K-SHIELD ENTERPRISE Sentinel · v5.0.0

Local-first security assurance.
Passive by design.
Evidence you can verify.

K-Shield observes authorized systems without exploiting them. It preserves forensic evidence, keeps observation perspectives distinct and gives operators control over data movement.

Read-onlyLocal-firstKFIF 0.1Zero implicit telemetry
Web Operations Console · sanitized

WHY K-SHIELD

Security work should leave an evidence trail.

K-Shield is a Python-based, single-node security assurance platform for authorized web systems. Its built-in plugins observe passively. They do not exploit vulnerabilities or change the target.

Each result records target identity, observation perspective, evidence lineage, integrity metadata and authorization context.

HOW IT WORKS

Authorize first. Observe second. Preserve the evidence.

  1. 01DefineTarget, perspective, transport, profile and plugins
  2. 02SimulateCheck policy and capabilities without target traffic
  3. 03ConfirmOne-time approval bound to the request
  4. 04ObserveAn authorized worker runs passive plugins
  5. 05PreserveEvidence, reports and KFIF

THREE PERSPECTIVES

Know where each observation came from.

01

Local Origin

Observe an authorized origin through an explicit loopback or private transport while preserving its public canonical identity.

02

Public Edge

Observe an explicitly authorized public endpoint, including behavior visible at the reachable edge.

03

Remote Authorized

Use the optional owner-managed authorization channel for controlled remote observation.

Local Origin does not describe CDN, WAF, public TLS, public DNS or other edge behavior unless those controls were observed separately. Correlation keeps unlike observations distinct.

WEB OPERATIONS CONSOLE

One authenticated workspace for operators.

Server-side sessions, RBAC, CSRF controls, queue status, policy simulation, evidence review and assurance checks are available in one local administrative surface.

How console access works →
Web Operations Console · sanitized

EVIDENCE & KFIF

Reports that keep their context.

JSON, HTML, Markdown and KFIF artifacts preserve evidence, provenance, perspective and integrity metadata. KFIF verification detects content changes. Authenticity also requires a valid detached signature and a trusted key.

Explore KFIF 0.1 →
Web Operations Console · sanitized

ENTERPRISE ASSURANCE

Machine-tested controls with clear limits.

Assurance Doctor checks privacy defaults, broker enforcement, capabilities, egress policy, signing trust, storage and backend state. PASS describes the current machine-tested state. It is not a certification or penetration-test result.

Understand PASS and WARN →
Web Operations Console · sanitized

PRIVACY BY DEFAULT

Zero implicit telemetry.

Analytics, crash upload, cloud sync, automatic report upload, silent OTEL transmission and update telemetry are disabled by default.

Read the privacy model →

AUTHORIZED ENVIRONMENTS

Built for owners and operators.

For webmasters, self-hosters, DevOps teams, security engineers, internal IT, auditors and authorized researchers.

Review security boundaries →

CURRENT RELEASE

Sentinel · 5.0.0

SHA-256 manifests, signatures, verification and CycloneDX SBOM generation are implemented. Public packaging remains gated.

Release availability →

TALK TO K-SHIELD

Early access, commercial evaluation, partnerships or security disclosure.

Tell us what you need. We will reply through a private email conversation. The public site does not expose product packages or administrative systems.

Choose a contact path

START WITH THE OPERATING MODEL

Understand authorization, perspective and evidence before the first scan.