Local Origin
Observe an authorized origin through an explicit loopback or private transport while preserving its public canonical identity.
K-SHIELD ENTERPRISE Sentinel · v5.0.0
K-Shield observes authorized systems without exploiting them. It preserves forensic evidence, keeps observation perspectives distinct and gives operators control over data movement.
WHY K-SHIELD
K-Shield is a Python-based, single-node security assurance platform for authorized web systems. Its built-in plugins observe passively. They do not exploit vulnerabilities or change the target.
Each result records target identity, observation perspective, evidence lineage, integrity metadata and authorization context.
HOW IT WORKS
THREE PERSPECTIVES
Observe an authorized origin through an explicit loopback or private transport while preserving its public canonical identity.
Observe an explicitly authorized public endpoint, including behavior visible at the reachable edge.
Use the optional owner-managed authorization channel for controlled remote observation.
Local Origin does not describe CDN, WAF, public TLS, public DNS or other edge behavior unless those controls were observed separately. Correlation keeps unlike observations distinct.
WEB OPERATIONS CONSOLE
Server-side sessions, RBAC, CSRF controls, queue status, policy simulation, evidence review and assurance checks are available in one local administrative surface.
How console access works →EVIDENCE & KFIF
JSON, HTML, Markdown and KFIF artifacts preserve evidence, provenance, perspective and integrity metadata. KFIF verification detects content changes. Authenticity also requires a valid detached signature and a trusted key.
Explore KFIF 0.1 →ENTERPRISE ASSURANCE
Assurance Doctor checks privacy defaults, broker enforcement, capabilities, egress policy, signing trust, storage and backend state. PASS describes the current machine-tested state. It is not a certification or penetration-test result.
Understand PASS and WARN →PRIVACY BY DEFAULT
Analytics, crash upload, cloud sync, automatic report upload, silent OTEL transmission and update telemetry are disabled by default.
Read the privacy model →AUTHORIZED ENVIRONMENTS
For webmasters, self-hosters, DevOps teams, security engineers, internal IT, auditors and authorized researchers.
Review security boundaries →CURRENT RELEASE
SHA-256 manifests, signatures, verification and CycloneDX SBOM generation are implemented. Public packaging remains gated.
Release availability →TALK TO K-SHIELD
Tell us what you need. We will reply through a private email conversation. The public site does not expose product packages or administrative systems.
Choose a contact pathSTART WITH THE OPERATING MODEL