Endpoint Detection
Windows / Linux / macOSLightweight agent with Sigma/YARA rules, behavioral analysis, and ML-assisted threat detection. Real-time telemetry, live response, and full forensic capability.
Protect your endpoints, applications, and infrastructure from runtime attacks. Tamandua Sentinel is a self-hosted security platform with EDR, mobile app protection, and enterprise portfolio governance. Sensitive telemetry never leaves your servers.
A unified security platform covering endpoint detection, mobile app protection, and enterprise portfolio governance. Self-hosted, privacy-first, verifiable.
Lightweight agent with Sigma/YARA rules, behavioral analysis, and ML-assisted threat detection. Real-time telemetry, live response, and full forensic capability.
Runtime application self-protection for mobile apps. Hardware attestation, root/jailbreak detection, anti-hooking, and code obfuscation.
Unified security posture across your entire portfolio. Centralized policy, compliance reporting, and executive dashboards for security leadership.
A six-stage pipeline: telemetry never leaves your perimeter, but anyone can verify the integrity of an incident on-chain.
Lightweight cross-platform agent. Outbound mTLS only. No inbound port.
PrivateSigma/YARA plus behavioral rules running locally on the host.
PrivateHashed indicators of compromise. Process, file and network metadata.
PrivateKill, quarantine, isolate. Operator-signed live response.
PrivateManifest hash anchored on-chain. No telemetry exposed.
PublicAnyone can verify the proof exists. No customer data exposed.
PublicProtect your iOS and Android apps from reverse engineering, tampering, and runtime attacks. Hardware-backed attestation ensures only genuine, unmodified apps can access your backend.
Root/jailbreak detection, hook detection, debugger detection, emulator detection with continuous runtime monitoring.
Apple App Attest and Google Play Integrity verify device integrity and app authenticity at the hardware level.
Control flow obfuscation, string encryption, and anti-decompilation make reverse engineering impractical.
Binary integrity checks, signature validation, and repackaging detection ensure only authentic code runs.
Cryptographic record that a detection occurred without exposing what was on the host.
Periodic attestation of fleet posture: clean endpoints, ingestion health and agent count.
Counter-attestation linked back to an incident, signed after live response actions are executed.
Tamandua publishes hashes and metadata, never hostnames, usernames, file paths, IP addresses or raw telemetry. The on-chain footprint is fixed-size, content-free and deterministic.
Whether it is an infostealer on a treasury workstation, a hooked trading app, or a rooted device accessing your backend. Tamandua assumes the threat is already present.
Protect your mobile apps from reverse engineering, credential theft, and runtime manipulation.
Anti-cheat, anti-tamper, and anti-bot protection for competitive and economy-driven games.
Unified posture across endpoints and mobile fleet with compliance reporting and policy enforcement.
Hot-key custodians, ops desks and support consoles with high blast radius.
Multisig signers, settlement desks and finance operations handling sensitive assets.
MSSPs, in-house SOCs and responders who want Sigma/YARA, not telemetry hostage.
For teams that need public, verifiable security attestations, Tamandua can anchor proof metadata on Solana. This is optional and designed for Web3 compliance use cases.
High-throughput public ledger that can absorb continuous health attestations without backpressure on the SOC.
A proof every minute is economically viable. Auditors and counterparties pay nothing to verify.
Anyone can confirm an incident hash exists, when it landed and which manifest signed it.
Self-hosted agent enrollment, server, dashboard, basic detections, response paths and devnet proof metadata validated in a lab scope.
Community hub, component mirrors, docs and contribution/security guidance are public with explicit claim boundaries and production gaps.
Curated detection/config workflow, bounty validation gates and public audit/feed views.
Mobile runtime protection with RASP, hardware attestation (App Attest, Play Integrity), and code protection shipped.
Multi-tenant governance, unified dashboards, compliance reporting and policy engine across EDR and App Guard.
Mainnet policy, advanced validation, bounty settlement controls, and enterprise certifications.