Specifications, limits and deployment guidance

The numbers your architecture review will ask for

Module datasheets, agent footprints, supported platforms, ingest limits, retention options and rollout guides for Guardian Sentinel. Published openly — no form, no sales gate, no asterisk hiding the real figure.

<1% Sustained CPU per protected endpoint Measured at p95 across 6,800 tenants
92 MB Resident memory, full sensor Windows, macOS and Linux builds
99.99% Contractual platform availability Measured monthly, credits apply
400+ Documented integrations and connectors Plus a fully open REST and streaming API

Module datasheets

One datasheet per module, all ungated

Each PDF covers the module's detection coverage, deployment prerequisites, resource requirements, data handling, licensing unit and known limitations. Yes, there is a limitations section — it is on page two, not buried in an appendix.

Endpoint Security

Prevention, behavioural detection, forensic recording and one-click rollback for Windows, macOS and Linux, including air-gapped and VDI estates.

Licensed per endpoint · 14 pages · Rev 2026.2

Network Security

East-west visibility, encrypted traffic analysis without decryption, inline blocking and microsegmentation policy for datacentre and campus.

Licensed per Gbps inspected · 16 pages · Rev 2026.2

Cloud Security

Posture management, workload runtime protection, container and Kubernetes defence, infrastructure-as-code scanning and control-plane monitoring.

Licensed per workload · 18 pages · Rev 2026.2

Identity Protection

Directory and identity-provider telemetry, privilege path analysis, session anomaly detection and automated credential or token revocation.

Licensed per identity · 12 pages · Rev 2026.2

Data Protection

Classification at rest and in motion, lineage tracking, egress control and content-aware response across endpoint, cloud storage and SaaS.

Licensed per user · 15 pages · Rev 2026.2

Threat Detection

The correlation and behavioural analytics layer: cross-surface incident assembly, ATT&CK mapping, confidence scoring and analyst reasoning traces.

Included with any module · 20 pages · Rev 2026.2

Automation & Response

Playbook engine, guardrail and approval model, blast-radius limits, reversible actions and the full audit record for every autonomous decision.

Included with any module · 17 pages · Rev 2026.2

Threat Intelligence

Adversary profiles, indicator feeds in STIX 2.1 and MISP formats, attribution confidence levels and the intelligence-to-detection pipeline.

Licensed per tenant · 13 pages · Rev 2026.2

Integrations & API

Connector catalogue, authentication models, rate limits, webhook delivery guarantees and the streaming export schema for your data lake.

Included with any module · 22 pages · Rev 2026.2

Managed Detection & Response

Service description for Guardian MDR: coverage model, escalation paths, three-minute acknowledgement service level and the responsibility matrix.

Service datasheet · 11 pages · Rev 2026.2

Incident Response Retainer

Retainer terms, activation procedure, remote and on-site response timelines, evidence handling standards and post-incident reporting scope.

Service datasheet · 9 pages · Rev 2026.2

Compliance Evidence Pack

Control mappings for SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, DORA and NIS2, with the report templates that satisfy each evidence request.

Reference pack · 34 pages · Rev 2026.2

Reference architecture

How the pieces fit together

Sensors collect locally and enforce locally. The analytics plane correlates across surfaces. Nothing in the response path depends on a round trip to the cloud, which is why containment still works when the link to us is down.

guardian-sentinel / reference-architecture
Sensors Endpoint agent Kernel + user mode, offline capable Network sensor Virtual or hardware tap Cloud connector Agentless + runtime eBPF Identity connector Directory + IdP event streams Data sensor Classification at rest and in motion Streaming ingest Regional, encrypted Sentinel analytics plane Cross-surface correlation Behavioural AI & reasoning Intelligence enrichment Response engine Guardrails, approvals, reversible actions, audit Enforcement executes locally at the sensor — containment continues if the cloud link drops
Data residency Choose a processing region at tenant creation: United States, European Union, United Kingdom, United Arab Emirates, Singapore, Australia or Canada. Telemetry never leaves the selected region.
Offline resilience Sensors hold 72 hours of buffered telemetry and continue prevention and containment with the last-known policy if connectivity is lost.
Air-gapped deployment A self-hosted control plane is available for classified and isolated environments, with offline intelligence packages delivered on a defined cadence.

