CAPABLE BY DESIGN. HONEST BY DEFAULT.

Protection, with
you in control.

Focused tools. Clear signals. A transparent foundation
for a free, open-source security project.

01
STAY IN THE LOOP

Real-time awareness.

Native filesystem watchers scan created and modified files in your selected folders. A bounded, debounced queue keeps bursts manageable and makes dropped events visible.

  • inotify on Linux, ReadDirectoryChangesW on Windows, FSEvents on macOS
  • Sampled process creation awareness through running executable scans
  • Local interface traffic counters; no network blocking
  • Explicit coverage status and configurable exclusions
02
QUICK. FULL. YOUR CHOICE.

A scan that fits your day.

Choose a focused check, sweep accessible volumes, or scan selected folders. Streamed enumeration avoids retaining an entire filesystem inventory in memory.

  • Quick: running executables, startup folders, downloads, common browser extensions
  • Full: accessible mounted volumes, with skipped files and errors reported
  • Custom: folders and drives selected through native dialogs
  • Pause, resume, cancel, throughput-based time estimate, and saved reports
03
LOOK INSIDE

A transparent detection engine.

A SHA-256 signature database pairs with optional YARA matching and conservative script heuristics. Detection details explain exactly what matched.

  • No file execution or sample uploads
  • Bounded reads, regular-file checks, and symlink avoidance
  • Ed25519-authenticated signature feed with replay protection
  • Bundled signatures are examples and harmless test detections
04
CONTROL COMES STANDARD

Every action is your call.

Review a report, quarantine a detected file, allow an exact hash, or leave it pending. Quarantine encrypts backups and restoration refuses to overwrite existing files.

  • ChaCha20-Poly1305 authenticated encryption for quarantine content
  • Private per-user storage and local history
  • Source rehashing before removal; incomplete actions reported
  • Cloud lookup stays off; no provider is included

Know the current boundaries.

This release is a source preview. It does not scan process memory, unpack archives, intercept kernel file access, block execution, or provide a production malware corpus. Watcher and process sampling can miss activity. Keep existing protection while evaluating, and help us harden the next release.

Read the coverage notes
YOUR NEXT CHAPTER. A LITTLE MORE PROTECTED.

Peace of mind.
Without the price tag.

Unbreakable Protection. Zero Cost. Built in Rust.

100% free forever · Open source · No account required