Who is on the network
Every device that joins, every device that goes quiet, and the ones you have never seen before. Name the ones you recognise once and Guardian stops asking about them.
Network watchdog — every plan starts with three months free
It watches the machines, the websites and the traffic you are responsible for — and for the routine problems, it does not just tell you, it fixes them. Built for the person who gets the call when the network breaks: one house, one office, or a hundred client sites.
No card and no checkout — billing does not exist in the product yet, so access is granted by hand, one deployment at a time.
Handled without waking anyone · 7 days
38
Of 44 findings. The other six needed a decision only a person could make.
last scan —
This panel normally streams the notices Guardian raised on a watched network in the last few days — devices arriving and going quiet, ports opening, lookups blocked, repairs made. It needs JavaScript, and the hub has to be reachable. The rest of the page does not.
Newest first · refreshed every few seconds
Security score
77/100
Uptime, 7 days
99.84%
Handled, 7 days
38
Asked you first
6
The problem
Nothing on a network announces itself. The disk fills quietly, the certificate lapses quietly, the new device joins quietly. What is not quiet is the phone call afterwards.
Illustrative — the sentences a callout usually starts with, not quotes from named customers.
Nobody can watch a network by hand at three in the morning. Something sitting on it, looking, can.
One sensor on the network, one page with everything on it. No hunting through six different admin panels to answer one question.
Every device that joins, every device that goes quiet, and the ones you have never seen before. Name the ones you recognise once and Guardian stops asking about them.
Disk, memory, load, and the updates waiting to be installed — including the ones that need a reboot before they count. You find out a disk is filling up while it is still a nuisance.
Whether each site answers, how fast, and how many days are left on its certificate. An expiring certificate is a warning weeks out, not an outage on a Sunday.
The names your devices look up, which ones were blocked, and which device asked. Useful when a smart TV is chatting to somewhere odd, and useful when something is broken and you need to know what it reached for.
The ports actually reachable from outside, and the addresses trying them — where they are from and what they went after.
Which phones and laptops are home, when they usually are, and how long they have been on today. The same signal answers "is anyone in the office?" and "how much screen time was that?".
Three steps, and you are looking at your own network.
One command on any machine that stays on — a spare Pi, a NAS, a server you already run. It watches from the inside, which is the only place a network is honest.
The sensor sweeps on a schedule and sends up a summary of what it found. Nothing else leaves the network: no packet captures, no file contents, no traffic tunnelled anywhere.
A single page for the whole picture, and a notification when something actually changes — a new device, a site down, a certificate running out, a port that opened.
curl -fsSL https://my.guarder.io/install | sh -s -- --code YOUR-ENROL-CODE
The enrolment code comes from your own dashboard and is good for one sensor. Add a second network later and it gets its own.
The difference
An alert is only useful if someone acts on it, and at 2am nobody does. This is the part of Guardian that is not a dashboard.
Guardian can restart a service that died, clear a log directory that filled a disk, renew a certificate that is about to lapse, re-block a DNS rule that fell off. That list is fixed and allow-listed: if a repair is not on it, Guardian cannot perform it, however it is asked.
A fix runs, then that fix is locked for a while. A service that dies every ninety seconds gets restarted once and then escalated to you — because the second restart was never the answer, and a tool that keeps trying hides the real fault.
There is an assistant on the dashboard that can read everything Guardian knows and run those same repairs. Ask it why the office internet was slow last night, or tell it to restart the thing that is stuck.
Anything disruptive — a reboot, cutting a device off the network — is proposed, not performed. You see exactly what it intends to do and say yes. Every action, automatic or asked for, is written down with who or what triggered it.
What it does
Pick one and the panel shows it running. These are the checks Guardian performs on every sweep, and what it does when one of them fails.
Evidence
Every tool can raise an alert. The number that matters is how much of it never reached you at all.
Minutes from finding to fix demo
Closed by Guardian, by day demo
By severity, fourteen days demo
Who uses it
The same sensor and the same page, whether you are looking after one house or a hundred client sites.
Sysadmins, IT leads and security engineers who already know what a failing certificate costs. Guardian handles the routine sweep so the hours go on the work that actually needs judgement.
