A browser your team can point at anything.

Guard.ch gives everyone on your team a real browser that runs in our cloud instead of on their machine. Open what you would rather not open locally, watch what the page actually does while it loads, and hand the same browser to your agent when you want the clicking done for you.

A real browser, somewhere else.

Every session starts a real browser in a throwaway container in our cloud and streams it into your tab. Real tabs, real typing, real sign-ins when a page insists on one. Eight browsers to pick from: Chrome, Chromium, Brave, Edge, Opera, Vivaldi, Firefox and Tor.

Your side

A live picture of a browser that is not yours, and your clicks going back the other way. Nothing the page ships executes on your endpoint, and nothing it drops touches your network.

Our side

A fresh container per session, torn down when you leave. No profile, no history, nothing to correlate. The site can probe as hard as it likes: it reaches our egress, never your address.

Your team's side

Everyone works in their own session inside the same workspace: the same browsers, the same exit locations, the same rules, on a managed laptop or on a phone in a corridor.

Egress on your terms.

Choose where the traffic comes out. A country and city catalog of exit locations covers most work. When a site behaves differently for datacenter ranges, switch to residential egress; every plan comes with an allowance for it.

Workspaces can bring their own WireGuard exit profiles instead, in fallback mode or a strict mode that hard-denies rather than quietly leaking out of the wrong door. Switching exits mid-investigation takes a click.

Evidence you can point at.

Turn the analysis lane on and Guard.ch reads the page beside you: what the container observed while it ran, plus the look-ups you asked for. It runs on the Chromium browsers (Chrome, Chromium, Brave, Edge, Opera, Vivaldi); Firefox and Tor are for browsing only. Switch it off mid-session and you are back to a plain browser.

Registration

Registry data over RDAP, falling back to WHOIS, punycode-safe so an IDN returns real records. Registrar, creation date, nameservers. A domain nine days old that presents itself as a bank has already told you something.

Hosting

The address that actually answers, its ASN and network owner, and where it sits. Rank, age and certificate facts describe the registrable domain; anything deeper is verified on its own.

Certificate

The leaf presented on the wire, its issuer and validity window, checked against the CA ecosystem's own database. Subject and SAN coverage compared with the address bar, not inferred from a padlock.

Reputation

The hostname put to authoritative malware and phishing feeds, national CERT feeds, independent DNS security filters and community report feeds, alongside a domain popularity ranking. Every hit is reported with the kind of source it came from.

Technology fingerprint

What the page is really built on, each match carrying the evidence that produced it. A bank sign-in served off a free site builder is a finding, not a footnote.

Network and storage

Every request and response, every third-party host contacted, every cookie and storage write with its actual value, and the full redirect chain end to end.

Tracking and probes

Tracking services and third-party domains are classified from the requests the page makes, with the responsible organisations and categories shown clearly.

What it hid

Console output, thrown exceptions, WebSocket traffic and coercive dialogs. The part of the page a visitor never sees is usually the part worth reading.

None of it is recorded. The evidence lives in the running session and is gone when the session ends: no report to file, no archive to defend. What leaves with you is what you copied out and what you now know.

A floor you can reason about.

A deterministic rules engine computes the minimum severity from concrete signals. The AI read runs on top of that floor and can raise it. It can never lower it, and when the evidence does not support a call, the result says so instead of guessing.

Feeds weighted by authority

A hit on an authoritative malware or phishing feed hard-floors the verdict on that exact hostname. Community and report-grade feeds are weighted down on established domains, where popularity rank and age make a false positive the likelier reading.

Independent filters have to agree

Blocked by two or more independent DNS security filters floors the verdict at risk. Exactly one floors it at caution, because one filter disagreeing with the rest is a data point, not a conclusion.

The exact hostname, nothing broader

The verdict describes the host you submitted. Findings on sibling subdomains are shown separately with their provenance, so a compromised neighbour never quietly condemns the host you asked about.

Impersonation without a brand list

No list of protected brands exists to fall out of date. The read works out which service the page claims to be from its own content, confirms the real sign-in domain by live search, and flags the mismatch. Structural checks run beside it: where the login form posts, which domains serve the assets, whether the certificate subject matches the address.

