Endpoint Security
Prevention, behavioural detection, forensic recording and one-click rollback for Windows, macOS and Linux, including air-gapped and VDI estates.
Licensed per endpoint · 14 pages · Rev 2026.2
Specifications, limits and deployment guidance
Module datasheets, agent footprints, supported platforms, ingest limits, retention options and rollout guides for Guardian Sentinel. Published openly — no form, no sales gate, no asterisk hiding the real figure.
Module datasheets
Each PDF covers the module's detection coverage, deployment prerequisites, resource requirements, data handling, licensing unit and known limitations. Yes, there is a limitations section — it is on page two, not buried in an appendix.
Prevention, behavioural detection, forensic recording and one-click rollback for Windows, macOS and Linux, including air-gapped and VDI estates.
Licensed per endpoint · 14 pages · Rev 2026.2
East-west visibility, encrypted traffic analysis without decryption, inline blocking and microsegmentation policy for datacentre and campus.
Licensed per Gbps inspected · 16 pages · Rev 2026.2
Posture management, workload runtime protection, container and Kubernetes defence, infrastructure-as-code scanning and control-plane monitoring.
Licensed per workload · 18 pages · Rev 2026.2
Directory and identity-provider telemetry, privilege path analysis, session anomaly detection and automated credential or token revocation.
Licensed per identity · 12 pages · Rev 2026.2
Classification at rest and in motion, lineage tracking, egress control and content-aware response across endpoint, cloud storage and SaaS.
Licensed per user · 15 pages · Rev 2026.2
The correlation and behavioural analytics layer: cross-surface incident assembly, ATT&CK mapping, confidence scoring and analyst reasoning traces.
Included with any module · 20 pages · Rev 2026.2
Playbook engine, guardrail and approval model, blast-radius limits, reversible actions and the full audit record for every autonomous decision.
Included with any module · 17 pages · Rev 2026.2
Adversary profiles, indicator feeds in STIX 2.1 and MISP formats, attribution confidence levels and the intelligence-to-detection pipeline.
Licensed per tenant · 13 pages · Rev 2026.2
Connector catalogue, authentication models, rate limits, webhook delivery guarantees and the streaming export schema for your data lake.
Included with any module · 22 pages · Rev 2026.2
Service description for Guardian MDR: coverage model, escalation paths, three-minute acknowledgement service level and the responsibility matrix.
Service datasheet · 11 pages · Rev 2026.2
Retainer terms, activation procedure, remote and on-site response timelines, evidence handling standards and post-incident reporting scope.
Service datasheet · 9 pages · Rev 2026.2
Control mappings for SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, DORA and NIS2, with the report templates that satisfy each evidence request.
Reference pack · 34 pages · Rev 2026.2
Reference architecture
Sensors collect locally and enforce locally. The analytics plane correlates across surfaces. Nothing in the response path depends on a round trip to the cloud, which is why containment still works when the link to us is down.
Technical specifications
Figures are p95 measurements from production tenants, not best-case laboratory numbers. Where a platform has a caveat, it is stated in the row.
| Platform | Supported versions | CPU (p95) | RAM | Disk | Reboot on install | Notes |
|---|---|---|---|---|---|---|
| Windows desktop | 10 (1809+), 11 | 0.6% | 88 MB | 1.4 GB | Not required | Full rollback requires VSS enabled |
| Windows Server | 2016, 2019, 2022, 2025 | 0.8% | 104 MB | 2.0 GB | Not required | Core and Nano installations supported |
| macOS | 13 Ventura and later | 0.5% | 76 MB | 1.1 GB | Not required | System extension approval via MDM |
| Linux (eBPF) | Kernel 5.8+ · RHEL 9, Ubuntu 22.04+, Debian 12, SLES 15 | 0.4% | 64 MB | 900 MB | Not required | No kernel module compiled or loaded |
| Linux (legacy module) | Kernel 3.10–5.7 · RHEL 7/8, CentOS 7 | 0.9% | 92 MB | 900 MB | Recommended | Signed module; extended support to 2028 |
| Kubernetes | 1.26+ · EKS, AKS, GKE, OpenShift 4.12+ | 0.3% / node | 120 MB / node | 600 MB | Not required | DaemonSet plus admission controller |
| Container runtime | containerd 1.6+, CRI-O 1.26+, Docker 24+ | Included | Included | Included | Not required | Covered by the node DaemonSet |
| Serverless | Lambda, Azure Functions, Cloud Run | +3 ms | 18 MB | n/a | Not required | Layer or extension, cold-start impact measured |
| Mobile | iOS 16+, Android 12+ | Negligible | 42 MB | 180 MB | Not required | Detection only; no on-device containment |
| OT / ICS | Passive collector appliance | n/a | n/a | n/a | Not required | No agent on controllers; span or tap only |
Scroll the table sideways to see every column.
