Guardian One documentation

System requirements

Current requirements for the five-instance Portable Demo release.

Development baseline reviewed: 4 August 2026

This page states the current validated baseline. A platform is not supported merely because Python or ODBC can run on it.

Guardian One host

Validated OS64-bit Windows 10 Pro.
Other WindowsWindows 11 and Windows Server require release-specific validation before customer use.
CPUMinimum 4 logical processors; recommended 4 or more physical cores.
MemoryMinimum 8 GB RAM; recommended 16 GB.
DiskMinimum 5 GB free; recommended 10 GB plus separately sized evidence, report, log and backup retention.
Storage typeLocal NTFS. SQLite must not be on a web root, file share, removable drive or synchronised user folder.
BrowserCurrent Microsoft Edge or Google Chrome. Internet Explorer is not supported.

Required software

Packaged releaseCommercial releases require an approved, Authenticode-signed Guardian One package with its supplied runtime. Development builds are not customer releases.
Source demonstrationAuthorised source evaluation uses 64-bit Python 3.14 and the exact validated versions in requirements-lock.txt. Build and test tooling is pinned separately.
ODBC64-bit Microsoft ODBC Driver 18 for SQL Server, named exactly ODBC Driver 18 for SQL Server.
PowerShellWindows PowerShell 5.1 for current deployment and optional remote-Windows collection commands.

Verify ODBC before installation:

Get-OdbcDriver -Name "ODBC Driver 18 for SQL Server" -Platform "64-bit"

SQL Server targets

VersionsCollector compatibility is designed for SQL Server 2012 through SQL Server 2025 on Windows, with version-specific missing evidence reported as not assessed. This is not a commercial support statement.
Live validated buildCurrent live validation evidence covers SQL Server 2025 version 17.x, Developer Edition on Windows; every commercial support combination requires release-specific validation.
Initial databasetempdb. Repository creation uses master separately and deliberately.
AuthenticationWindows integrated authentication. SQL usernames and passwords are not supported by the current release.
Not supportedAzure SQL Database, Azure Synapse, Fabric SQL Database and non-Windows targets for the current full machine-and-instance assessment.

Network and ports

SQL ServerOutbound TCP to each target’s configured SQL port. Do not assume TCP 1433 for named instances.
SQL BrowserUDP 1434 only when the customer deliberately uses instance discovery instead of a fixed port.
Optional WinRMTCP 5985 for Kerberos-protected HTTP or TCP 5986 for approved HTTPS, restricted to the Guardian One host or management subnet.
Published websiteTCP 443 to customer-managed IIS or reverse proxy. Port 8080 is a local development/demo binding and is not the production endpoint.
InfrastructureForward DNS, working domain trust/SPNs and time synchronisation where Kerberos is used.
InternetNot required for installed assessment execution.

Identity and permissions

Guardian One host

  • Read/execute on application code; Read on configuration and licence files.
  • Modify on protected repository, report and log directories.
  • Log on as a batch job only for optional Task Scheduler use, or Log on as a service only for a service deployment.

SQL Server

  • Windows login, CONNECT SQL, appropriate metadata visibility and version-specific server-state permissions.
  • Approved version-specific log-reading permission for SQL Server and Agent summaries.
  • No blanket sysadmin grant solely for Guardian One.

Automatic Windows evidence (access permitting)

  • Guardian One attempts bounded local or WinRM collection automatically and logs unavailable evidence without stopping the SQL assessment.
  • Remote Management Users and Performance Monitor Users on approved remote targets.
  • Read/Remote Enable access to root\cimv2 where explicitly required.
  • No local Administrators or Domain Admins membership solely for collection.

Portable assessment limits

CapacityFive distinct canonical SQL Server identities for the lifetime of the SQLite database during evaluation.
Repeat assessmentsNo count limit for an already registered identity while the evaluation or signed subscription remains active. This is not unlimited product access.
Access and durationRestricted by the fourteen-day evaluation period or signed subscription, enabled services, installation binding and approved Windows/SQL permissions.
Slot managementNo supported delete, replacement, import, reassignment or reset function.
DataProtected local GuardianOne_Portable.db; SQLite is not encrypted by Guardian One.
LicenceValid signed, installation-bound Foundation or higher assessment entitlement.

What the installation approval records

Target scopeUp to five canonical SQL Server names, environment, business owner and DBA approval.
Service levelThe Foundation, Advisor or Compliance capabilities enabled by the signed licence.
Collection identityThe exact Windows account and its approved SQL, filesystem and optional WinRM access.
RetentionHow long SQLite, HTML, logs and backups are kept, who can access them and their review/destruction rule.