It starts with a link you can't quite place.
A payment reminder from a sender you almost recognise. A shared file from a colleague who never shares files. You won't click it on your own machine, but you still need to know what it is.
Guard.ch opens links you do not trust in a browser in our cloud and shows you live what they really do. Close it, and that browser is destroyed. Your machine is never involved.
Here's the ideaOne sealed box in our cloud does the dangerous part. The only thing that ever leaves it is the picture on your screen.
Only a live picture of a faraway browser ever reaches your device. You click and type on that picture; the site's code never runs on your machine.
The link opens in a real browser inside that box: brand new for every investigation, destroyed when you leave. The site can probe all it wants; every attempt ends at the wall, and it sees Guard.ch's address, never you.
One suspicious email, one investigation, about a minute of your time.
A payment reminder from a sender you almost recognise. A shared file from a colleague who never shares files. You won't click it on your own machine, but you still need to know what it is.
Right-click the link and choose Open in Guard.ch, or paste it at guard.ch. Seconds later a brand-new browser runs live on your screen; your own computer is out of the story.
Before the page finishes loading, Guard.ch has pulled its records: who registered the domain, when, and the certificate it presents. A bank that is nine days old has told you plenty.
You click around like in any browser, just from a safe distance. Beside the page, every move appears as it happens: each server called, each cookie set, every quiet write.
More about the live viewWhen the page starts measuring the browser to recognise it later (the trick is called fingerprinting), Guard.ch flags it instantly and names the technique. Let it measure: that browser is gone in a minute.
One click captures a snapshot: the page as it looks, plus everything it just did. Take as many as you like; each lives at its own link, ready to hand to IT or the friend who almost clicked.
More about snapshotsThis is what a saved snapshot opens to: eight of its panels, annotated.
We check the site against the major popularity rankings: a name millions rely on stands apart from one nobody visits.
Every exchange between the page and its servers, kept in full: what it sent, and what came back.
Everything the page quietly saved, cookies and all, down to the exact values.
Is the site already known to be dangerous? We check the big scam and malware blocklists plus dozens of safety filters, and name every warning we find.
Who owns the domain and since when. A bank registered last week gives itself away right here.
Where the site really lives: whose servers answer for it, and from where in the world.
What the page is built with, each match backed by proof. A bank login on a free website builder tells you plenty.
The quiet tricks a page uses to identify your device, each named, with the exact call behind it.
And the grid keeps going: the full-page screenshot, the certificate it presented, every other server it quietly contacted, the permissions it asked for, the direct connections it opened, its console log, and the errors it never showed you.
An AI analyst reads the same signals and posts its verdict in plain language: safe, caution or risk, with the reasons, and the evidence one click away.
When something makes you curious, ask in your own words: who runs this site, why that redirect happened. Answers come back as saved cards with tables and sources; sensitive values are masked before anything reaches the model.
A verdict, you can check.
Most scanners hand you a colour and ask for trust. Guard.ch shows every signal behind its call: the decision stays yours.
Add a card to start, we will not charge it until the trial ends, and cancelling is just a few clicks away.