Create your account
Open Create Account, enter your email and password, and verify the email using the code sent to your inbox. Registration is not complete until the verification code is accepted.
Practical playbook for the open-source edition: account + download, alert response, baselines, and troubleshooting. For architecture and model internals, use the technical reference.
If you only need the practical setup path, follow these five steps in order. This matches the current live website and desktop flow.
Open Create Account, enter your email and password, and verify the email using the code sent to your inbox. Registration is not complete until the verification code is accepted.
After verification, sign in and open Download or My Account. A free account is required to download the Windows installer from this site.
Use the download button to fetch the latest Windows installer (saved to your Downloads folder). Install it on each Windows device you want to monitor.
On first launch, follow the in-app setup: accept terms, confirm experimental posture, and let the elevated monitor start. No activation token is required in the open-source edition.
On a clean, stable machine, record per-app or whole-system baselines so Guardian can personalize local thresholds. See the Baselines section below.
The website handles registration, sign-in, password resets, and authenticated installer download. Core detection runs on-device under AGPL-3.0.
The Windows app is organized into main sidebar views. After first-run setup, the dashboard and alerts are available immediately — no subscription gate in the open-source edition.
Shows overall protection state, counts for Investigation Required and Action Required, Under Review summaries, and a tier-marked timeline for recent activity.
Shows actionable review lanes (user-installed and newly discovered executables), plus dedicated tabs for Windows OS, signed software, hardware processes, and background monitoring.
Deviation Tier 3 work that is not yet operational Tier 4: review evidence, use Suggested Actions on protected categories, and wait for corroboration before destructive steps.
Operational Tier 4 only: corroborated escalation that needs an immediate decision. Use Respond for guided steps and hand off to Windows Security — the OSS edition does not quarantine files.
Compares local snapshots of Defender, firewall, and related Windows settings against a reference you establish. Drift and unacknowledged incidents can surface review items.
Where you record trusted per-app or whole-system clean behavior so Guardian can personalize local thresholds on your PC.
Used for global sensitivity, monitor-only behavior, and other device-side operating preferences. Use Check for Updates to install the latest build from the same release channel as the website installer (no in-app browser checkout).
Guardian uses local anomaly scores to move activity through review tiers. Different process categories expose different actions so the app does not offer unsafe remediation for Windows or driver components.
A process has been flagged at least once, but not strongly enough to demand immediate action. Guardian keeps watching it quietly.
Suspicious behavior is becoming consistent. User-installed processes appear in actionable review lanes; protected system categories stay in their own tabs. You can Acknowledge to return a card to monitoring; it may re-escalate if activity continues.
Strong sustained deviation from baseline: a behavioral signal, not a final verdict. Work is routed to the Investigation Required sidebar view so you can review evidence before any destructive step.
Operational Tier 4 only: corroborated escalation (for example correlated secondary indicators or Defender-confirmed routing). Use Respond for step-by-step guidance.
Guardian ships with fixed ONNX models. Local recordings do not retrain model weights; they derive bounded local thresholds on your machine so Guardian can better separate trusted behavior from true anomalies.
Record a clean lifecycle for one trusted executable. This is the right tool when one app repeatedly raises false positives and you want Guardian to learn a tighter local envelope for that process on your PC.
Record a machine state you trust. This can expand process coverage and contribute clean behavioral windows for the slower machine-wide layer. Use it only on a clean, stable system state you actually trust.
If a trusted application changes meaningfully over time, recording again can improve local coverage. Guardian treats the resulting baseline information as additive local context rather than a model-weight change.
Useful when you want to observe without prompting response actions. Alerts still surface; you review conservatively before using Respond.
Most issues fall into a few predictable buckets: email delivery, download/sign-in, SmartScreen or Defender friction, or alert interpretation. Start with the simplest explanation first.
Check spam or filtered folders first. If the website flow says the request was accepted but the message never arrives, use the support form and include the email address you used.
Sign in on the website, open Download or My Account, and use the download button. If you are signed out, create a free account first — the download page will gate until you are authenticated.
If you still run a legacy commercial installer, you may see activation UI. Download the latest open-source build from Download to use the AGPL edition without subscription gates.
Open Information on the card first. If the process is trusted, Acknowledge can move it back to monitoring, and a clean baseline recording can make future evaluation more accurate on your PC.
Guardian is not yet code-signed with a publisher certificate, so Windows may flag the installer or monitor as unknown software. Download only from this website, use More info → Run anyway on SmartScreen if needed, and add a Defender exclusion for %LOCALAPPDATA%\AI Malware Guardian\ if the monitor is quarantined. You can submit a false-positive report to Microsoft if desired.
Elevated or automation-heavy workloads can surface Under Review or Investigation Required. Action Required stays corroboration-gated. Use Information and baseline recordings before taking remediation steps on trusted tools.
The detection engine runs on-device. Account and support actions use the website when you choose; Guardian does not depend on cloud-hosted behavior scoring for local evaluation.
Use the Support page for account, billing, setup, or technical issues. If the form is unavailable, the documented fallback path is support@aimalwareguardian.com.
In Settings → Check for Updates, install the latest build from the same channel as the website. If the monitor will not start after Defender quarantine, reinstall from your account download and re-activate if needed.