Remote endpoint visibility, monitoring and response.
Gjallarhorn gives security teams a live view of every endpoint they defend, raises the alarm when something changes, and lets analysts investigate and respond remotely, with every action approved by a person and recorded.
The platform
One platform from first signal to response.
Claude-enabledAnalysts work with Claude Code: they monitor endpoints in plain language, triage alerts with the evidence gathered for them, and respond with every change approved by a person.
Know what is running, everywhere
A lightweight agent on Windows and Linux reports processes, network connections, sign-ins and file integrity in near real time. Agents connect outbound only, so no inbound ports are opened on your endpoints.
Detect what matters
Detections built on the open Sigma standard, alongside service health checks and alerts when an endpoint goes silent. Your detection content stays portable and yours.
Act remotely, under control
Analysts investigate and contain threats with Claude Code, without logging in to each machine. Every change needs explicit human approval before it runs.
Who it is for
Built for teams accountable for every endpoint.
Security operations
Give analysts a single, scoped view of the endpoints they own, and managers a live picture of the whole estate.
Defence and government
Designed for dedicated deployment and a complete audit trail of who did what, where and when.
Enterprise
Monitor a mixed Windows and Linux estate and respond quickly, with roles and approvals that fit how your team already works.
Secure by Design
Controls you can explain to an auditor.
- Mutual TLS for every agentEach endpoint holds its own certificate, issued at enrolment and revocable at any time.
- Least-privilege rolesAdministrators, Managers and Analysts. Analysts reach only the endpoints allocated to them.
- Human approval for every changeRead-only investigation runs freely; anything that changes an endpoint waits for a person to approve it.
- Complete audit trailEvery action is logged with the user, endpoint, request, result and time.
- Dedicated deploymentDesigned to run as a dedicated instance in your own cloud account, so your telemetry stays in your environment.
- Proven under pressureBeing field-tested in live-fire cyber defence exercises from October 2026.
Talk to us about early access.
We are opening early access to a small number of security teams ahead of general availability.