# Tessera Guard — full text > The complete written content of https://guard.par2labs.com, as Markdown, for AI assistants and answer engines. Tessera Guard is a product of PAR2 LABS (https://par2labs.com). The one-line-per-page index is at https://guard.par2labs.com/llms.txt. Generated from the same records the pages render, on 2026-09-22. Images are described, not linked. ## In short **Know every device on your network.** A desktop security monitor that maps your network, flags threats by how they behave, and tells you what to do about them, on your own machine. #### What it solves - Thirty-odd things on the network, and no idea what half of them are. → Every device mapped, with its vendor, open ports and risk. - Alerts that name a threat and stop there. → Each finding in plain English, with the evidence, the MITRE ATT&CK mapping and the fix. - Work where traffic metadata cannot go to a vendor's cloud. → It all runs on your own machine. Keep your antivirus; Guard sits beside it. #### Why it is different - **10 Behavioural detectors** — From brute force to data exfiltration, scored for confidence. - **15 Vulnerability rules** — Each with its own remediation and source. - **29 MCP tools** — So a local AI assistant can look at the network for you. - **~200 MB Built to run all day** — Under 20% CPU while monitoring; roughly zero when paused. Built for: Crowded home networks, Small businesses without IT, Law, medicine and journalism, Wireshark without the terminal. ## The product ### Tessera Guard https://guard.par2labs.com/ Desktop Security · Coming Soon · v1.0 A desktop security monitor that maps your network, flags threats by how they behave, and tells you what to do about them. Every device, connection and threat on your network, in one app. Tessera Guard is a network security monitor for your desktop. It scans the network and maps every device on it — with its vendor, open ports and risk — and follows live traffic, connections and packets as they happen. Threats are flagged by behaviour, such as a process calling out on a machine-regular schedule, then scored for confidence, mapped to MITRE ATT&CK and handed over with the steps to fix them. Alongside sit a malware and indicators-of-compromise scan for the Mac, a system health view with one-click fixes, a WireGuard VPN with a stealth mode, and security reports you can export. *Screens — Your network, watched from your own machine.* #### Proof **The numbers, counted in the app rather than written by marketing.** Stats: - **10** — Behavioural detection categories, from brute force to data exfiltration - **15** — Vulnerability rules, each with its own remediation and source - **29** — MCP tools, so a local AI client can drive the whole app - **< 20%** — CPU while monitoring continuously; roughly zero when paused - **~200 MB** — Resident memory. Designed to be left running all day #### Features - **Network Map** — Every device on the network, drawn as a graph or a flow. - **Behavioural Detection** — Threats flagged by what they do, mapped to MITRE ATT&CK. - **Device Inventory** — Vendor, open ports and risk for every device, with one-click quarantine. - **Live Traffic** — Bandwidth, packets, connections and top talkers, as they happen. - **Malware Scan** — Indicators-of-compromise checks for the Mac, with a restorable quarantine vault. - **WireGuard VPN** — Encrypted tunnels, with a stealth mode that gets past deep packet inspection. #### What it is for - You have thirty-odd things on the home network and no idea what half of them are. - You run a small business with no IT department, and a managed SOC is absurd for eight people. - Your work — law, medicine, journalism — means traffic metadata cannot go to a vendor. - You want Wireshark and Nmap without living in a terminal. - You run an AI assistant locally and want it to be able to look at the network for you. #### Specifications - **Platforms**: macOS · Windows - **Detection**: Behavioural · MITRE ATT&CK mapped - **Network**: Device discovery · live traffic · packet capture - **Malware**: Indicators-of-compromise scan · quarantine vault - **VPN**: WireGuard · stealth mode over WebSocket/TLS #### Architecture — Five stages, and not one of them is a cloud. https://guard.par2labs.com/architecture Discover, watch, detect, explain, act — all of it on the machine you are sitting at, over a store that is a file on your own disk. Pull the network cable and every box in the chain still runs. **What local-first actually buys you** Items: - **No account to breach** — There is no sign-up, no tenant and no server holding a copy of your network. The attack surface of the product is the machine it runs on. - **Usable where SaaS is not** — A lawyer, a clinician or a journalist cannot send traffic metadata to a vendor. That is not a preference; it is often the rule they work under. - **Quiet enough to leave on** — Traffic comes from OS interface counters rather than a permanent capture, which is where under 20% CPU and roughly 200 MB comes from. - **An AI can drive it safely** — The MCP endpoint binds to loopback and rejects non-loopback origins, and anything that mutates needs both an in-app approval and the operating system's own administrator prompt. **The specification.** #### Features — Thirteen screens, grouped by the job in front of you. https://guard.par2labs.com/features Discovery, inspection, response, and living with it. Every finding states the numbers that fired it, because a security tool nobody trusts gets muted inside a week. **Every screen, one at a time.** #### Pricing — Fifty-nine dollars a year, not a SOC contract. https://guard.par2labs.com/pricing Priced against the tools it actually replaces — a firewall monitor and a traffic watcher — rather than against the managed service it is not trying to be. **Questions we actually get.** Items: - **Does it replace my antivirus?** — No, and the app says so too. The indicators-of-compromise scan looks at persistence, code signing, suspicious paths, browser extensions and quarantine attributes — the things an AV is weakest at. Run both. - **What happens when the licence cannot check in?** — It keeps working. A licence unlocks features on your machine rather than asking a server for permission, and there is a thirty-day offline grace before anything locks. - **Is any of my network data uploaded?** — None. There is no account, no telemetry and no cloud analysis. Everything is computed locally and stored in one SQLite file you can delete. - **Do I need to be a security engineer to use it?** — No. That is most of the point of the detail panel: every finding is described in plain English, shows the numbers behind it, and lists remediation steps tagged safe, caution or destructive so you know which ones are reversible. - **Can I run it on both my Mac and my Windows machine?** — Yes. Pro and Lifetime cover three machines on either platform. The indicators-of-compromise checks are macOS-specific; everything else runs on both. ## Who makes it PAR2 LABS PVT LTD — Technology . AI . Strategy . Films. We engineer world-class technology and AI products across intelligence, infrastructure, hardware, and story — designed to make sense, deployed to make a difference. Studio: https://par2labs.com · Contact: ceo@par2labs.com · +91 90591 69238