HOLGuard Desktop

Your command center for local AI protection.

Protect AI tools before they touch sensitive files, commands, credentials, packages, MCP servers, plugins, or skills. Review approvals and evidence in one native app. Guard Cloud remains optional.

HOL Guard Desktop

Overview

Guard Core is enforcing before supported AI actions execute. No action required.

Protected

Guard is active

Local policy · Core 3.x

Pending

0

No requests need review

Claude Code
Protected
Codex
Protected
Cursor
Protected
Gemini CLI
Protected
OpenCode
Protected
Guard CloudOptional · Not connected
Illustrative Guard Desktop layout. Core still makes every security decision.
Apple siliconmacOS 13+Windows x64Linux x86_64Local by default

Current release: 3.0.48

Use the command line

Review before execution, without living in a terminal.

Desktop is the control surface. Core makes every security decision. The native app asks the local runtime for a bounded status view and invokes only fixed supported actions. Desktop telemetry is off by default. Prompts, code, command text, file paths, receipts, policies, and secrets are not uploaded by the app. Guard Cloud is a separate, optional connection for teams that intentionally enable sync.

  • No Guard root credentials in browser JavaScript
  • No generic shell, filesystem, or network bridge
  • Fixed native commands with bounded output and timeouts
  • Unknown Core versions fail closed instead of showing protected
  • Cloud connection is optional and visually separate

Approvals

Claude Code · this machine
Needs review

pnpm deploy --workspace api --prod

Guard paused this action before execution. Approve, block, or scope it without exposing Guard credentials to the interface.

Requested by
Claude Code
Decision owner
You, on this Mac
BlockApprove
Illustrative approval. Prompts, paths, and secrets stay off the marketing page.

Every published installer should be independently verifiable.

Check the release checksum and macOS Developer ID signature before opening the app. Production installers are code-signed, notarized, checksum-published, and distributed with signed update metadata.