Advanced Alpha Validation gate: closure unknown, preflight unknown, dispatch unknown View validation scope
Mobile App Guard Enterprise Portfolio Self-hosted EDR Privacy-first

Runtime Trust Platform.

Protect your endpoints, applications, and infrastructure from runtime attacks. Tamandua Sentinel is a self-hosted security platform with EDR, mobile app protection, and enterprise portfolio governance. Sensitive telemetry never leaves your servers.

DESIGNED FOR App Developers Game Studios Enterprise Security Exchanges Treasury Teams MSSPs
tamandua://overview Live

Security Status

Fleet overview
All systems healthy
EDR Agents12
Protected Apps4
Open Alerts3
Trust Score94
Platform status edr=active · app_guard=active · attestation=ready mitre=T1555.003 · rasp_blocks=47 · threats_stopped=12
Platform

Three pillars of runtime trust.

A unified security platform covering endpoint detection, mobile app protection, and enterprise portfolio governance. Self-hosted, privacy-first, verifiable.

EDR

Endpoint Detection

Windows / Linux / macOS

Lightweight agent with Sigma/YARA rules, behavioral analysis, and ML-assisted threat detection. Real-time telemetry, live response, and full forensic capability.

Sigma/YARA Behavioral Live Response Quarantine eBPF
APP GUARD

Mobile App Protection

iOS / Android

Runtime application self-protection for mobile apps. Hardware attestation, root/jailbreak detection, anti-hooking, and code obfuscation.

RASP App Attest Play Integrity Anti-tamper Obfuscation
ENTERPRISE

Portfolio Governance

Multi-tenant / Fleet

Unified security posture across your entire portfolio. Centralized policy, compliance reporting, and executive dashboards for security leadership.

Multi-tenant Compliance Policy Engine RBAC Audit Log
How it works

Detect privately. Prove publicly.

A six-stage pipeline: telemetry never leaves your perimeter, but anyone can verify the integrity of an incident on-chain.

STAGE 01

Agent

Lightweight cross-platform agent. Outbound mTLS only. No inbound port.

Private
STAGE 02

Detection

Sigma/YARA plus behavioral rules running locally on the host.

Private
STAGE 03

IOCs

Hashed indicators of compromise. Process, file and network metadata.

Private
STAGE 04

Response

Kill, quarantine, isolate. Operator-signed live response.

Private
STAGE 05

Attestation

Manifest hash anchored on-chain. No telemetry exposed.

Public
STAGE 06

Public audit

Anyone can verify the proof exists. No customer data exposed.

Public
App Guard

Mobile runtime protection.

Protect your iOS and Android apps from reverse engineering, tampering, and runtime attacks. Hardware-backed attestation ensures only genuine, unmodified apps can access your backend.

R

RASP

Root/jailbreak detection, hook detection, debugger detection, emulator detection with continuous runtime monitoring.

H

Hardware Attestation

Apple App Attest and Google Play Integrity verify device integrity and app authenticity at the hardware level.

C

Code Protection

Control flow obfuscation, string encryption, and anti-decompilation make reverse engineering impractical.

A

Anti-Tamper

Binary integrity checks, signature validation, and repackaging detection ensure only authentic code runs.

Proof model

Three classes of attestation.

INCIDENT

Proof of Incident

Cryptographic record that a detection occurred without exposing what was on the host.

incident_hashmanifest_hashseverityMITRE IDsioc_count
HEALTH

Proof of Health

Periodic attestation of fleet posture: clean endpoints, ingestion health and agent count.

fleet_idclean_countsince_last_criticaltrust_score
REMEDIATION

Proof of Remediation

Counter-attestation linked back to an incident, signed after live response actions are executed.

incident_refactions[]operator_pubkeyts_remediated
Privacy model

Nothing sensitive ever leaves your servers.

Tamandua publishes hashes and metadata, never hostnames, usernames, file paths, IP addresses or raw telemetry. The on-chain footprint is fixed-size, content-free and deterministic.

On-chain

Incident hashyes
Manifest hashyes
Severityyes
MITRE technique IDsyes
IOC count by typeyes
Timestampyes

Self-hosted only

Hostnamenever
Username / domainnever
Internal IP / pathnever
Raw process telemetrynever
Customer identitynever
Wallet addressesnever
Who it protects

Teams that cannot afford runtime compromise.

Whether it is an infostealer on a treasury workstation, a hooked trading app, or a rooted device accessing your backend. Tamandua assumes the threat is already present.

App Developers

Protect your mobile apps from reverse engineering, credential theft, and runtime manipulation.

Game Studios

Anti-cheat, anti-tamper, and anti-bot protection for competitive and economy-driven games.

Enterprise Security

Unified posture across endpoints and mobile fleet with compliance reporting and policy enforcement.

Exchanges

Hot-key custodians, ops desks and support consoles with high blast radius.

Treasury Teams

Multisig signers, settlement desks and finance operations handling sensitive assets.

Security Teams

MSSPs, in-house SOCs and responders who want Sigma/YARA, not telemetry hostage.

Optional: Solana

Privacy-safe proof layer for Web3 teams.

For teams that need public, verifiable security attestations, Tamandua can anchor proof metadata on Solana. This is optional and designed for Web3 compliance use cases.

01

Attestation layer

High-throughput public ledger that can absorb continuous health attestations without backpressure on the SOC.

02

Low-cost settlement

A proof every minute is economically viable. Auditors and counterparties pay nothing to verify.

03

Public verification

Anyone can confirm an incident hash exists, when it landed and which manifest signed it.

Roadmap

Honest about where we are.

Private Hackathon Build

Self-hosted agent enrollment, server, dashboard, basic detections, response paths and devnet proof metadata validated in a lab scope.

Shipped

Open Source Alpha

Community hub, component mirrors, docs and contribution/security guidance are public with explicit claim boundaries and production gaps.

Shipped

Ecosystem Alpha

Curated detection/config workflow, bounty validation gates and public audit/feed views.

Shipped

App Guard Launch

Mobile runtime protection with RASP, hardware attestation (App Attest, Play Integrity), and code protection shipped.

Shipped

Enterprise Portfolio

Multi-tenant governance, unified dashboards, compliance reporting and policy engine across EDR and App Guard.

Current

Production Readiness

Mainnet policy, advanced validation, bounty settlement controls, and enterprise certifications.

Planned
Advanced alpha. Current public scope covers Windows/Linux/macOS endpoint enrollment, iOS/Android App Guard with hardware attestation, Sigma/YARA/IOC/behavioral and ML-assisted detection paths, selected response actions and privacy-safe proof metadata. Enterprise multi-tenant governance, advanced compliance reporting, and production ML malware detection remain validation pending or roadmap. Sensitive telemetry remains self-hosted in every release.