Frequently asked questions

Twenty-seven answers, written by the people who would have to defend them

These are the questions that come up in real evaluations, real deployments and real security reviews — answered with specifics rather than positioning. If something here is wrong or out of date, tell us and we will fix it.

Jump to a category

What people actually search for in Guardian documentation
Sensor deployment & upgrades Detection tuning & exclusions Integrations & the API Licensing & asset counting Data residency & retention Response playbook authoring Everything else 24% 19% 16% 13% 11% 9% 8%

Search volume across Guardian documentation and Guardian Connect, last quarter. The categories below are ordered to match.

27 Questions answered on this page Reviewed every quarter by product and support
11 min Median time to a useful answer in Guardian Connect Faster than opening a Severity 4 case
Not finding it here? The security glossary defines 180+ terms, the support hub covers service levels and escalation, and the contact page reaches a human.

Category 01

Product & platform

What Sentinel is, what it covers and how it behaves on a real machine.

Is Guardian Sentinel one product or a suite of products?

One product, one sensor, one console, one data model. Endpoint, cloud, network, identity and data protection are capabilities of the same platform rather than separately architected tools sharing a logo. That matters operationally: a detection can correlate a process execution on a laptop with an anomalous token issued in your identity provider and an unexpected egress flow, because all three are events in the same graph.

The practical consequence is that you never integrate Guardian with Guardian. There is no connector between our own modules, no duplicate agent, and no reconciliation job to work out whether two consoles are describing the same incident. See the platform overview for the architecture.

Which operating systems and platforms does the sensor support?

Windows 10 21H2 and later, Windows 11, Windows Server 2016 through 2025, macOS 13 Ventura and later on both Apple silicon and Intel, and the major Linux distributions: RHEL and derivatives 8/9/10, Ubuntu LTS 20.04 onward, Debian 11+, SUSE Linux Enterprise 15, Amazon Linux 2 and 2023. Container runtimes covered are containerd, CRI-O and Docker, on Kubernetes 1.26 and later including EKS, AKS, GKE and OpenShift.

Legacy estates are supported with a reduced-capability sensor for Windows Server 2012 R2 and CentOS 7, which many customers still need for OT and clinical systems. Mobile threat defence covers iOS 16+ and Android 12+. Full version matrices and end-of-support dates are in the datasheets.

What is the performance impact of the sensor?

Median steady-state CPU is below 1 percent, resident memory is approximately 180 MB on Windows and 145 MB on Linux, and the installed footprint is under 400 MB including local models. During a full on-demand scan CPU rises to a configurable ceiling that defaults to 25 percent of one core.

The number that usually matters more is boot and login delay, because that is what users complain about. Guardian adds a median of 0.4 seconds to boot and no measurable login delay. On Windows the sensor runs its detection logic in user mode with a minimal kernel callback surface, which is why an agent fault cannot bugcheck the machine — a design decision the industry learned the hard way.

Does Guardian Sentinel replace our SIEM?

For most customers it replaces the security-detection workload of the SIEM, and about a third of customers retire the SIEM entirely within two years. Sentinel already ingests, normalises, correlates and retains security telemetry with sub-second search across the full retention window, so running a second copy of that pipeline is usually pure cost.

What Sentinel does not try to be is a general-purpose log warehouse for application, billing and business telemetry. If your SIEM is doing that job, keep it and stream Guardian incidents into it — we have certified integrations for Splunk, Microsoft Sentinel, Elastic, QRadar, Chronicle and Exabeam, listed on the integrations page.

How does the Sentinel AI Analyst reach a conclusion, and can we audit it?

Every triage decision produces a written record: the evidence considered, the detections that fired, the historical sightings compared against, the hypotheses evaluated and rejected, and the confidence attached to the conclusion. That record is stored with the incident, is queryable through the API and is exportable for audit. It is not a summary generated after the fact — it is the reasoning trace itself.

Autonomous containment is always bounded by a policy you write. You decide which incident classes may be actioned without a human, on which asset groups, at which confidence threshold, and during which hours. Everything else is a recommendation with a one-click approval. Details are on the automation and response page.

What happens when an endpoint is offline or permanently air-gapped?

Protection is local-first. Prevention models, behavioural detection and ransomware rollback all execute on the device using models that ship with the sensor, so an offline laptop in a hotel is defended exactly as it would be on the corporate network. Telemetry is buffered locally for up to 14 days and uploaded when connectivity returns, preserving the full timeline.

