORRELATED ENTITY j.okafor One incident, five surfaces, zero manual joins Resolved on write · queryable for 365 days · exportable as OCSF

Scroll horizontally to see the full chart on a small screen.

87% Telemetry compressed at source before it leaves the host
340ms p95 query latency over a 90-day window, 100k endpoints
365d Hot retention included on every Enterprise licence

Modules

Nine modules. One licence, one deployment, one investigation.

Enable what you need today and switch on the rest without a new agent, a new contract vehicle or a new data pipeline. Every module writes into the same fabric, so coverage you add on Monday improves detections everywhere else by Tuesday.

Threat detection

Behavioural models, sequence analysis and attack-graph correlation that surface real intrusions in seconds and suppress the rest. 214 MITRE ATT&CK techniques covered.

Explore threat detection

Endpoint security

Prevention, EDR, device control and one-click rollback in a single agent that holds under 1.2% CPU at steady state and keeps protecting when the device is offline.

Explore endpoint security

Network security

Network detection and response with true east-west visibility, encrypted traffic analysis without decryption, and inline blocking at the sensor or the firewall.

Explore network security

Cloud security

CNAPP across AWS, Azure and Google Cloud: posture, entitlements, workload runtime, Kubernetes and infrastructure-as-code scanning in the developer's pull request.

Explore cloud security

Identity protection

Credential theft, Kerberos abuse, token replay and privilege escalation caught at the directory and the identity provider, with session revocation in under two seconds.

Explore identity protection

Data protection

Classification that follows the object rather than the location, with movement monitoring across endpoints, SaaS, email and cloud stores — and containment before exfiltration completes.

Explore data protection

Automation & response

Playbooks written in plain policy, executed at machine speed, with an approval model that lets you keep humans in the loop exactly where you want them.

Explore automation

Threat intelligence

Guardian Labs tracks 340 named adversary groups and pushes new detection logic to every tenant continuously — no content packs to import, no rule tuning weekend.

Explore threat intelligence

Integrations

400+ certified connectors for SIEM, SOAR, ITSM, identity providers, ticketing and data lakes, plus a documented REST and streaming API with parity to the console.

Explore integrations

Deployment

Run it where your regulator, your architecture and your latency budget require

The same code, the same detections and the same console ship in four deployment shapes. Tenants can move between them without re-instrumenting endpoints or losing history.

Guardian Cloud — multi-tenant SaaS

The default for most organisations. Fully managed across 14 regions, with per-tenant encryption keys, hardware-backed key custody and a 99.99% availability commitment. New detection content reaches your tenant within four hours of publication.

  • Median time to first detection after agent install: 11 minutes
  • Data residency pinned to a named region; no cross-region replication unless you enable it
  • Zero infrastructure to size, patch or scale

Sovereign region — single-tenant, in-country

A dedicated control plane and dedicated storage inside a jurisdiction you nominate, operated by Guardian but isolated from the multi-tenant fleet. Built for regulated workloads under DORA, NIS2, national banking rules and public-sector frameworks.

  • Named-operator access controls with customer-visible break-glass audit
  • Customer-managed keys with external HSM or KMS custody
  • Available in 9 jurisdictions, including FedRAMP High environments

Self-managed — your Kubernetes, your cloud account

Deploy the full control plane into your own EKS, AKS, GKE or OpenShift cluster with a signed Helm chart. You own the infrastructure, the storage tier and the upgrade cadence; Guardian ships releases and detection content you pull on your schedule.

  • Reference sizing from 2,500 to 250,000 endpoints, published per node class
  • Storage on S3-compatible object storage you already operate
  • Signed images with SLSA provenance and a published SBOM per release

Air-gapped — no outbound connectivity at all

For classified networks, defence programmes and operational-technology environments that cannot route to the internet. Detection content, models and platform updates arrive as signed offline bundles verified against an offline root of trust.

  • Weekly signed content bundles; models run entirely on local inference
  • Full behavioural detection retained with no cloud lookup dependency
  • Deployed today across 34 defence and critical-infrastructure programmes

Mixed estates are normal. Many customers run Guardian Cloud for corporate IT and an air-gapped enclave for OT or classified networks, federated into one reporting view. See energy & utilities and government & defence for reference designs.

Comparison

What changes when the platform is actually one platform

A side-by-side against the two architectures most enterprises are running today: a legacy antivirus plus SIEM stack, and a best-of-breed collection of modern point tools.

