AEGUARD · AI-AGENT & ENDPOINT DETECTION FOR MACOS

AEGUARD · AI-AGENT & ENDPOINT DETECTION FOR MACOS

Know the moment your Mac stops being yours.

Know the moment your Mac stops being yours.

Know the moment your Mac stops being yours.

Apple Endpoint Security entitlement

Notarized Apple System Extension

Tamper-evident BLAKE3 ledger

100% local — data never leaves your Mac

Built by Astragar Limited — granted Apple’s restricted Endpoint Security entitlement, the same OS-level framework enterprise EDR tools use.

A local, tamper-evident audit log for macOS — built to catch what AI agents do on your machine. Aeguard learns your known-good baseline and records every change: files, processes, connections, USB, and AI-agent activity tied back to the agent behind it. Nothing leaves your device.

A local, tamper-evident audit log for macOS — built to catch what AI agents do on your machine. Aeguard learns your known-good baseline and records every change: files, processes, connections, USB, and AI-agent activity tied back to the agent behind it. Nothing leaves your device.

A local, tamper-evident audit log for macOS — built to catch what AI agents do on your machine. Aeguard learns your known-good baseline and records every change: files, processes, connections, USB, and AI-agent activity tied back to the agent behind it. Nothing leaves your device.

Detects AI agents

100% on-device

No keystroke capture

Local event chain

BLAKE3 verified

AI agent detected · acting autonomously

↳ terminal write to ~/.zshrc · tied to the agent

File fingerprint changed · /Applications

USB device attached · new identifier

Append-only, mirrored to Keychain — if the chain changes, the evidence shows it.

BUILT FOR THE AGENT ERA

AI can now find a way in — and act on its own.

AI can now find a way in — and act on its own.

AI can now find a way in — and act on its own.

Most tools watch for known-bad software. Agents aren’t malware you’ve blocklisted — they’re legitimate tools acting autonomously, and they leave the same footprints a person would. Aeguard is built to see them.

Most tools watch for known-bad software. Agents aren’t malware you’ve blocklisted — they’re legitimate tools acting autonomously, and they leave the same footprints a person would. Aeguard is built to see them.

Detect — by behavior, not signatures

Detect — by behavior, not signatures

Detect — by behavior, not signatures

Catches agents by how they act, even when they are renamed, unknown, embedded in another app, or driving your screen instead of the network. If something starts behaving like an autonomous agent, Aeguard flags it.

Attribute — back to the agent

Attribute — back to the agent

Attribute — back to the agent

When an agent spawns a script or shell that touches your files, network, or USB, that activity is tied to the agent that set it off — not lost in the process tree.

Cross-check — intent against reality

Cross-check — intent against reality

Cross-check — intent against reality

Aeguard lines up an agent’s own telemetry against what actually happened on the machine, and flags when the two do not match.

Every one of these lands in the same tamper-evident log as the rest of your endpoint activity — so an agent’s actions are evidence, not guesswork.

Every one of these lands in the same tamper-evident log as the rest of your endpoint activity — so an agent’s actions are evidence, not guesswork.

Every one of these lands in the same tamper-evident log as the rest of your endpoint activity — so an agent’s actions are evidence, not guesswork.

HOW IT WORKS

From known-good to trusted evidence.

From known-good to trusted evidence.

From known-good to trusted evidence.

Baseline

Records a known-good fingerprint of every file with BLAKE3.

Watch

Monitors files, processes, network, USB, clipboard metadata, browser history and AI-agent activity against the baseline.

Verify

Every event joins an append-only, hash-chained log mirrored to the Keychain; tampering shows.

WHAT YOU GET

Endpoint evidence you can actually use.

Endpoint evidence you can actually use.

Endpoint evidence you can actually use.

File integrity monitoring

Process, network & USB

AI-agent visibility (OpenTelemetry)

Tamper-evident hash chain

Search & alerts

Encrypted, off-machine checkpoints

LOCAL BY DESIGN

Your data never leaves the device.

Your data never leaves the device.

Your data never leaves the device.

Aeguard is detection and forensics, not prevention. It keeps the endpoint record close to the endpoint, with privacy boundaries built in.

Aeguard is detection and forensics, not prevention. It keeps the endpoint record close to the endpoint, with privacy boundaries built in.

✓ Runs entirely on your Mac (no cloud)

✓ Runs entirely on your Mac (no cloud)

✓ Encrypted at rest

✓ Encrypted at rest

✓ Clipboard metadata only (never contents)

✓ Clipboard metadata only (never contents)

✓ No keystroke capture

✓ No keystroke capture

✓ Nothing sold or shared

✓ Nothing sold or shared

HOW AEGUARD FITS ASTRAGAR

The risk platform now closes the loop at the device.

The risk platform now closes the loop at the device.

The risk platform now closes the loop at the device.

DRM identifies & values data

VRM quantifies the impact

GRC maps it to regulation

Aeguard closes the loop at the device

Aeguard is the detection module of the Astragar risk platform.

EARLY ACCESS

Be among the first to run Aeguard.

Be among the first to run Aeguard.

Be among the first to run Aeguard.

Free during the beta. Early access on macOS.

Free during the beta. Early access on macOS.

Download for Mac (Apple Silicon)

©Astragar All rights reserved.

©Astragar All rights reserved.

©Astragar All rights reserved.