For permanently disconnected estates, Guardian supports an on-premises deployment where the entire control plane runs inside your boundary and intelligence updates are delivered as signed offline bundles on whatever cadence your change process allows. This is common in defence, nuclear and pharmaceutical manufacturing environments.

Category 02

Deployment & operations

Getting Sentinel into production without breaking anything, and keeping it there.

How long does a typical deployment take?

A 5,000-endpoint estate typically reaches full coverage in three to five weeks; a 50,000-endpoint multi-region estate in eight to twelve. The gating factor is almost never the technology — it is your change advisory board, your maintenance windows and how confident you are that the incumbent agent can be removed cleanly.

The sensor installs without a reboot on every supported platform and deploys through whatever you already use: Intune, SCCM, Jamf, Workspace ONE, Ansible, Puppet, Chef, Salt or a plain package repository. Cloud workloads are covered by a DaemonSet or an agentless snapshot scanner depending on the workload type.

Can Guardian run alongside our existing EDR during migration?

Yes, and we recommend it. Guardian ships in detect-only mode with the incumbent left in blocking mode, so the two run in parallel with no protection gap and no fight over the same kernel resources. Sentinel is explicitly tested for coexistence with the major EDR and antivirus products, and Guardian provides the exclusion sets both directions.

Parallel running usually lasts two to six weeks. It is also the most persuasive part of an evaluation: roughly one in five customers finds a live intrusion during parallel run that their incumbent tooling had not surfaced.

How are sensor upgrades handled, and can we control the pace?

You control it entirely. Sensors are assigned to update rings — typically canary, early, general and conservative — and each ring can be pinned to a specific version, set to N−1, or set to auto-update within a maintenance window you define. Nothing upgrades itself against your policy.

Detection content is separate from sensor code and updates continuously by default, because that is what makes new tradecraft detectable within hours. Content can also be staged through rings if your change process requires it. Every content release carries a changelog, a risk rating and a one-click rollback.

What network access does the sensor require?

Outbound HTTPS on TCP 443 to your regional Guardian endpoint, with certificate pinning. No inbound ports, no VPN requirement and no public exposure of any customer system. Full DNS names and IP ranges per region are published in the deployment documentation and are stable and versioned, so firewall change requests do not become recurring work.

Sites with constrained egress can deploy a Guardian relay: a lightweight proxy inside your network that aggregates sensor traffic and holds a single outbound connection. TLS interception is supported but not recommended; if you must, Guardian can validate against your internal CA.

Can Guardian be deployed entirely on-premises?

Yes. Guardian Sentinel Sovereign runs the complete control plane — ingest, detection, storage, console and API — inside your data centre or a sovereign cloud region you nominate. It is the same code as the multi-tenant service, released on a quarterly cadence rather than continuously.

Sovereign deployments are sized from 5,000 protected assets upward and require customer-provided infrastructure to a published specification. They are most common in defence, central banking, national infrastructure and jurisdictions with strict data localisation law. Talk to the public sector team for sizing.

How do you cover OT and ICS networks where agents are not allowed?

Passively. A Guardian network sensor attaches to a SPAN, mirror or TAP port and performs deep protocol inspection for Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC UA, BACnet and around forty other industrial protocols. It never transmits on the control network, so it cannot influence a process, and it requires no change to a PLC, HMI or historian.

From that traffic Guardian builds an asset inventory, a communication baseline per production cell and detections for unauthorised programme changes, unexpected engineering-workstation activity and IT-to-OT boundary violations. Most customers have a usable inventory within ten days. See manufacturing and energy and utilities.

Category 03

Licensing & billing

How the commercial model works, including the parts vendors normally leave to the contract.

How is Guardian Sentinel licensed?

Per protected asset, per month, billed annually. One endpoint, server or workstation is one asset. Cloud container capacity is counted at 8 vCPU of concurrent protected capacity per asset unit, averaged over the month rather than measured at peak. One monitored human identity is one asset. One passively discovered OT device is one asset.

Console users, API clients, service accounts, machine identities, detection content and telemetry produced by Guardian sensors are never licensed units. Full rates and plan inclusions are on the pricing page.

What happens if we go over our licensed asset count?