Architecture comparison. Point-tool figures reflect the median of 412 competitive displacements Guardian completed between January 2025 and March 2026.
Capability Legacy AV + SIEM Best-of-breed point tools Guardian Sentinel
Agents on the endpoint 3–5, often conflicting 3–4, one per vendor 1
Telemetry schema Vendor-specific, parsed downstream with fragile regex Per-product schemas, joined manually in the SIEM One OCSF-aligned schema, resolved to entities on write
Detection logic Signatures plus hand-written correlation rules Per-surface models with no shared context Cross-surface behavioural models over a shared entity graph
Mean time to detect Hours to days 14–40 minutes Under 5 seconds
Mean time to contain Manual, measured in hours Semi-automated, 8–25 minutes 3.8 seconds, autonomous
Analyst alerts per 10k endpoints, per day 1,900+ 380 27
Retention economics Per-gigabyte ingest billing; teams drop telemetry to control cost Mixed; hot windows typically 30–90 days 365 days hot, included per endpoint
Cloud and container runtime coverage None or agent-only Separate CNAPP vendor and separate console Native CSPM, CWPP, CIEM, KSPM and IaC scanning
Identity signal in endpoint detections Not correlated Correlated after the fact, if at all Native — identity is a first-class entity in the graph
Rollback of encrypted or altered files Restore from backup Partial, endpoint only One-click, per-host or per-incident
Time to full deployment, 25k endpoints 6–12 months 10–16 weeks 9 days median
Three-year total cost of ownership Baseline −12% vs baseline −41% vs baseline

Scroll the table horizontally to see every column.

Figures are medians from Guardian deployment telemetry and customer-reported finance data. Your results will vary with estate composition and starting maturity — ask for a modelled estimate against your own environment.

Adoption path

From first agent to full autonomy in four stages

Nobody flips autonomous response on across 40,000 endpoints on day one. Guardian's rollout model earns trust in measurable steps, and every stage is reversible.

Observe

Deploy the agent in detect-only mode to a pilot ring. Sentinel builds per-entity baselines, inventories the estate and reports what your current stack is missing. No enforcement, no user impact.

Prevent

Turn on prevention for the highest-confidence classes — known-malicious execution, credential dumping, ransomware canaries. Typical false-positive rate at this stage is under 0.2%.

Automate

Enable containment playbooks with approval gates for the actions you consider disruptive. The AI Analyst writes the incident narrative; your team approves the action in one click.

Delegate

Move proven playbooks to fully autonomous execution and keep humans on the exceptions. Most customers reach this stage on their top ten detection classes within 90 days.

We removed four products and a full-time SIEM engineer's worth of rule maintenance. What surprised us was not the consolidation — it was that our detection coverage went up while our alert volume fell by an order of magnitude.
Marcus Reyes VP Security Operations, Northlane Financial

Measured after 12 months, 31,400 endpoints

94%Fewer analyst-facing alerts
4Products retired
11×Faster mean time to contain
£2.1mAnnual run-rate saving

Northlane consolidated endpoint, network and cloud detection onto Sentinel in three waves over nine weeks, retiring a legacy EPP, a standalone NDR appliance fleet, a CSPM tool and 62% of their SIEM ingest volume.

Read the full case study

Platform questions

What security architects ask us first

Do we have to replace our SIEM to adopt Sentinel?

No. Sentinel streams normalised OCSF records to Splunk, Microsoft Sentinel, Elastic, Chronicle, Snowflake and S3-compatible lakes, so your SIEM keeps its compliance and log-of-record role. In practice most customers reduce SIEM ingest by 50–70% because the raw endpoint and network firehose no longer needs to land there to be useful.

How much of the detection works without cloud connectivity?

The on-device models — static classification, behavioural sequence analysis, ransomware canary monitoring and script-behaviour analysis — run entirely locally and can block and quarantine with no network at all. Cross-surface correlation and the AI Analyst narrative require the control plane, and queue locally until the host reconnects. See endpoint security for the full offline behaviour matrix.

Can we bring our own detection content?

Yes. Custom detections are authored in Sentinel Query Language, version-controlled in your own Git repository and promoted through dev, staging and production tenants via the API. Sigma rules import natively, and you can unit-test detections against recorded telemetry before promotion.

What happens to our historical data if we leave?

You can export the full normalised fabric as OCSF-formatted Parquet at any time, at no charge, through the bulk export API. Guardian does not hold your telemetry hostage as a retention mechanism — the contractual export window is 90 days after termination.

How do you handle model updates without breaking our tuning?

Every model release is shadow-scored against 30 days of your own telemetry before it takes effect, and the projected change in alert volume is shown in the console prior to promotion. You choose automatic, staged or manual promotion per detection family, and can roll back to any prior model version for 180 days.

Is there a services option if we do not run a 24/7 SOC?

Yes. Guardian MDR operates the platform on your behalf with a three-minute triage SLA and named analysts, and incident response is available on retainer with a one-hour engagement commitment. Both operate inside your tenant, so you keep full visibility of every action taken.

More answers in the support FAQ and the security glossary.

See Sentinel run against your own telemetry

A 45-minute technical walkthrough with a Guardian solutions architect — architecture, detection quality, deployment shape and a modelled cost comparison against what you run today.