Guardian Agent security workspace with diagrams, findings and GRC context

Guardian Agent

Understand your environment. Connect the risks. Stay in control.

Open-source security workspace that merges Guardian operations with Context Cypher diagram and GRC workflows. Check workstation posture, turn environments into editable diagrams, analyse threats with AI, manage GRC, and connect assistants through MCP, CLI and HTTP. Runs locally on Windows, macOS and Linux.

Guardian Agent is open source under Apache 2.0. Clone the repository, build locally, and keep control of your security workspace.

Also available

Context Cypher

Standalone open-source threat modeling and diagram tool. Use it on its own, or import Context Cypher files into Guardian Agent.

GUARDIAN AGENT CAPABILITIES

Security findings are more useful when you can see what they affect. Move from an observation on a workstation or network to the system diagram, assets, risks and controls needed to decide what to do next.

Check your workstation

Review host posture, Microsoft Defender status and registered antivirus products. Propose and approve supported Defender scans.

Understand your environment

Review local network observations or enrolled AWS inventory, preview a snapshot, and turn it into an editable system diagram.

Model your systems

Build diagrams with a drag-and-drop toolbox, security zones, detailed node and connection data, and layout tools. Import Context Cypher files when needed.

Analyse threats with AI

Ask security questions, analyse selected architecture and generate proposed diagrams with your chosen provider. Review results before you apply them.

Connect diagrams to GRC

Sync diagram nodes into the asset register, link risks to diagram elements, and manage controls, assessments, evidence and statements of applicability.

Review and report

Investigate findings, record review decisions, inspect activity, and export diagrams, portable project files and GRC reports.

Work with AI assistants

Give Codex, Claude Code and other compatible clients scoped access through MCP, CLI and HTTP interfaces, with approvals kept in the loop.

Local-first control

Runs on your machine and binds to loopback by default. Supported security actions use explicit permissions, approvals and recorded decisions.

Context Cypher inside

Guardian Agent includes Context Cypher diagram and GRC workflows in one workspace, while Context Cypher remains available as a standalone open-source tool.

Get Guardian Agent

Prefer the standalone diagram tool? See Context Cypher downloads or contact support