Technical specifications

Sensor footprint and platform support

Figures are p95 measurements from production tenants, not best-case laboratory numbers. Where a platform has a caveat, it is stated in the row.

Guardian Sentinel sensor requirements by operating system, release 2026.2.
Platform Supported versions CPU (p95) RAM Disk Reboot on install Notes
Windows desktop 10 (1809+), 11 0.6% 88 MB 1.4 GB Not required Full rollback requires VSS enabled
Windows Server 2016, 2019, 2022, 2025 0.8% 104 MB 2.0 GB Not required Core and Nano installations supported
macOS 13 Ventura and later 0.5% 76 MB 1.1 GB Not required System extension approval via MDM
Linux (eBPF) Kernel 5.8+ · RHEL 9, Ubuntu 22.04+, Debian 12, SLES 15 0.4% 64 MB 900 MB Not required No kernel module compiled or loaded
Linux (legacy module) Kernel 3.10–5.7 · RHEL 7/8, CentOS 7 0.9% 92 MB 900 MB Recommended Signed module; extended support to 2028
Kubernetes 1.26+ · EKS, AKS, GKE, OpenShift 4.12+ 0.3% / node 120 MB / node 600 MB Not required DaemonSet plus admission controller
Container runtime containerd 1.6+, CRI-O 1.26+, Docker 24+ Included Included Included Not required Covered by the node DaemonSet
Serverless Lambda, Azure Functions, Cloud Run +3 ms 18 MB n/a Not required Layer or extension, cold-start impact measured
Mobile iOS 16+, Android 12+ Negligible 42 MB 180 MB Not required Detection only; no on-device containment
OT / ICS Passive collector appliance n/a n/a n/a Not required No agent on controllers; span or tap only

Scroll the table sideways to see every column.

Disk figures include the local forensic buffer at default retention. Sizing for extended local retention is covered in the deployment guide below.

Scale and limits

What the platform will do before you have to ask us

Published limits are the ones enforced in the product. Anything above them is available, but it is a conversation with an architect rather than a configuration change, because it usually implies a topology decision.

Default tenant limits by licence tier. Higher limits available on request.
Dimension Standard Enterprise Sovereign
Protected assets per tenant 25,000 500,000 Unlimited
Telemetry retention (hot) 30 days 90 days Customer defined
Telemetry retention (cold) 1 year 7 years Customer defined
API requests per minute 600 6,000 Configurable
Streaming export throughput 50 MB/s 500 MB/s Configurable
Custom detections 500 10,000 Unlimited
Response playbooks 50 1,000 Unlimited
Child tenants (multi-tenancy) Not available 250 Unlimited

Scroll the table sideways to see every column.

Full commercial terms are on the pricing page. Sovereign tier covers self-hosted and air-gapped control planes.

sentinel / ingest-scaling.bench

Detection latency against sustained ingest

4 s 3 s 2 s 1 s 0 10K 100K 500K 1M 1.5M 2M Sustained events per second p99 latency median latency

Benchmark environment: single Enterprise tenant, EU region, mixed endpoint and cloud telemetry. Reproduction methodology is in the Integrations & API datasheet.

Deployment guides

From signed contract to full coverage in four phases

The median enterprise deployment reaches 90 percent endpoint coverage in eleven days. These guides are the ones our own deployment engineers follow, published verbatim.

Prepare

Network egress and proxy requirements, MDM profiles for macOS system extensions, exclusion strategy for existing security tooling, and the pilot group definition. Typically half a day of work.

Preparation checklist

Pilot

Deploy to 200–500 representative assets in detect-only mode. Validate performance on your heaviest workloads, confirm no conflict with the incumbent agent, and tune the first exclusion set.

