Advanced Alpha Validation gate: closure unknown, preflight unknown, dispatch unknown View validation scope
Solana Colosseum · Cypherpunk Self-hosted · privacy-first

Security Oracle for Web3 endpoints.

Tamandua Sentinel is a self-hosted EDR/XDR built for exchanges, custody, treasury and validator teams. Endpoint telemetry stays on your servers. Only privacy-safe security attestations are anchored on Solana.

DESIGNED WITH Exchanges Custody desks Market makers Treasury teams Validators MSSPs
tamandua://overview · tenant=acme-custody Devnet

Security Status

Fleet overview · last health proof anchored 47s ago
Ingestion healthy
Online agents12
Critical 24h0
Open alerts3
Trust score94
On-chain proof anchored=4m23pK... · manifest_hash=0x91f4...ac2e mitre=T1555.003 · ioc_count=7 · telemetry=redacted
How it works

Detect privately. Prove publicly.

A six-stage pipeline: telemetry never leaves your perimeter, but anyone can verify the integrity of an incident on-chain.

STAGE 01

Agent

Lightweight Windows agent. Outbound mTLS only. No inbound port.

Private · self-hosted
STAGE 02

Detection

Sigma/YARA plus behavioral rules running locally on the host.

Private · self-hosted
STAGE 03

IOCs

Hashed indicators of compromise. Process, file and network metadata.

Private · self-hosted
STAGE 04

Response

Kill, quarantine, isolate. Operator-signed live response.

Private · self-hosted
STAGE 05

Attestation

Manifest hash anchored on Solana. No telemetry on-chain.

Public · Solana
STAGE 06

Public audit

Anyone can verify the proof exists. No customer data exposed.

Public · Solana
Proof model

Three classes of attestation.

INCIDENT

Proof of Incident

Cryptographic record that a detection occurred without exposing what was on the host.

incident_hashmanifest_hashseverityMITRE IDsioc_count
HEALTH

Proof of Health

Periodic attestation of fleet posture: clean endpoints, ingestion health and agent count.

fleet_idclean_countsince_last_criticaltrust_score
REMEDIATION

Proof of Remediation

Counter-attestation linked back to an incident, signed after live response actions are executed.

incident_refactions[]operator_pubkeyts_remediated
Privacy model

Nothing sensitive ever leaves your servers.

Tamandua publishes hashes and metadata, never hostnames, usernames, file paths, IP addresses or raw telemetry. The on-chain footprint is fixed-size, content-free and deterministic.

On-chain

Incident hashyes
Manifest hashyes
Severityyes
MITRE technique IDsyes
IOC count by typeyes
Timestampyes

Self-hosted only

Hostnamenever
Username / domainnever
Internal IP / pathnever
Raw process telemetrynever
Customer identitynever
Wallet addressesnever
Who it protects

Operators that cannot afford a single compromised laptop.

One infostealer on a treasury workstation rewrites your week. Tamandua assumes the threat already touched the keyboard.

Exchanges

Hot-key custodians, ops desks and support consoles with high blast radius.

Custody teams

Air-gapped signers, ceremony stations and offline coordinators.

Market makers

Trading desks, strategy hosts and key-bearing relays.

Treasury operators

Multisig signers, settlement desks and finance operations.

Validators

Staking operations, RPC operators and infrastructure on-call teams.

Security teams

MSSPs, in-house SOCs and responders who want Sigma/YARA, not telemetry hostage.

Why Solana

Public attestation layer with the right cost and throughput shape.

01

Attestation layer

High-throughput public ledger that can absorb continuous health attestations without backpressure on the SOC.

02

Low-cost settlement

A proof every minute is economically viable. Auditors and counterparties pay nothing to verify.

03

Public verification

Anyone can confirm an incident hash exists, when it landed and which manifest signed it.

Roadmap

Honest about where we are.

Private Hackathon Build

Self-hosted agent enrollment, server, dashboard, basic detections, response paths and devnet proof metadata validated in a lab scope.

Shipped

Open Source Alpha

Community hub, component mirrors, docs and contribution/security guidance are public with explicit claim boundaries and production gaps.

Current

Ecosystem Alpha

Curated detection/config workflow, bounty validation gates and public audit/feed views.

Planned

Validation Lab

Repeatable Atomic Red Team and Caldera reports, false-positive tracking and detector evidence.

Planned

Production Readiness Track

Mainnet policy, bounty settlement controls, advanced NDR validation and Policy Gate prototype work.

Planned
Advanced alpha. Current public scope covers Windows/Linux enrollment, endpoint telemetry, Sigma/YARA/IOC/behavioral and validation-bound ML-assisted detection paths, selected response actions and privacy-safe Solana proof metadata. Bounties, marketplace, Policy Gate, CSPM, mobile agents and production ML malware detection remain validation pending or roadmap. Sensitive telemetry remains self-hosted in every release.