Now in beta

Know the moment your Mac or Windows PC stops being yours.

Know the moment your Mac or Windows PC stops being yours.

See what AI agents actually do on your Mac or Windows PC.

See what AI agents actually do on your Mac or Windows PC.

See what AI agents actually do on your Mac or Windows PC.

Apple Endpoint Security entitlement

Notarized Apple System Extension

Tamper-evident BLAKE3 ledger

Local-first: your monitoring data stays on your Mac or Windows PC

Astragar Limited is a registered Apple Developer, granted Apple’s Endpoint Security entitlement. Every build is signed and notarized.

Aeguard is a local, tamper-evident audit log for the AI-agent era. It learns your Mac or Windows PC’s known-good baseline and records every change: files, processes, network connections, USB, and AI-agent activity, tied back to the agent behind it. Real-time, on-device, and your monitoring data stays on your machine.

Aeguard is a local, tamper-evident audit log for the AI-agent era. It learns your Mac or Windows PC’s known-good baseline and records every change: files, processes, network connections, USB, and AI-agent activity, tied back to the agent behind it. Real-time, on-device, and your monitoring data stays on your machine.

Aeguard is a local, tamper-evident audit log for the AI-agent era. It learns your Mac or Windows PC’s known-good baseline and records every change: files, processes, network connections, USB, and AI-agent activity, tied back to the agent behind it. Real-time, on-device, and your monitoring data stays on your machine.

Requirements: macOS 13 (Ventura) or later, Apple Silicon and Intel.

Aeguard keeps your monitoring data on your Mac. The one thing it can send us is a Report a concern message you choose to write; it’s on by default so we hear about problems, and you can switch it off in-app (Help → Privacy) or leave it off in local-only mode.

Full detail in our

.

New to Windows? Read the install guide

Beta · Free for macOS and Windows

Detects AI agents

100% on-device

No keystroke capture

Local event chain

BLAKE3 verified

AI agent detected · acting autonomously

↳ terminal write to ~/.zshrc · tied to the agent

File fingerprint changed · /Applications

USB device attached · new identifier

Append-only, mirrored to Keychain: if the chain changes, the evidence shows it.

BUILT FOR THE AGENT ERA

AI can now find a way in and act on its own.

AI can now find a way in and act on its own.

AI can now find a way in and act on its own.

Most tools watch for known-bad software. Agents aren’t malware you’ve blocklisted; they’re legitimate tools acting autonomously, and they leave the same footprints a person would. Aeguard is built to see them.

Most tools watch for known-bad software. Agents aren’t malware you’ve blocklisted; they’re legitimate tools acting autonomously, and they leave the same footprints a person would. Aeguard is built to see them.

Catch AI agents in the act

Catch AI agents in the act

Catch AI agents in the act

Aeguard reads each agent’s own rulebook, its CLAUDE.md and settings, and checks whether what it actually does matches what it declared, flagging violations like an agent reading your SSH keys.

Real-time, kernel-level monitoring

Real-time, kernel-level monitoring

Real-time, kernel-level monitoring

Built on Apple’s Endpoint Security framework, Aeguard sees process launches, file changes, and code injection as they happen, with the responsible process identified.

Tamper-evident by design

Tamper-evident by design

Tamper-evident by design

Every event is cryptographically chained and anchored off-machine, so a rogue agent or malware can’t quietly rewrite history. If something changes, you’ll know.

Every one of these lands in the same tamper-evident log as the rest of your endpoint activity, so an agent’s actions are evidence, not guesswork.

Every one of these lands in the same tamper-evident log as the rest of your endpoint activity, so an agent’s actions are evidence, not guesswork.

HOW IT WORKS

From known-good to trusted evidence.

From known-good to trusted evidence.

From known-good to trusted evidence.

Baseline

Records a known-good fingerprint of every file with BLAKE3.

Watch

Monitors files, processes, network, USB, clipboard metadata, browser history and AI-agent activity against the baseline.

Verify

Every event joins an append-only, hash-chained log mirrored to the Keychain; tampering shows.

WHAT YOU GET

Endpoint evidence you can actually use.

Endpoint evidence you can actually use.

Endpoint evidence you can actually use.

File integrity monitoring

Process, network & USB

AI-agent visibility (OpenTelemetry)

Tamper-evident hash chain

Search & alerts

Encrypted, off-machine checkpoints

REAL-TIME DETECTION

The moment it happens - with the actor attached.

The moment it happens - with the actor attached.

The moment it happens - with the actor attached.

