Our Approach
We removed the attack path instead of getting better at spotting it. This page is the argument for that decision, and what it means for a deployment on your estate.

Enforcement at Ring 0
Policy applied before an instruction is permitted to run
The argument
Why we build the boundary.
Most of the industry is trying to raise a detection rate. We think that is the wrong number to be optimising, and the reasoning is short enough to check.
Detection needs a prior
A signature engine has to have seen something like the attack before. A behavioural model has to have been trained on something like it. Both are asking the same question — does this resemble a thing we already know? — and a genuinely novel intrusion is defined by the answer being no.
A boundary does not
An exploit nobody has published still cannot reach a kernel it has no route to. Each process runs inside its own virtualised environment, enforced at ring 0, so a compromise stays inside the box it started in. The boundary does not need to recognise what it is holding back.
Built where it runs
The engine, the telemetry pipeline and the Argon hosting layer are built and operated in India. For government and defence work we will run entirely on your hardware instead, with no telemetry leaving your jurisdiction and no foreign vendor in the trust chain.
In practice
How a deployment actually goes.
Enforcement that breaks a payroll system gets switched off by Friday, so the sequence matters more than the engine.
We look at what you run
Before anything is installed we go through the estate with you — what is on it, what cannot be patched, what nobody is allowed to restart. The systems people are nervous about are usually the ones worth enforcing around first.
Enforcement goes on in observe mode
The driver is installed and reports what it would have blocked, without blocking it. This is the part that tells you whether a policy is going to break a line-of-business application, and it is cheaper to learn here than in production.
Prevention is switched on, in stages
Enforcement is turned up per group rather than per fleet. Where a rule is refused, the device records why — so a policy that is not actually in force shows up as a finding rather than as a silent assumption.
You audit containment instead of triaging alerts
Once the boundary holds, the daily work changes shape. There is a log of what was contained and what was refused, and reading it is a different job from working an alert queue.
Limits
What this does not do.
Worth reading before a trial, because these are the questions that otherwise surface in month three.
Process isolation stops code from reaching what it has no route to. It does not stop a user typing their password into a convincing page — that is what the browser layer and credential monitoring are for.
A device that has stopped checking in is not the same as a device that is protected. Until it reports, we say we cannot tell the difference rather than showing you a green tick.
Absence from a threat blocklist is not an assertion that something is safe. It means nobody has listed it yet, and we report it that way.
An agent running a version that predates a reporting feature says nothing either way about that feature. We would rather show a gap than infer a result.
Bring us the environment that worries you.
Tell us what you run and which part of it you would rather not think about. We will show you where the enforcement points land and what the first ninety days look like.