Nothing stops working. There is no licence enforcement that leaves a machine undefended while procurement catches up, because an unprotected endpoint is a security incident waiting to happen and we are not willing to cause one over an invoice.

Overage is reconciled at the next quarterly true-up and invoiced pro rata at your contracted rate. If growth pushes you into a better volume tier, the improved rate is applied to the entire estate rather than only to the new assets. Sustained overage triggers a conversation about resizing the commitment, not a penalty.

Can we buy through a partner or a cloud marketplace?

Yes. Guardian transacts through more than 400 resellers, distributors and MSSPs worldwide, and is listed on the AWS, Microsoft Azure and Google Cloud marketplaces. Marketplace purchases usually draw down against your committed cloud spend, which for many organisations is the fastest route through procurement.

Public sector buyers can transact through GSA, G-Cloud, SEWP and equivalent regional frameworks. Support, service levels and product entitlement are identical regardless of purchase route — you are never a second-class customer for buying through a partner. See Guardian Partners.

What currencies, terms and invoicing options do you support?

USD, EUR, GBP, CAD, AUD, SGD and JPY, invoiced annually in advance by default. Quarterly and monthly invoicing are available on Enterprise and Sentinel Complete. Standard payment terms are net 30, with net 45 and net 60 available by region and by negotiation.

Multi-year terms fix the per-asset rate for the whole period, including assets added mid-term. Three-year commitments are typically 12 percent below the annual rate and five-year around 18 percent. Purchase orders, e-invoicing portals and consolidated billing across business units are all supported.

What happens to our data if we do not renew?

You keep full read and export access for 30 days after the subscription ends. During that window you can export incidents, detections, telemetry and audit logs through the API or as bulk archives in open formats — JSON, Parquet and OCSF — not a proprietary blob that only Guardian can read.

Thirty days after the export window closes, all customer data is permanently deleted from primary and backup systems within 45 days, and Guardian issues a signed certificate of deletion. Sensors can be removed by policy, by script or by your normal software-management tooling; there is no phone-home requirement and no uninstall password held hostage. The full data lifecycle is documented on Trust & security.

Category 04

Security, privacy & data

The questions your security review, your DPO and your regulator will ask. The answers are the same ones in our SOC 2 report.

Where is our data stored, and can we choose the region?

You choose the region at tenant creation and it cannot be silently changed afterwards. Guardian operates nineteen regional deployments including the United States, Canada, United Kingdom, Germany, France, Ireland, Switzerland, United Arab Emirates, India, Singapore, Japan, South Korea, Australia and Brazil, plus a FedRAMP High region and an IL5 environment for US government workloads.

Telemetry, incidents, backups and search indexes for a tenant remain within the chosen region. Cross-region transfer happens only if you explicitly enable a global view for a multinational deployment, and that choice is logged and reversible. Anonymised threat intelligence — file hashes, network indicators, behavioural patterns — is shared globally and never contains customer-identifying data.

Who at Guardian can access our data, and how is that controlled?

Nobody, by default. Guardian personnel have no standing access to customer tenants. Access is granted just in time, requires a documented business justification and a second-person approval, is limited to the minimum scope needed, and expires automatically — typically within four hours.

Every access event is written to your own audit log, visible in your console in near real time, and you can require your explicit approval before any Guardian employee is granted access at all. MDR and Signature customers can additionally restrict access to named personnel, to a nominated jurisdiction, or to personnel holding specific clearances.

What certifications and attestations does Guardian hold?

SOC 2 Type II (Security, Availability, Confidentiality) audited annually, ISO/IEC 27001, 27017, 27018 and 27701, FedRAMP High authorisation, DoD Impact Level 5 provisional authorisation, IRAP assessment to PROTECTED in Australia, C5 attestation in Germany, ENS High in Spain, and PCI DSS 4.0 Level 1 service provider status.

Reports and certificates are available under NDA before a first technical call — you should not have to sit through a demo to see the SOC 2. Current scope and renewal dates are published on Compliance.

Do you train your AI models on our data?

Not on your content. Guardian's detection models are trained on adversary tradecraft — malware corpora, red-team output, honeypot and telemetry from Guardian's own research infrastructure — and on aggregate, anonymised behavioural signals such as the prevalence of a file hash or the rarity of a parent-child process pair. Those signals carry no customer identifier and cannot be reversed to a tenant.