Built on Apple’s Endpoint Security framework, Aeguard catches a whole class of attacks in real time - each event carrying the process that caused it. Polling was blind to all of these.

Built on Apple’s Endpoint Security framework, Aeguard catches a whole class of attacks in real time - each event carrying the process that caused it. Polling was blind to all of these.

Built on Apple’s Endpoint Security framework, Aeguard catches a whole class of attacks in real time - each event carrying the process that caused it. Polling was blind to all of these.

Thread injection

Thread injection

code injected into another process

ptrace / debugger attach

ptrace / debugger attach

a process latching onto another

Runtime code-signature invalidation

Runtime code-signature invalidation

signed code tampered after launch

Background-item (BTM) persistence

Background-item (BTM) persistence

new login & background items

Privilege & auth changes

Privilege & auth changes

escalations and authorization events

XProtect malware hits

XProtect malware hits

Apple’s malware scanner firing

Kernel-extension (kext) loads

Kernel-extension (kext) loads

drivers loading into the kernel

Volume mounts

Volume mounts

disks and disk images mounting

Sensitive-file reads

Sensitive-file reads

access to protected files

Each detection arrives already attributed to the process behind it - detect-only, on-device, sealed into your tamper-evident log.

Each detection arrives already attributed to the process behind it - detect-only, on-device, sealed into your tamper-evident log.

Each detection arrives already attributed to the process behind it - detect-only, on-device, sealed into your tamper-evident log.

LOCAL BY DESIGN

Your records stay on your device.

Your records stay on your device.

Your records stay on your device.

Aeguard is detection and forensics, not prevention. It keeps the endpoint record close to the endpoint, with privacy boundaries built in. The only things that ever leave: a cryptographic fingerprint of your log, the off-machine anchor that makes tampering provable, never the contents, and a Report-a-concern message when you choose to send one.

Aeguard is detection and forensics, not prevention. It keeps the endpoint record close to the endpoint, with privacy boundaries built in. The only things that ever leave: a cryptographic fingerprint of your log, the off-machine anchor that makes tampering provable, never the contents, and a Report-a-concern message when you choose to send one.

✓ Runs entirely on your Mac or Windows PC

✓ Runs entirely on your Mac or Windows PC

✓ Encrypted at rest

✓ Encrypted at rest

✓ Clipboard metadata only (never contents)

✓ Clipboard metadata only (never contents)

✓ No keystroke capture

✓ No keystroke capture

✓ Nothing sold or shared

✓ Nothing sold or shared

HOW AEGUARD FITS ASTRAGAR

The risk platform now closes the loop at the device.

The risk platform now closes the loop at the device.

The risk platform now closes the loop at the device.

DRM identifies & values data

VRM quantifies the impact

GRC maps it to regulation

Aeguard closes the loop at the device

Aeguard is the detection module of the Astragar risk platform.

DOWNLOAD

Run Aeguard on your Mac or Windows PC.

Run Aeguard on your Mac or Windows PC.

Run Aeguard on your Mac or Windows PC.

Beta · Free for macOS and Windows

Beta · Free for macOS and Windows

Requirements: macOS 13 (Ventura) or later, Apple Silicon and Intel.

Aeguard keeps your monitoring data on your Mac. The one thing it can send us is a Report a concern message you choose to write; it’s on by default so we hear about problems, and you can switch it off in-app (Help → Privacy) or leave it off in local-only mode.

Full detail in our

.

INSTALL · WINDOWS

Installing the Windows edition

Installing the Windows edition

Installing the Windows edition

Because each build is freshly signed, Windows and your browser may warn before they recognise it. Here’s how to get it running in under a minute and how to confirm it’s genuinely from us.

Download for Windows

Signed NSIS installer (aeguardwin-setup.exe) · Publisher Astragar Limited

If your browser blocks the download

  • Chrome: click the ⋯ next to the blocked download, then Keep.

  • Edge: click the ⋯ on the download, then Keep → Keep anyway.

The blue “Windows protected your PC” box

  1. Click More info, the small link in the dialog.

  2. Confirm it reads Publisher: Astragar Limited; that’s the proof it’s really ours.

  3. Click Run anyway.

That’s the whole thing: More info → Run anyway.

Still won’t unblock? (optional)

Right-click aeguardwin-setup.exePropertiesGeneral tab → tick Unblock at the bottom → OK, then run it.

How to check it’s genuine

Right-click the file → PropertiesDigital Signatures tab. You’ll see Astragar Limited with a valid Microsoft timestamp, the same signature on every build we ship.

©Astragar All rights reserved.

©Astragar All rights reserved.

©Astragar All rights reserved.