Pilot guide

Scale

Ring-based rollout through your existing software distribution channel. Cloud and identity connectors are enabled in parallel — they need no endpoint work and usually deliver the first real findings.

Rollout guide

Enable response

Move from recommend-only to autonomous containment one intrusion class at a time, with guardrails, change-window awareness and a documented rollback for every action.

Response guide
Migrating from an existing endpoint product

Guardian is designed to run alongside another endpoint agent for the length of a parallel evaluation. The migration guide covers mutual exclusion paths for the eight most common incumbents, the order in which to remove the old agent, and how to preserve historical detection evidence before decommissioning.

Median parallel-run period across enterprise migrations is 45 days. We do not recommend shorter unless you have a compelling reason.

Virtual desktop and non-persistent estates

Golden image preparation, sensor identity handling on clone, and the reduced local buffer configuration for non-persistent pools. Includes tested guidance for the major VDI platforms and the storage impact figures you will be asked for by the platform team.

Air-gapped and classified environments

Self-hosted control plane sizing, the offline intelligence package format and delivery cadence, and the cross-domain transfer procedure for detection content. Written against FedRAMP High and equivalent national frameworks; see compliance for current authorisations.

Multi-tenant and MSSP deployment

Tenant hierarchy design, cross-tenant detection content distribution, per-customer data boundaries and the role model that lets an analyst work across tenants without being able to export between them. Required reading for Guardian partners.

Operational technology and ICS networks

Collector placement across Purdue levels, span and tap configuration, protocol parser enablement for Modbus, DNP3, OPC UA, PROFINET and EtherNet/IP, and the safety review checklist to complete with your engineering team before any response capability is enabled.

Developer documentation

Everything in the console is in the API

There is no privileged internal API. The console is built on the same documented, versioned REST and streaming interfaces you get, authenticated with OAuth 2.0 client credentials and scoped to the same role model.

  • OpenAPI 3.1 specification published for every endpoint, with generated clients for Python, Go, TypeScript, Java and C#.
  • Webhook delivery with at-least-once guarantees, signed payloads, exponential backoff and a 24-hour replay window.
  • Streaming export in OCSF and ECS schemas to your own data lake or SIEM, with schema versioning and deprecation notice periods.
  • Twelve months minimum between a breaking change being announced and the old version being retired.
// Retrieve open incidents above a confidence threshold
GET /v3/incidents?status=open&min_confidence=0.85
Authorization: Bearer <access_token>
Accept: application/json

// 200 OK
{
  "items": [
    {
      "id": "inc_01J8ZQ4K7M",
      "severity": "critical",
      "confidence": 0.97,
      "surfaces": ["identity", "endpoint"],
      "technique": "T1550.001",
      "first_observed": "2026-08-04T09:41:22Z",
      "contained_at": "2026-08-04T09:41:58Z",
      "actions": ["session.revoke", "host.isolate"]
    }
  ],
  "next_cursor": "eyJvZmZzZXQiOjI1fQ"
}
Full API reference Endpoint reference, authentication guide, rate-limit behaviour, pagination and error taxonomy are documented in the Integrations & API datasheet and the developer portal. Sandbox tenants are available free for integration development — request one.

Everything else

Other documentation you may be looking for

Operations and administration

  • Administrator guide — roles, policy inheritance and tenant configuration
  • Detection authoring reference — query language, testing and promotion
  • Playbook cookbook — 60 tested response playbooks with guardrail settings
  • Release notes archive and the twelve-month deprecation calendar

Assurance and procurement

  • SOC 2 Type II report and ISO 27001 certificate (under NDA)
  • Standard security questionnaire responses, pre-completed
  • Data processing agreement, sub-processor list and transfer mechanisms
  • Software bill of materials for every shipped sensor build

Looking for narrative rather than specifications? The whitepapers cover architecture reasoning, the case studies show these specifications in production, and the glossary defines any term used above that is new to you.

Specifications answered. Ready to test them?

Deploy Guardian Sentinel in your own environment and measure the footprint, the latency and the detection quality against the figures on this page.