Guardian plans and add-ons

Choose the operating responsibility first. Then add the products and quantities you need.

Guardian packages define the customer operating model. Product entitlements define the technical capability and quantities. Managed products and Aegis define the work Damocles is responsible for performing.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Core customer workspaceAssurance adds remediation depthManaged Defence adds AegisProducts retain explicit quantities and scope
How to choose

Packages describe the operating model; products describe the actual control or security capability.

Start with Guardian Core when the customer needs one governed place for posture, risk, actions, human defence, baseline external exposure and evidence. Add Guardian Assurance where deeper vulnerability and remediation verification are required. Add Guardian Managed Defence where Aegis will perform contracted monitoring, triage, investigation and escalation.

Managed endpoint, DNS and WAF controls; vulnerability and monitoring products; Katana; external monitoring; infrastructure assessment; intelligence and other modules remain separately defined. The applicable schedule identifies exactly what is entitled, the quantity, the connector and which party operates it.

01

Package

Defines the customer workspace and broad operating model.

02

Product entitlement

Defines the protection, assurance, monitoring or specialist capability plus its quantity and covered scope.

03

Managed responsibility

Defines what Damocles operates, monitors, investigates, coordinates or reports and during which contracted service window.

Quick package comparison

See what changes as Guardian operating responsibility increases.

The comparison state is derived from the package SSOT. Core provides the shared customer workspace. Assurance adds deeper vulnerability and remediation capability. Managed Defence adds Guardian Security Operations and Aegis. Managed protection and specialist products remain explicit add-ons.

CapabilityGuardian CoreGuardian AssuranceGuardian Managed Defence
Guardian customer workspaceIncludedIncludedIncluded
Guardian Security DashboardIncludedIncludedIncluded
Risk Register and All ActionsIncludedIncludedIncluded
Guardian University and Human RiskIncludedIncludedIncluded
Guardian Dark Web MonitoringIncludedIncludedIncluded
Website Vulnerability MonitoringIncludedIncludedIncluded
Standard evidence and reportingIncludedIncludedIncluded
Vulnerability and RemediationUpgrade to AssuranceIncludedIncluded
Security Operations and AegisAdd-onAdd-onIncluded
Endpoint Protection and Managed PatchingAdd-onAdd-onAdd-on
DNS ProtectionAdd-onAdd-onAdd-on
Katana Website and API Security TestingAdd-onAdd-onAdd-on
Core website monitoring and Katana are different products

Guardian Core includes baseline vulnerability monitoring for the approved website allowance. Katana is selected for deeper active website and API testing, authenticated or custom profiles, additional cadence, evidence and rescans.

Package positioning

What changes as operating responsibility increases.

Commercial structure approved for website drafting; dollar pricing and exact allowances remain proposal-specific until separately approved.

Guardian Core
01

Guardian Core

A customer workspace for understanding security posture, managing risk and completing accountable action. Schedule-specific allowances and service quantities: University user and content allowances are confirmed in the package schedule. Dark Web monitored domains, email addresses and keywords are confirmed in the package schedule. Included websites and website-vulnerability monitoring cadence are confirmed in the package schedule. Katana active website and API security testing, custom assessment profiles and additional assessment activity are separately entitled. Custom training content and expanded monitoring scope may be separately priced.

Guardian Assurance
02

Guardian Assurance

Guardian Core plus deeper vulnerability and remediation assurance. Schedule-specific allowances and service quantities: Asset volumes, compatible connectors, verification and managed remediation support are confirmed in the package schedule.

Guardian Managed Defence
03

Guardian Managed Defence

Guardian Assurance plus customer-facing security operations and the Aegis managed service. Schedule-specific allowances and service quantities: Coverage hours, monitored scope, ingestion, retention, investigation and escalation commitments are confirmed in the applicable service agreement.

Products remain explicit

A package name never hides the actual licensed or managed products.

Select products according to the customer estate and required operating responsibility. Exact quantities and commercial terms remain in the approved schedule.

PR

Protection

Endpoint Protection and Managed Patching, DNS Protection and Svalinn Managed WAF are selected for the approved protected estate.

Browse products →
AS

Assurance

Vulnerability Management, Katana Website and API Security Testing, External Vulnerability Monitoring and Infrastructure Assessment add defined technical coverage.

Browse products →
MD

Monitoring and managed defence

Security Monitoring provides the compatible monitoring model; Aegis adds contracted Damocles source-health, triage, investigation, escalation and reporting activity.

Browse products →
SP

Specialist capability

Guardian Intelligence and Advanced Security Reporting are separately entitled where their governed workflows are required.

Browse products →
ZS

ZeroShield bundles

ZeroShield packages explicit Guardian products and quantities together; the bundle name does not replace the component entitlements.

View ZeroShield →
PS

Professional services

Penetration testing, code review, cloud review, incident work, network engineering, custom connectors and specialist remediation remain separately scoped services.

Browse Damocles services →
Before activation

Commercial schedules resolve the details that package names cannot.

QT

Quantities and estate

Users, participants, endpoints, websites, public assets, monitored identifiers, targets and source counts are recorded explicitly.

CN

Connector and technology

The selected compatible source or security technology, licensing responsibility and supported integration are identified before activation.

SV

Service coverage

Coverage hours, source-health process, triage, investigation, escalation, support and reporting commitments are stated rather than inferred.

RA

Response authority

Monitoring does not automatically authorise endpoint isolation, identity disablement, firewall change, containment or other production action.

EV

Evidence and closure

The package or service defines which source state, rescan, retest, configuration, investigation or other evidence supports resolution review.

CM

Commercial relationship

Direct and MSP relationships can use different approved commercial schedules without changing the customer product entitlement.

Pricing publication status

Public pages explain inclusions and boundaries; approved commercial schedules provide prices and exact allowances.

The website does not publish internal cost, wholesale pricing, direct pricing, recommended retail pricing or MSP customer retail pricing unless a separate approval process authorises that publication.

The approved proposal and package schedule define product codes, quantities, effective dates, allowances, service responsibilities, selected connectors and the applicable commercial relationship.

Build the right package

Start with the customer responsibility model, then select only the products required to support it.

We will map the users, endpoints, websites, sources, targets, service coverage, connector model and provider relationship to the appropriate Guardian package and products.