A product under RAVIONIX
Coming soonRAVIONIX GuardWindows endpoint security, in development.
Guard is a privacy-first Windows security platform combining a fail-closed protection foundation with planned AI assistance, vulnerability intelligence, scam defense and controlled recovery. It is one product under RAVIONIX, not the RAVIONIX platform.
Not publicly released. Guard is a controlled engineering build. It is not production-trusted, not independently certified, and not proven across a production fleet. Current artifacts use development and test trust only.
What is verified today
The strongest thing about Guard today is disciplined security architecture, not AI.
- Verified
Windows security service
An automatic LocalSystem service with recovery behavior, an exact required-privilege list, component health and protected persistent data.
- Verified
Content scanning
Rule-based scanning in a separate worker with a restricted token, low integrity, job limits and fail-closed result handling.
- Verified
Assessment and intelligence
Local assessment, threat-intelligence dataset activation, process, network and persistence observations, with optional Sysmon integration.
- Verified
Response and vault
A single response authority, quarantine and vault storage, protected paths and local evidence persistence.
- Verified
Audit integrity
Audit-chain verification fails closed and passed both elevated and unelevated live checks at the same commit.
- Verified
Installer and reboot durability
Service configuration, persistent directories, an ACL boundary for ordinary users, and marker, version and database preservation across reboot.
Open items and blockers
The real gaps between a strong engineering build and a credible public security product.
- Release blocker
Production-trusted signing. Public-trust identity, certificate profile, real signing and clean-machine verification are deferred to the release gate.
- Open
The scanner worker has token, integrity and job restrictions but no OS-enforced network egress boundary.
- Open
Config write isolation: the service runs as LocalSystem, so a service-SID read ACE does not subtract that access.
- Open
Failed-upgrade rollback is statically verified but has not been proven on a sacrificial VM.
- Privacy work
No final personal-data inventory, retention schedule, consent model or production subprocessor register exists yet.
Roadmap
Staged, in order. Each stage gates the next.
- Stage A
Finish security and release assurance: containment, isolation, rollback proof, privacy specification and production signing.
- Stage B
Private signed early access to a small Windows cohort, with a secure updater and explicit diagnostics consent.
- Stage C
Exposure and update advisor: software inventory, CVE correlation, signed packages and evidence-backed rollback.
- Stage D
Explainable AI: an on-device risk model with uncertainty, drift monitoring and human-approved response.
- Stage E
Scam Protect: text, URL, image and QR analysis with local redaction and explicit unknown states.
- Stage F
App Sleep, Family and Business: multi-device views, role-based policy and controlled remediation.
Plans
Four tiers are proposed — Guard Free, Guard Plus, Guard Family, Guard Business — plus optional add-ons. These are product proposals, not approved prices. No Guard pricing is published, and the platform prices elsewhere on this site do not apply to Guard.