1. Two proofs instead of promises
Server Warden should not ask a buyer to trust marketing. Before purchase, a visitor can inspect their own server with a read-only audit and then watch the protection lifecycle in an interactive security lab.
Audit your server for free
45 read-only checks with no installation or changes. The script produces a local HTML/TXT report with risks and recommendations.
See the protection work
Security Lab runs controlled scenarios and shows protected vs unprotected behavior, timeline, recovery and independent proof.
2. A closed protection loop
RECOVERED ≠ VERIFIED. A restart or rollback is not proof. VERIFIED is earned only after independent health, hash, listener, firewall, identity and scenario-specific checks.
3. Free server audit
The audit is the first persuasion loop. It is a one-shot read-only diagnostic, not the Server Warden agent.
Host baseline
OS release · kernel · uptime/load · disk usage · memory/swap
Exposure
Listening TCP sockets · public SSH exposure · Docker TCP API · database/service ports
Firewall
UFW · nftables · iptables
SSH & accounts
Failed-login signals · top source IPs · effective SSH config · UID 0 users · sudo/admin groups · authorized_keys permissions
nginx / web
nginx version · config test · suspicious log patterns and paths · server inventory · risky directives
Filesystem
Sensitive-path markers · world-writable project files · executables in temp directories
Persistence / systemd
SUID snapshot · cron · failed services · suspicious systemd Exec lines
Packages & processes
Update signal · fail2ban · top CPU processes · suspicious process indicators
Docker
Socket permissions · containers · privileged/network risk
Resilience / ops
Recent backups · backup freshness · Let’s Encrypt certificates · disk pressure
Report
Local HTML/TXT report · risk score · recommendations
4. Server Warden modules
Do not publish a crude “13/17 complete” counter. Show the real capability status: available now, infrastructure-dependent, in qualification, or dependent on customer endpoints. The product capability matrix should remain the source of truth.
Core Platform
Signed policy, module supervision, Action Broker, leases, approvals, kill switch, generation fencing.
Integrity & Self-Heal
File/config drift, one-byte and binary replacement, permission drift, persistence, safe repair and Recovery Proof.
Network Defense
Unauthorized listeners, firewall/posture drift, network observation and controlled isolation.
Identity Defense
Unauthorized accounts/admin, identity drift and privileged-state checks.
Ransomware Shield
Mass file rewrites, canaries, containment and recovery workflows.
Egress / Exfiltration
Unexpected egress and exfiltration signals; observe first, enforcement through network policy.
Deception Fabric
Honeytokens and deception signals that should never appear in legitimate work.
Hardening Posture
Search-path and privileged-binary posture checks with evidence-based findings.
Forensics / Time Machine
Timeline, replay, signed proof packs and final-state verification.
Compliance Evidence
Evidence-to-control mapping; never presents a certification without evidence.
Security Commander
Deterministic triage plus AI advisory; AI never gets an unrestricted privileged shell.
Guardian Recovery
Single-plane out-of-band recovery exists; multi-plane HA needs an independent second plane.
Digital Twin
A/B counterfactual and twin graph are available; full isolated live proof needs dedicated lab infrastructure.
Application Shield / Veil
Survival/bundle foundation exists; full App Shield is being completed.
DDoS Reflex
Requires a dedicated load-generation and hardware qualification environment before public performance claims.
Enterprise Integrations
Local JSON/CEF and ingest foundations exist; live remote delivery depends on customer endpoints/credentials.
Windows parity
Linux is the qualified baseline today; Windows parity requires dedicated validation hosts.
5. Architecture
Effectful actions pass through the Action Broker; detectors and AI do not receive a generic privileged shell. Security Commander assists with triage and explanation while deterministic protection continues without an LLM.
6. Security Lab
The public terminal is a strict allowlisted DSL, not an arbitrary browser shell. The strongest mode is Protected vs Unprotected: the same controlled activity is applied to identical environments.
warden-demo> run firewall-drift --compare 00.000 policy changes 00.094 drift observed
Unprotected: DRIFT REMAINS
Evidence: collecting
DETECTED CORRELATED RECOVERED VERIFIED
7. Getting started
- Optionally run the free audit and keep the report.
- Purchase one license per protected server/instance under the current commercial model.
- Install and enroll through the current customer-specific delivery flow; never publish permanent secrets in static docs.
- Create the baseline and verify heartbeat, policy version and active modules.
- Choose which conditions are detect-only, auto-contain, auto-recover or approval-gated.
- Operate through incidents, timeline, Recovery Proof and reports.
8. Current status
Available now on Linux: trusted core, integrity/self-heal, network, identity, ransomware, egress, deception, posture, forensics/proof, compliance evidence and Security Commander.
Infrastructure-dependent: multi-plane Guardian HA and evaluator-grade isolated Twin/LiveFire.
In qualification: full App Shield, DDoS Reflex, Windows parity and live remote enterprise connectors.
9. Price
Server Warden · 1 server
Annual: 9,990 UAH. USD should remain an indicative dynamic reference only; settlement is in UAH.
10. Who it fits
Good fit
VPS and dedicated servers, production services and teams that need more than alerts: controlled containment, recovery and evidence.
Not a replacement for
Hardware/firmware security, provider-scale DDoS scrubbing, or capabilities the endpoint has no authority to perform. Those boundaries should be stated explicitly.