Your files, documents, email content, credentials and personal data are never used for training, are never used to improve a model for another customer, and are never sent to a third-party model provider. If you require a contractual commitment to that effect, it is in the standard Data Processing Addendum, not an expensive addendum.

How do you handle GDPR obligations and data subject requests?

Guardian acts as a processor for customer telemetry and as a controller only for the limited contact data of your administrators. The Data Processing Addendum incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, and a current Transfer Impact Assessment is published for each region.

Data subject access, rectification and erasure requests can be executed by your administrators directly in the console: search by identity, review what is held, export it, or erase it with a documented audit trail. Guardian does not need to be in the loop, which is what makes a 30-day statutory deadline realistic. Write to [email protected] for DPA queries or see the Privacy Policy.

How do you secure Guardian itself — and what if you are compromised?

Sentinel is built under a documented secure development lifecycle: memory-safe languages for parsers, mandatory code review, static and dynamic analysis in every pipeline, dependency provenance with signed SBOMs, and reproducible builds. Sensor binaries and detection content are cryptographically signed, and sensors refuse anything that fails signature validation. Guardian runs its own platform on Guardian.

We commission independent penetration tests twice a year and publish the summary findings, and we run a public bug bounty with safe-harbour terms and no gag clause. If Guardian suffers a security incident affecting customer data, notification is contractually committed within 24 hours — not “without undue delay” — along with a written post-mortem. Report a vulnerability to [email protected]; the PGP key is on Trust & security.

Category 05

Support & services

How to get help, and what Guardian will do for you rather than sell to you.

How do I open a support case, and what are the response targets?

Open cases from the Guardian console under Support → New case, which attaches your entitlement, tenant region, sensor versions and recent platform events automatically. Email to [email protected] also works. Premium, Signature and Complete customers can additionally open cases by phone.

Severity 1 first-response targets are four hours on Standard, one hour on Premium, fifteen minutes on Signature and three minutes on Sentinel Complete. Every case is answered by an engineer with production access, not a triage script. Full severity definitions and update cadences are on the support hub.

What does Guardian MDR do that we would otherwise do ourselves?

Guardian MDR puts our SOC inside your tenant. We monitor continuously, triage every incident within three minutes, investigate, and take containment action on your behalf under a written authority matrix that you approve line by line — which hosts may be isolated, which accounts may be disabled, at what hours and at what confidence.

You keep full visibility and can override anything at any time; it is your tenant, not a black box we operate beside you. MDR customers also receive proactive threat hunting as a monthly written report and a named shift lead they can call. Details on the managed detection and response page.

Do you offer an incident response retainer, and what does it cover?

Yes. A standard retainer is 40 pre-paid hours per year with a one-hour engagement service level and a named lead responder who is briefed on your architecture before anything happens. It covers ransomware, extortion, business email compromise, insider incidents, destructive attacks and data theft, including forensic imaging, malware analysis, threat-actor attribution and regulator-ready reporting.

Unused hours convert to consulting, training or tabletop-exercise credit at renewal, so a quiet year is not wasted budget. Retainer customers also get a discounted hourly rate if an incident exceeds the retained hours. Without a retainer, the emergency hotline is still answered — the first triage call is free for anyone. See incident response.

How do we report a vulnerability in a Guardian product?

Email [email protected], encrypted with the PGP key published on Trust & security. We acknowledge within one business day, provide a triage decision within three, and agree a remediation timeline with you rather than imposing one.

Guardian operates a public bug bounty with legal safe harbour for good-faith research, no gag clause and no requirement to delay publication beyond a coordinated 90 days. Researchers are credited in the advisory unless they ask not to be, and qualifying findings are rewarded on a published scale.

Still stuck?

Where a question should go

Sending the right question to the right place is the single biggest factor in how quickly you get a useful answer. This is how Guardian routes them internally.

routing / question → fastest answer
Your question classified by impact Active compromise ransomware, data theft, extortion IR hotline, 24/7 responder callback in 15 minutes Production impact something is broken or degraded Support case 3 min to 4 h, by plan and severity How do I…? configuration, tuning, authoring Docs & Guardian Connect median 11 minutes to an answer Commercial question licensing, renewal, contracts Your account team or [email protected]

Ask us the question that is not on this page

Security reviews, architecture challenges, awkward compliance edge cases — a Guardian solutions architect will answer directly, in writing, without routing you through a discovery call first.