Credential and payment risk

A password collected over plain HTTP floors at risk. So does a cross-origin credential post from a fresh domain; from an established one it floors at caution. Downloads that start themselves, OAuth consent with a redirect target that does not match, and cross-domain redirect chains each carry their own weight.

New domains count, never alone

A registration a few weeks old raises caution when at least one other tell agrees with it. On its own it proves nothing, and the engine will not pretend it does.

An analyst that shows its work.

Once the page has settled, a bounded, tool-using agent goes back over the same evidence: it reads the page, looks at the screenshot, pulls domain records and searches the open web. What comes back is structured, not a paragraph of vibes: a headline, a tone, the facts it relied on, the signals that moved it, what to do next, and its sources, cited.

Ask it questions too, in your own words or from presets. Who operates this, why did that redirect fire, is that the real sign-in domain. It answers from evidence already on hand and only escalates to tool calls when something is genuinely unresolved, and it reports cross-references by the count: how many independent sources mention the exact domain, and whether they are news, court and regulator records, forums or review sites.

Give your agent a browser.

Point Claude Code, Claude Desktop, Cursor, VS Code, Codex CLI, Gemini CLI, Windsurf or anything else that speaks MCP at api.guard.ch/mcp with an app key. It gets 35 browser tools driving real cloud browsers. Nothing is installed on your machine, and nothing runs there.

Sessions it opens itself

Start, list and close browser sessions on any of the Chromium images, up to three side by side, and pick the exit location the same way a person would.

Hands on the page

Navigate, click, type, fill and submit forms, scroll, hover, drag, upload a file, answer a dialog, go back and forward, and work across several tabs.

Eyes on the page

Screenshots of the viewport or of one element, the page as structured text, console output and the network log, and downloads it triggered. When nothing else will do, it runs JavaScript in the page.

Told in plain words

Act and extract take an instruction in ordinary language: accept the cookie banner, pull every price off this list. The agent keeps the intent, the browser does the mechanical part.

Sees for itself

It reads its own sessions directly: every request and response, console output, the page as structured text, screenshots and its own JavaScript. If someone starts an investigation in the app and hands it over, the agent can switch that session's analysis lane on or off, and the owner watches the findings in the live view.

You keep the keys

Every call carries an app key from your account in a header. Revoke it and the agent stops. Open the running session in your own browser to watch what it is doing, and end it whenever you like.

Prefer your own code? The same sessions answer to a REST API and to CDP, so Playwright or Puppeteer can connect straight to the browser and keep the rest of your pipeline unchanged.

Built for a team, not a login.

A workspace holds the seats, the sign-in and the rules. One seat belongs to one person: give someone a seat and they have the whole product from their first session, take it back and they do not.

  • Seats and members

    Buy the seats you need and hand them out from the workspace. A member holds one seat, a manager can move a seat to someone else, and a workspace never ends up without a manager.

  • Microsoft Entra SSO

    A guided per-workspace wizard with encrypted secrets, a live connection test that names the actual error instead of failing silently, optional auto-provisioning and a domain hint.

  • Tenant auto-join

    A manager can claim a tenant they have proven they control. After that, sign-ins from that tenant land in the workspace on their own. Off by default, and one tenant maps to exactly one workspace.

  • Managed rollout

    Force-install the browser extension through Google Admin, GPO, Intune or a managed policy file, locked to your workspace so a launch cannot end up in a personal account.

  • Sign-in that fits

    Email-first authentication that resolves to a password, a passkey, a magic link or your SSO on its own. Google and Microsoft OAuth as well.

  • Your name on it

    Rename the workspace and put your own logo on it, so your people can see whose workspace they are signing in to.

Single sign-on, tenant auto-join and workspace branding come with the Team plan. Residential data and the AI analyst's budget are pooled across the workspace, so a quiet week for one member is headroom for another. Data lives in an EU datacenter in Helsinki; edge nodes persist nothing. A DPA and the subprocessor list are self-serve. SOC 2 and ISO 27001 are on the roadmap and not yet attested, and we would rather write that down than let you assume otherwise.

Someone still has to open it.

The link will not vet itself, and not clicking is rarely an option. Guard.ch makes opening it a cheap, disposable act: a browser that is not yours, a running account of what the page did while you were there, and an agent to do the clicking when you would rather not.

Everything, free for 30 days.

Nothing is held back. A card is attached up front and charged nothing until the trial ends.

Start 30-day trial