DataShield Guardian v0.9.4
Availability is a compliance control
A dead audit pipeline is an Art. 12 gap. Guardian is the daemon that keeps the governance stack — and the evidence plane it emits — alive.
EU AI Act Article 12 requires lifetime event logging. If your audit pipeline is down, the events it missed are gone. Guardian treats availability as a compliance control, not an ops nicety.
Audit pipeline availability: why a supervisor, not a dashboard
Observability tools tell you the audit pipeline died. Guardian's job is that it doesn't stay dead — and that the hash chain Auth seals stays continuous through the incident.
Guardian supervises the DataShield services (Auth, Ontology, the MCP surfaces) as a resident daemon: it gates boot order, watches resource trends before they become crashes, and restarts under governance rather than in a panic loop.
Phased boot, health gates, and restart circuit breakers
SafeBoot phased boot
Services come up in dependency phases — core, then Auth, then Ontology, then MCP surfaces — each behind a per-service health gate. A failing gate holds its phase instead of cascading a broken dependency upward.
Restart circuit breakers
A crashing service is restarted through a circuit breaker: after N failed restarts the breaker trips and the failure is surfaced instead of flapped. The stack recovers under governance, not panic.
Trend detection and load shedding
Memory-climb and CPU-trend detection catch degradation before it becomes an outage; load shedding drops non-essential work first so the evidence plane keeps writing. Telemetry is kept in retention tiers so incident history survives.
Three questions engineers ask us
Isn't this just Datadog or PagerDuty?
Those tell you something died and page a human. Guardian is a supervisor with a compliance objective: phased boot, health-gated dependencies, and governed restarts so the audit pipeline itself — the thing EU AI Act Art. 12 logging depends on — stays available without a human in the loop.
What happens to the audit chain during a crash?
The chain stays verifiable. Entries sealed before the crash remain intact, and verification distinguishes a truncation gap from tampering — so an outage window is visible and bounded, not silently papered over. Run the check on the verify page.
Is Guardian actually running anywhere?
Guardian v0.9.4 has been live in production on our own infrastructure since April 2026, supervising the same Auth and Ontology services described on this site.
Guardian v0.9.4 — live in production on our own infrastructure since April 2026. Fleet roll-up via Lighthouse.
Keep the evidence plane alive on your own infrastructure — self-hosted, supervised, verifiable.
See pricingYou've seen the proof
Ready for a number? Scope your deployment and we'll price it against your own economics.
Get your quote →