Skip to main content
We’re upgrading Seclum to RAVIONIX.
Back to RAVIONIX

A product under RAVIONIX

Coming soon

RAVIONIX GuardWindows endpoint security, in development.

Guard is a privacy-first Windows security platform combining a fail-closed protection foundation with planned AI assistance, vulnerability intelligence, scam defense and controlled recovery. It is one product under RAVIONIX, not the RAVIONIX platform.

Not publicly released. Guard is a controlled engineering build. It is not production-trusted, not independently certified, and not proven across a production fleet. Current artifacts use development and test trust only.

What is verified today

The strongest thing about Guard today is disciplined security architecture, not AI.

  • Verified

    Windows security service

    An automatic LocalSystem service with recovery behavior, an exact required-privilege list, component health and protected persistent data.

  • Verified

    Content scanning

    Rule-based scanning in a separate worker with a restricted token, low integrity, job limits and fail-closed result handling.

  • Verified

    Assessment and intelligence

    Local assessment, threat-intelligence dataset activation, process, network and persistence observations, with optional Sysmon integration.

  • Verified

    Response and vault

    A single response authority, quarantine and vault storage, protected paths and local evidence persistence.

  • Verified

    Audit integrity

    Audit-chain verification fails closed and passed both elevated and unelevated live checks at the same commit.

  • Verified

    Installer and reboot durability

    Service configuration, persistent directories, an ACL boundary for ordinary users, and marker, version and database preservation across reboot.

Open items and blockers

The real gaps between a strong engineering build and a credible public security product.

  • Release blocker

    Production-trusted signing. Public-trust identity, certificate profile, real signing and clean-machine verification are deferred to the release gate.

  • Open

    The scanner worker has token, integrity and job restrictions but no OS-enforced network egress boundary.

  • Open

    Config write isolation: the service runs as LocalSystem, so a service-SID read ACE does not subtract that access.

  • Open

    Failed-upgrade rollback is statically verified but has not been proven on a sacrificial VM.

  • Privacy work

    No final personal-data inventory, retention schedule, consent model or production subprocessor register exists yet.

Roadmap

Staged, in order. Each stage gates the next.

  1. Stage A

    Finish security and release assurance: containment, isolation, rollback proof, privacy specification and production signing.

  2. Stage B

    Private signed early access to a small Windows cohort, with a secure updater and explicit diagnostics consent.

  3. Stage C

    Exposure and update advisor: software inventory, CVE correlation, signed packages and evidence-backed rollback.

  4. Stage D

    Explainable AI: an on-device risk model with uncertainty, drift monitoring and human-approved response.

  5. Stage E

    Scam Protect: text, URL, image and QR analysis with local redaction and explicit unknown states.

  6. Stage F

    App Sleep, Family and Business: multi-device views, role-based policy and controlled remediation.

Plans

Four tiers are proposed — Guard Free, Guard Plus, Guard Family, Guard Business — plus optional add-ons. These are product proposals, not approved prices. No Guard pricing is published, and the platform prices elsewhere on this site do not apply to Guard.