Disk figures include the local forensic buffer at default retention. Sizing for extended local retention is covered in the deployment guide below.
Scale and limits
Published limits are the ones enforced in the product. Anything above them is available, but it is a conversation with an architect rather than a configuration change, because it usually implies a topology decision.
| Dimension | Standard | Enterprise | Sovereign |
|---|---|---|---|
| Protected assets per tenant | 25,000 | 500,000 | Unlimited |
| Telemetry retention (hot) | 30 days | 90 days | Customer defined |
| Telemetry retention (cold) | 1 year | 7 years | Customer defined |
| API requests per minute | 600 | 6,000 | Configurable |
| Streaming export throughput | 50 MB/s | 500 MB/s | Configurable |
| Custom detections | 500 | 10,000 | Unlimited |
| Response playbooks | 50 | 1,000 | Unlimited |
| Child tenants (multi-tenancy) | Not available | 250 | Unlimited |
Scroll the table sideways to see every column.
Full commercial terms are on the pricing page. Sovereign tier covers self-hosted and air-gapped control planes.
Detection latency against sustained ingest
Benchmark environment: single Enterprise tenant, EU region, mixed endpoint and cloud telemetry. Reproduction methodology is in the Integrations & API datasheet.
Deployment guides
The median enterprise deployment reaches 90 percent endpoint coverage in eleven days. These guides are the ones our own deployment engineers follow, published verbatim.
Network egress and proxy requirements, MDM profiles for macOS system extensions, exclusion strategy for existing security tooling, and the pilot group definition. Typically half a day of work.
Preparation checklistDeploy to 200–500 representative assets in detect-only mode. Validate performance on your heaviest workloads, confirm no conflict with the incumbent agent, and tune the first exclusion set.
Pilot guideRing-based rollout through your existing software distribution channel. Cloud and identity connectors are enabled in parallel — they need no endpoint work and usually deliver the first real findings.
Rollout guideMove from recommend-only to autonomous containment one intrusion class at a time, with guardrails, change-window awareness and a documented rollback for every action.
Response guideGuardian is designed to run alongside another endpoint agent for the length of a parallel evaluation. The migration guide covers mutual exclusion paths for the eight most common incumbents, the order in which to remove the old agent, and how to preserve historical detection evidence before decommissioning.
Median parallel-run period across enterprise migrations is 45 days. We do not recommend shorter unless you have a compelling reason.
Golden image preparation, sensor identity handling on clone, and the reduced local buffer configuration for non-persistent pools. Includes tested guidance for the major VDI platforms and the storage impact figures you will be asked for by the platform team.
Self-hosted control plane sizing, the offline intelligence package format and delivery cadence, and the cross-domain transfer procedure for detection content. Written against FedRAMP High and equivalent national frameworks; see compliance for current authorisations.
Tenant hierarchy design, cross-tenant detection content distribution, per-customer data boundaries and the role model that lets an analyst work across tenants without being able to export between them. Required reading for Guardian partners.
Collector placement across Purdue levels, span and tap configuration, protocol parser enablement for Modbus, DNP3, OPC UA, PROFINET and EtherNet/IP, and the safety review checklist to complete with your engineering team before any response capability is enabled.
Developer documentation
There is no privileged internal API. The console is built on the same documented, versioned REST and streaming interfaces you get, authenticated with OAuth 2.0 client credentials and scoped to the same role model.
// Retrieve open incidents above a confidence threshold
GET /v3/incidents?status=open&min_confidence=0.85
Authorization: Bearer <access_token>
Accept: application/json
// 200 OK
{
"items": [
{
"id": "inc_01J8ZQ4K7M",
"severity": "critical",
"confidence": 0.97,
"surfaces": ["identity", "endpoint"],
"technique": "T1550.001",
"first_observed": "2026-08-04T09:41:22Z",
"contained_at": "2026-08-04T09:41:58Z",
"actions": ["session.revoke", "host.isolate"]
}
],
"next_cursor": "eyJvZmZzZXQiOjI1fQ"
}
Everything else
Looking for narrative rather than specifications? The whitepapers cover architecture reasoning, the case studies show these specifications in production, and the glossary defines any term used above that is new to you.
Deploy Guardian Sentinel in your own environment and measure the footprint, the latency and the detection quality against the figures on this page.