All modules

Your AI security team. Always watching.

Guard is the security analyst that small businesses could never afford — reviewing contracts in plain English, watching your inbox for phishing, tracking vulnerabilities in your stack, and checking you against GDPR / DPDP / PCI. No security expertise required. On Builder & up (Solo gets 10 scans a month to try it).

00 What is Guard? 01 Contract scanner 02 Threat monitor 03 Vulnerabilities 04 Compliance

Cybersecurity for businesses without an IT team.

Contract review · phishing watch · vulnerability tracking · compliance — in one place

Most small businesses are exposed not because owners don't care, but because staying safe takes expertise they don't have time to build. Guard is an AI security analyst that reviews your contracts, watches for threats and tells you what to fix — in plain language, with nothing technical required from you.

Risk Assessment47-page agreement · 3 sections
62/ 100Moderate Risk
✓ Scanned the entire document · any Hindi / regional clauses were translated to English
HIGH
Auto-renewal trap

Section 8.2: renews for 24 months unless cancelled 90 days prior, with annual price rises capped at 40% — unusually high.

MED
Data residency gap

Section 6.3: vendor may store data outside India. Required disclosure under the DPDP Act 2023.

MED
One-sided termination

Only the vendor can terminate early without cause; you're locked in for the full term.

Drop a PDF — even a scanned one, even in Hindi — and Guard returns a risk score with plain-English findings.
Real story — SaaS startup, 7 people

Deepa's small team builds software in Chennai. Nobody on the team specialises in security.

Once, a developer accidentally saved a password into a shared file visible to the internet. Nobody noticed for three days — by then someone had run up ₹35,000 of cloud charges.

Now Guard scans their vendor contracts before they sign. When their host sent a new agreement, Guard flagged one clause in plain English: "Clause 8.3 lets the vendor raise your price by up to 30% with 15 days' notice, and you can't exit during that window." Deepa renegotiated before signing. No lawyer. No security consultant on retainer.

Replaces A security consultant Manual contract review Expensive monitoring tools GitGuardian

Read every clause. In plain English.

Drop a PDF — even scanned, even multi-language — and get a risk score in seconds

Drop a vendor agreement, employment contract or terms of service. Guard returns a risk score out of 100 and a plain-English summary of the traps — auto-renewals, uncapped liability, one-sided termination, data-residency gaps. No legal training needed to spot them.

  1. Reads scanned PDFs tooIf the pages are images, not selectable text, Guard runs OCR to pull the text straight off the scan.
  2. Handles Hindi & regional languagesMixed-language documents are transcribed and translated — and analysed in English, so nothing is missed.
  3. Scans long agreements end to end200-page contracts are read section by section in one upload — bounded so a single scan never drains your monthly budget.
  4. GDPR & DPDP-awareIt knows what's required for Indian businesses and flags the missing or risky compliance clauses.

Watches your inbox — so threats don't reach you.

Scans incoming email for phishing, spoofed senders and payment-fraud language

Connect your inbox and Guard checks what arrives — phishing patterns, suspicious links, spoofed senders, payment-fraud wording — and logs everything to a tamper-evident audit trail. You get alerted when something actually matters, not a stream of noise.

Every message is judged first by rules running on your own machine: who really sent it, whether the domain is a lookalike, whether it is asking you to verify an account or move a payment. Ordinary mail — receipts, statements, newsletters, offers — is settled there and costs you nothing. Only genuinely suspicious mail is escalated to the AI for a second opinion, so a busy inbox never quietly burns through your plan.

Guard never deletes, moves or quarantines anything. It tells you what it found and why, records it, and leaves every decision to you. Each alert carries the reason and the signals behind it, so a "high" is something you can check rather than something you have to take on faith.

// Guard activity log● live
Phishing flagged · "invoice overdue" · spoofed senderHigh
Suspicious login flagged · new device · SingaporeMed
📄Vendor contract scanned · 2 medium clausesLogged
Unpatched dependency · Next.js 14.0.2 · CVE-2025-1042Med
A single feed of everything Guard catches — each entry hashed into a tamper-evident audit log.

A weekly briefing on what's actually risky for you.

Knows your stack · scores new CVEs by whether they affect your version

Guard knows what you run. Each week it sends a one-page briefing of new vulnerabilities disclosed in your tech stack — scored by whether you're actually affected. It filters out CVEs that don't touch your version or config, so there's no noise to wade through.

// weekly vulnerability briefing2 affect you
HIGH
CVE-2025-1042 · Next.js SSRF in image optimizer

You run Next.js 14.0.2 — affected. Upgrade to 14.2.5 or set a domain allow-list. Fix included.

MED
CVE-2025-1101 · Postgres planner crash

Affects your version only with a specific query shape you don't use. Low priority — patch on your next cycle.

Only the CVEs that matter to your actual versions — with the fix, not just the alert.

A readable scorecard for GDPR, DPDP, PCI & ISO.

Tell Guard what you do; it checks your code, config and policies against the rules

Tell Guard your business type, the data you handle and where you operate. It scans your actual code, config and policy files and gives you a one-page scorecard you can show a client or investor — with specific, actionable fixes for whatever's missing.

DPDP Act 2023
Consent & purpose

Consent capture found in the signup flow with a stated purpose.

!
DPDP Act 2023
Data residency

No region pinning found — data may leave India. Set storage region.

GDPR
Right to erasure

Account-deletion endpoint present and wired to data removal.

!
PCI-DSS
Vulnerability scans

No scheduled scan found — set up a quarterly ASV scan.

Pass / warn for each requirement, with exactly what was found — and what to do about the gaps.

If you run a business but can't afford a security team, Guard is it.

Guard fits best for:

People who benefit most
  • Founders & small teams — contract review and threat monitoring without hiring an expert.
  • Anyone signing vendor agreements — catch the traps before you sign, no lawyer needed.
  • Teams that need to prove compliance — a scorecard for clients, investors and audits.

Your security analyst, on call.

Guard is available on the Builder plan and above. On Solo you get 10 scans a month to try it. Contract scanning, threat monitoring and compliance — all running locally.