Agent
Lightweight Windows agent. Outbound mTLS only. No inbound port.
Private · self-hostedTamandua Sentinel is a self-hosted EDR/XDR built for exchanges, custody, treasury and validator teams. Endpoint telemetry stays on your servers. Only privacy-safe security attestations are anchored on Solana.
A six-stage pipeline: telemetry never leaves your perimeter, but anyone can verify the integrity of an incident on-chain.
Lightweight Windows agent. Outbound mTLS only. No inbound port.
Private · self-hostedSigma/YARA plus behavioral rules running locally on the host.
Private · self-hostedHashed indicators of compromise. Process, file and network metadata.
Private · self-hostedKill, quarantine, isolate. Operator-signed live response.
Private · self-hostedManifest hash anchored on Solana. No telemetry on-chain.
Public · SolanaAnyone can verify the proof exists. No customer data exposed.
Public · SolanaCryptographic record that a detection occurred without exposing what was on the host.
Periodic attestation of fleet posture: clean endpoints, ingestion health and agent count.
Counter-attestation linked back to an incident, signed after live response actions are executed.
Tamandua publishes hashes and metadata, never hostnames, usernames, file paths, IP addresses or raw telemetry. The on-chain footprint is fixed-size, content-free and deterministic.
One infostealer on a treasury workstation rewrites your week. Tamandua assumes the threat already touched the keyboard.
Hot-key custodians, ops desks and support consoles with high blast radius.
Air-gapped signers, ceremony stations and offline coordinators.
Trading desks, strategy hosts and key-bearing relays.
Multisig signers, settlement desks and finance operations.
Staking operations, RPC operators and infrastructure on-call teams.
MSSPs, in-house SOCs and responders who want Sigma/YARA, not telemetry hostage.
High-throughput public ledger that can absorb continuous health attestations without backpressure on the SOC.
A proof every minute is economically viable. Auditors and counterparties pay nothing to verify.
Anyone can confirm an incident hash exists, when it landed and which manifest signed it.
Self-hosted agent enrollment, server, dashboard, basic detections, response paths and devnet proof metadata validated in a lab scope.
Community hub, component mirrors, docs and contribution/security guidance are public with explicit claim boundaries and production gaps.
Curated detection/config workflow, bounty validation gates and public audit/feed views.
Repeatable Atomic Red Team and Caldera reports, false-positive tracking and detector evidence.
Mainnet policy, bounty settlement controls, advanced NDR validation and Policy Gate prototype work.