Autonomous XDR · AI Detection & Response

The endpoint defends
itself now.

Tamandua is a self-hosted AutoXDR platform. An AI detection-and-response engine reasons over process, network, and identity signals on your Windows and Linux endpoints — then executes the response before an analyst opens the ticket.

Deploy agent Read whitepaper
Apache-2.0·Self-hosted by design·No vendor cloud
aidr://response-engine · live {{ autonomyLabel }}
INCIDENT #A7F2 · treasury-ws-04HIGH
Infostealer behavior — credential store access + outbound beacon to unrooted domain.
01 Observe · 214 events correlated ✓ done
02 Reason · AI triage · confidence 0.96 ✓ done
03 Act · isolate host + kill process {{ actState }}
04 Prove · sign evidence manifest queued
mean time to contain1.8s
AGENTS ONLINE
1,20499.7%
Built for operators who can't lose one laptop
ExchangesCustody desksMarket makersTreasury teamsValidatorsMSSPs
The AIDR loop

Detection and response that closes its own loop.

{{ loopIntro }}

{{ step.no }}
{{ step.title }}
{{ step.body }}
{{ gateNote }}
Network Insight
24h 7d 30d
AGENTS ONLINE
1,204
▲ 99.7% healthy
CONNECTIONS LIVE
38.2k
DNS + TLS metadata
AUTO-CONTAINED
7
no analyst wait
OPEN ALERTS
3
awaiting review
Detection coverage · MITRE ATT&CK12 tactics
{{ ta.id }}
Live response actions
Isolate host · treasury-ws-04auto
Block domain · c2-relay.xyzauto
Quarantine · stealer.binauto
Rotate keys · signer-02approve
How it works

Collect locally. Reason with AI. Respond from the endpoint.

{{ h.no }}
{{ h.title }}
{{ h.body }}
Evidence model

Three records an operator can inspect.

Every autonomous action is backed by evidence — not a black box. The AI shows its work.

{{ r.tag }}
{{ r.title }}
{{ r.body }}
RECORDED FIELDS
{{ f }}
Privacy model

Nothing sensitive ever leaves your servers.

Raw telemetry, hostnames, identities, and wallet addresses stay on infrastructure you control. Only bounded, non-reversible proof metadata can ever be published — and only when you enable it.

FIELDON-CHAINSELF-HOSTED
{{ p.field }} {{ p.chain }} {{ p.self }}
Who it protects

Operators that can't afford a single compromised laptop.

One infostealer on a treasury workstation rewrites your week. We assume the threat already touched the keyboard.

{{ a.title }}
{{ a.body }}
{{ a.tag }}
Optional proof layer

Verifiable attestation, when you want it.

Anchor a compact manifest hash to a public ledger so auditors and counterparties can confirm an incident existed, when it landed, and which manifest signed it — without ever seeing your telemetry. Solana is where this started; the proof layer stays optional and off by default.

{{ pp.title }}
{{ pp.body }}
Roadmap

Honest about where we are.

{{ rm.when }}
{{ rm.title }}
{{ rm.body }}
Open source

Public component mirrors, open for contribution.

Focused Apache-2.0 mirrors for the agent, server, and validation harnesses. Inspect the code, self-host the agent, and contribute through the community hub.

The endpoint is the perimeter now.

Inspect the code, self-host the agent, let the AIDR loop contain threats in seconds, and keep everything else on a need-to-know basis.

Deploy agent Browse public proofs