This page states the current validated baseline. A platform is not supported merely because Python or ODBC can run on it.
Guardian One host
| Validated OS | 64-bit Windows 10 Pro. |
|---|
| Other Windows | Windows 11 and Windows Server require release-specific validation before customer use. |
|---|
| CPU | Minimum 4 logical processors; recommended 4 or more physical cores. |
|---|
| Memory | Minimum 8 GB RAM; recommended 16 GB. |
|---|
| Disk | Minimum 5 GB free; recommended 10 GB plus separately sized evidence, report, log and backup retention. |
|---|
| Storage type | Local NTFS. SQLite must not be on a web root, file share, removable drive or synchronised user folder. |
|---|
| Browser | Current Microsoft Edge or Google Chrome. Internet Explorer is not supported. |
|---|
Required software
| Packaged release | Commercial releases require an approved, Authenticode-signed Guardian One package with its supplied runtime. Development builds are not customer releases. |
|---|
| Source demonstration | Authorised source evaluation uses 64-bit Python 3.14 and the exact validated versions in requirements-lock.txt. Build and test tooling is pinned separately. |
|---|
| ODBC | 64-bit Microsoft ODBC Driver 18 for SQL Server, named exactly ODBC Driver 18 for SQL Server. |
|---|
| PowerShell | Windows PowerShell 5.1 for current deployment and optional remote-Windows collection commands. |
|---|
Verify ODBC before installation:
Get-OdbcDriver -Name "ODBC Driver 18 for SQL Server" -Platform "64-bit"
SQL Server targets
| Versions | Collector compatibility is designed for SQL Server 2012 through SQL Server 2025 on Windows, with version-specific missing evidence reported as not assessed. This is not a commercial support statement. |
|---|
| Live validated build | Current live validation evidence covers SQL Server 2025 version 17.x, Developer Edition on Windows; every commercial support combination requires release-specific validation. |
|---|
| Initial database | tempdb. Repository creation uses master separately and deliberately. |
|---|
| Authentication | Windows integrated authentication. SQL usernames and passwords are not supported by the current release. |
|---|
| Not supported | Azure SQL Database, Azure Synapse, Fabric SQL Database and non-Windows targets for the current full machine-and-instance assessment. |
|---|
Network and ports
| SQL Server | Outbound TCP to each target’s configured SQL port. Do not assume TCP 1433 for named instances. |
|---|
| SQL Browser | UDP 1434 only when the customer deliberately uses instance discovery instead of a fixed port. |
|---|
| Optional WinRM | TCP 5985 for Kerberos-protected HTTP or TCP 5986 for approved HTTPS, restricted to the Guardian One host or management subnet. |
|---|
| Published website | TCP 443 to customer-managed IIS or reverse proxy. Port 8080 is a local development/demo binding and is not the production endpoint. |
|---|
| Infrastructure | Forward DNS, working domain trust/SPNs and time synchronisation where Kerberos is used. |
|---|
| Internet | Not required for installed assessment execution. |
|---|
Identity and permissions
Guardian One host
- Read/execute on application code; Read on configuration and licence files.
- Modify on protected repository, report and log directories.
- Log on as a batch job only for optional Task Scheduler use, or Log on as a service only for a service deployment.
SQL Server
- Windows login,
CONNECT SQL, appropriate metadata visibility and version-specific server-state permissions. - Approved version-specific log-reading permission for SQL Server and Agent summaries.
- No blanket
sysadmin grant solely for Guardian One.
Automatic Windows evidence (access permitting)
- Guardian One attempts bounded local or WinRM collection automatically and logs unavailable evidence without stopping the SQL assessment.
- Remote Management Users and Performance Monitor Users on approved remote targets.
- Read/Remote Enable access to
root\cimv2 where explicitly required. - No local Administrators or Domain Admins membership solely for collection.
Portable assessment limits
| Capacity | Five distinct canonical SQL Server identities for the lifetime of the SQLite database during evaluation. |
|---|
| Repeat assessments | No count limit for an already registered identity while the evaluation or signed subscription remains active. This is not unlimited product access. |
|---|
| Access and duration | Restricted by the fourteen-day evaluation period or signed subscription, enabled services, installation binding and approved Windows/SQL permissions. |
|---|
| Slot management | No supported delete, replacement, import, reassignment or reset function. |
|---|
| Data | Protected local GuardianOne_Portable.db; SQLite is not encrypted by Guardian One. |
|---|
| Licence | Valid signed, installation-bound Foundation or higher assessment entitlement. |
|---|
What the installation approval records
| Target scope | Up to five canonical SQL Server names, environment, business owner and DBA approval. |
|---|
| Service level | The Foundation, Advisor or Compliance capabilities enabled by the signed licence. |
|---|
| Collection identity | The exact Windows account and its approved SQL, filesystem and optional WinRM access. |
|---|
| Retention | How long SQLite, HTML, logs and backups are kept, who can access them and their review/destruction rule. |
|---|