DataShield Guardian v0.9.4

Availability is a compliance control

A dead audit pipeline is an Art. 12 gap. Guardian is the daemon that keeps the governance stack — and the evidence plane it emits — alive.

EU AI Act Article 12 requires lifetime event logging. If your audit pipeline is down, the events it missed are gone. Guardian treats availability as a compliance control, not an ops nicety.

Availability is a compliance control SafeBoot brings services up phase by phase behind health gates; Guardian supervises the evidence plane, trips a circuit breaker on a crashed service, and the audit hash chain runs unbroken through the crash window. SAFEBOOT LADDER Phase 0 — Core health? Phase 1 — Auth health? Phase 2 — Ontology health? hold phase — don’t cascade Phase 3 — MCP surfaces EVIDENCE PLANE Auth healthy Ontology crashed MCP healthy recovered → Guardian daemon health · memory-climb · CPU trend · load shed breaker trips after N Lighthouse reports up AUDIT HASH CHAIN — UNBROKEN chain continuous through crash window EVIDENCE LANE Ed25519 checkpoint verify_chain → VALID

Audit pipeline availability: why a supervisor, not a dashboard

Observability tools tell you the audit pipeline died. Guardian's job is that it doesn't stay dead — and that the hash chain Auth seals stays continuous through the incident.

Guardian supervises the DataShield services (Auth, Ontology, the MCP surfaces) as a resident daemon: it gates boot order, watches resource trends before they become crashes, and restarts under governance rather than in a panic loop.

Phased boot, health gates, and restart circuit breakers

SafeBoot phased boot

Services come up in dependency phases — core, then Auth, then Ontology, then MCP surfaces — each behind a per-service health gate. A failing gate holds its phase instead of cascading a broken dependency upward.

Restart circuit breakers

A crashing service is restarted through a circuit breaker: after N failed restarts the breaker trips and the failure is surfaced instead of flapped. The stack recovers under governance, not panic.

Trend detection and load shedding

Memory-climb and CPU-trend detection catch degradation before it becomes an outage; load shedding drops non-essential work first so the evidence plane keeps writing. Telemetry is kept in retention tiers so incident history survives.

Three questions engineers ask us

Isn't this just Datadog or PagerDuty?

Those tell you something died and page a human. Guardian is a supervisor with a compliance objective: phased boot, health-gated dependencies, and governed restarts so the audit pipeline itself — the thing EU AI Act Art. 12 logging depends on — stays available without a human in the loop.

What happens to the audit chain during a crash?

The chain stays verifiable. Entries sealed before the crash remain intact, and verification distinguishes a truncation gap from tampering — so an outage window is visible and bounded, not silently papered over. Run the check on the verify page.

Is Guardian actually running anywhere?

Guardian v0.9.4 has been live in production on our own infrastructure since April 2026, supervising the same Auth and Ontology services described on this site.

Guardian v0.9.4 — live in production on our own infrastructure since April 2026. Fleet roll-up via Lighthouse.

Keep the evidence plane alive on your own infrastructure — self-hosted, supervised, verifiable.

See pricing

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →