Agent integrity attestation

The installed agent signs its own status using on-device asymmetric keys, so tampering or repackaging is detectable rather than assumed.

Encryption in transit and at rest

All data between the device, the GuardianX backend and the administrator console is encrypted in transit; stored data is encrypted at rest.

Role-based access control

Owner, administrator and reviewer roles enforce least-privilege access to inventory, location and exported evidence.

Full audit logging

Every sign-in, configuration change, export and policy update is recorded with actor, timestamp and outcome.

Retention & deletion controls

Administrators define retention windows per data category; expired data is deleted automatically per policy.

Cloud infrastructure

GuardianX runs on managed cloud infrastructure with standard provider-level security controls and monitoring.

Responsible disclosure

Found a security issue?

We take vulnerability reports seriously. Please report issues privately before public disclosure so we can investigate and respond.

Report a vulnerability