1. Два докази замість обіцянок
Server Warden не просить повірити рекламі. До покупки користувач може перевірити власний сервер read-only аудитом, а потім побачити роботу захисту в інтерактивній лабораторії.
Безкоштовно перевірте свій сервер
45 перевірок без встановлення та змін: surface exposure, SSH, firewall, nginx, files, persistence, Docker, backups, certificates та інше. Результат — локальний HTML/TXT звіт, risk score і рекомендації.
Подивіться, як працює захист
Security Lab показує однакову контрольовану активність у protected/unprotected середовищах, повний timeline та окремий Recovery Proof.
2. Повний цикл захисту
RECOVERED ≠ VERIFIED. Відновлення не вважається доведеним, доки окремі checks не підтвердили health, hashes, listeners, firewall, identity та сценарні invariants.
3. Безкоштовний audit
Це перший контур переконання: коротка read-only діагностика власного сервера користувача, а не постійний агент.
Host baseline
OS release · kernel · uptime/load · використання диска · memory/swap
Exposure
Listening TCP sockets · public SSH exposure · Docker TCP API · database/service ports
Firewall
UFW · nftables · iptables
SSH та акаунти
Failed-login signals · top source IPs · effective SSH config · UID 0 users · sudo/admin groups · authorized_keys permissions
nginx / web
nginx version · config test · suspicious log patterns and paths · server inventory · risky directives
Файли
Sensitive-path markers · world-writable project files · executables in temp directories
Persistence / systemd
SUID snapshot · cron · failed services · suspicious systemd Exec lines
Пакети та процеси
Update signal · fail2ban · top CPU processes · suspicious process indicators
Docker
Socket permissions · containers · privileged/network risk
Resilience / ops
Recent backups · backup freshness · Let’s Encrypt certificates · disk pressure
Звіт
Local HTML/TXT report · risk score · recommendations
4. Модулі Server Warden
На публічному сайті показуємо статус кожної capability, а не «13/17». Джерело істини — capability matrix продукту.
Core Platform
Signed policy, module supervision, Action Broker, leases, approvals, kill switch, generation fencing.
Integrity & Self-Heal
File/config drift, one-byte and binary replacement, permission drift, persistence, safe repair and Recovery Proof.
Network Defense
Unauthorized listeners, firewall/posture drift, network observation and controlled isolation.
Identity Defense
Unauthorized accounts/admin, identity drift and privileged-state checks.
Ransomware Shield
Mass file rewrites, canaries, containment and recovery workflows.
Egress / Exfiltration
Unexpected egress and exfiltration signals; observe first, enforcement through network policy.
Deception Fabric
Honeytokens and deception signals that should never appear in legitimate work.
Hardening Posture
Search-path and privileged-binary posture checks with evidence-based findings.
Forensics / Time Machine
Timeline, replay, signed proof packs and final-state verification.
Compliance Evidence
Evidence-to-control mapping; never presents a certification without evidence.
Security Commander
Deterministic triage plus AI advisory; AI never gets an unrestricted privileged shell.
Guardian Recovery
Single-plane out-of-band recovery exists; multi-plane HA needs an independent second plane.
Digital Twin
A/B counterfactual and twin graph are available; full isolated live proof needs dedicated lab infrastructure.
Application Shield / Veil
Survival/bundle foundation exists; full App Shield is being completed.
DDoS Reflex
Requires a dedicated load-generation and hardware qualification environment before public performance claims.
Enterprise Integrations
Local JSON/CEF and ingest foundations exist; live remote delivery depends on customer endpoints/credentials.
Windows parity
Linux is the qualified baseline today; Windows parity requires dedicated validation hosts.
5. Архітектура
AI допомагає аналізувати та пояснювати, але не отримує unrestricted privileged shell і не є єдиним захисним механізмом.
6. Security Lab
Публічний terminal — безпечний allowlisted DSL. Ключовий режим — Protected vs Unprotected: однакова активність у двох однакових середовищах.
warden-demo> run integrity-drift --compare 00.000 change starts 00.071 monitored state differs
Unprotected: DRIFT REMAINS
Evidence: collecting
DETECTED CORRELATED RECOVERED VERIFIED
7. Як почати
- Опційно запустити безкоштовний audit.
- Придбати ліцензію на сервер.
- Встановити агент через актуальний installer/enrollment flow.
- Створити baseline і перевірити heartbeat/policy/modules.
- Налаштувати policy для detect/contain/recover/approval.
- Працювати з incidents, timeline, proof та reports.
8. Поточний статус
Available now on Linux: core, integrity, network, identity, ransomware, egress, deception, posture, forensics/proof, compliance evidence, Security Commander.
Infrastructure-dependent: multi-plane Guardian HA та evaluator-grade isolated Twin/LiveFire.
In qualification: full App Shield, DDoS Reflex, Windows parity, live remote enterprise connectors.
9. Ціна
10. Кому підходить
Підходить
VPS/dedicated servers, production services і команди, яким потрібні не лише alerts, а контрольоване recovery з доказами.
Не замінює
Hardware/firmware security, provider-scale DDoS scrubbing та capabilities, для яких endpoint фізично не має authority.