Every finding says what it saw, why it matters and what it did about it, in plain words. It is a working network to learn on, not a wall of acronyms.
One office, one shop, one clinic. Nobody is watching the network at three in the morning, which is exactly when the certificate lapses and the disk fills.
Every client site on one page, each with its own sensor and its own report. What Guardian fixed is already written down when the client asks.
Integrations
Alerts go to the place you actually watch, and the important ones can be acknowledged from there without opening the dashboard.
Findings arrive in the channel your team already reads, with the severity and the host on the first line.
Critical findings raise a real incident, and acknowledging it there closes it in Guardian too.
For the smaller setups, where the team is a group chat rather than a rota.
A push notification with the buttons on it, so a repair can be approved from a phone.
Guardian becomes another sensor in the house, and alerts can be acknowledged from your own dashboard.
Every finding as JSON, to your own endpoint or pulled from the public API with a token you issue.
Pricing
The free trial is a subscription of its own — not a countdown attached to a paid plan. You get the whole product from the first day: the sensor, the dashboard, the alerts and the automatic repairs, for three months, with no payment method on file.
At the end of the three months nothing is charged and nothing converts on its own. The account pauses: everything already collected stays readable and exportable, and the sensors start reporting again the moment you pick a plan. If you would rather not, that is the end of it.
Today the last step is still a person. Checkout is built but not switched on, so there is no card form on this site yet: tell us what you are looking after and we set the deployment up by hand, one at a time. No card is taken to start the three months.
Free
The whole product, every feature, for three months — then it pauses until you choose. Nothing auto-charges, because nothing was ever collected to charge.
Start three months free$9/mo
$90/yr
One home network: the devices on it, who is around, and what your gear is talking to.
Subscribe Subscribe$49/site/mo
$490/site/yr
One office or shop: the network plus your servers, websites and certificates, with alerts that reach the right person.
Subscribe Subscribe$149/mo
$1490/yr
For a site you cannot afford to have down: automatic repairs, the assistant, deeper history and scheduled reports.
Subscribe Subscribe$99/site/mo
$990/site/yr
Many client sites in one place, white-labelled — your name and your colours on the dashboard and the reports.
Subscribe SubscribePrices are in US dollars. Business Essentials and Partner / MSP are per monitored site; Home and Business Pro are per account. Cancelling is telling us, or one click in the billing portal once your plan is running — it stops at the end of the period you have paid for, with no notice period and no exit call.
What a device on your network can see by asking politely: which addresses answer and what hardware they claim to be, which ports on them are open, whether your sites and servers respond, and — if you point your DNS at Guardian — the names that were looked up and by which device. It does not read your traffic, capture packets, or open files. On servers you connect it over your own SSH access and it runs read-only checks, plus exactly the repairs you allow.
In the hub for your account, and nowhere else — it is not sold, not pooled with anyone else's, and not used to train anything. What leaves your network is the sensor's summary of what it found, over HTTPS. Self-hosting the hub on your own machine is possible, and today it is something we set up with you rather than a download.
Nothing. The sensor is not in the path of your traffic — it watches from the side, so if it stops, or the hub is down, or your uplink is out, your network carries on exactly as before. The sensor keeps sweeping and sends what it collected once it can reach the hub again. The one exception is DNS filtering, which is opt-in and only in the path if you choose to point your devices at it; it keeps answering from its own cache and lists, without the hub.
You choose one of the plans and we agree it by email, or the sensor stops reporting and the dashboard goes quiet. Nothing is charged automatically — we never took a card, so there is nothing to charge. You will hear from us before the three months are up, not after.
During the three months there is nothing to cancel: no card was taken, so stopping is simply not continuing. On a paid plan afterwards, tell us and it stops at the end of the month you have paid for — no notice period and no exit call. Uninstalling the sensor is one command, and it leaves nothing behind. Ask and your data is deleted; ask and you get an export of it first.
Tell us what you are looking after and we will come back to you. Your three months start when we set you up — there is no card form and nothing to pay, because every deployment is still done by hand at this stage.