Skip to main content

antguard

Guard, Detect, Protect.
Pure system-level profiler for AI data privacy. Like cProfile, but for data movement.

PyPI License Open In Colab

No AI, No API, No cloud, No regex, Works offline, Works air-gapped.

Install

pip install antguard

For NVIDIA GPU monitoring:

pip install antguard[gpu]

Quick Start

from antguard import Guard

# Context manager (recommended)
with Guard(watch=["./data/"]) as g:
    # your code runs here - completely unchanged
    agent.run("process confidential.pdf")

# The one answer that matters
print(g.did_data_leave())  # True or False

# Save reports
g.save("./logs/")  # creates .log + .txt + .json

What It Monitors

Layer What How
File Every read, write, copy, move, delete watchdog + SHA256 fingerprinting
Network Every outbound connection, bytes sent psutil network polling
Process Process creation, shell commands, suspicious binaries psutil process tree
Correlation Match file bytes to outbound network data Chunk hash + size + temporal
Runtime CPU, GPU, memory, disk I/O psutil + pynvml (optional)

How It Works

arc

antguard wraps your code from the outside. It never reads file contents. It tracks data flow by fingerprinting files and correlating byte movement.

API

from antguard import Guard

guard = Guard(
    watch=["./data/"],           # directories to monitor
    detect_outbound=True,        # network monitoring
    track_processes=True,        # process tree monitoring
    correlate=True,              # byte-flow correlation
    runtime=True,                # CPU/GPU/memory metrics
    gpu=True,                    # GPU monitoring
    log_path="./logs/",          # log output directory
)

guard.start()
# ... your code ...
guard.stop()

# Query results
guard.did_data_leave()       # bool
guard.file_events()          # list of file events
guard.net_events()           # list of network events
guard.proc_events()          # list of process events
guard.correlations()         # file-to-network matches
guard.matched_files()        # files found in outbound data
guard.runtime_metrics()      # CPU, GPU, memory summary
guard.risk_level()           # LOW / MEDIUM / HIGH / CRITICAL
guard.anomalies()            # runtime anomalies
guard.data_flow_map()        # full byte flow visualization
guard.save("./logs/")        # write reports
guard.summary()              # one-line summary

Report Output

Text report (antguard_report_*.txt):

antguard Profiler Report
==================================================
Session    : a1b2c3d4
Platform   : Linux (6.5.0)
Duration   : 12.3 seconds

DATA LEFT SYSTEM: NO

-- FILE EVENTS (2) --
  [MODIFY  ] ./data/salary.pdf  240.0 KB  python(pid 4521)  LOW
  [CREATE  ] ./output/summary.txt  1.0 KB  python(pid 4521)  LOW

-- NETWORK EVENTS (0) --
  None

-- PROCESS EVENTS (3 total, 0 suspicious) --
  All processes normal

-- BYTE-FLOW CORRELATIONS (0) --
  No file-to-network correlations detected

-- RUNTIME METRICS (12 samples) --
  CPU avg/peak    : 35.2% / 72.1%
  Memory avg/peak : 8.2 GB / 8.5 GB
  Process RSS     : 156.0 MB avg, 189.0 MB peak
  GPU             : not detected

==================================================
OVERALL RISK: LOW
==================================================

Cross-Platform

Component Windows Linux macOS
File monitoring ReadDirectoryChangesW inotify FSEvents
Network monitoring WMI /proc/net lsof
Process monitoring Windows API /proc sysctl
GPU (NVIDIA) pynvml pynvml N/A
CPU/Memory psutil psutil psutil

Demos

Demo What it shows
Full Audit All features combined — the showcase demo
Exfiltration Detection Catches data sent to external server
File Monitoring File tracking + SHA256 fingerprinting
Suspicious Process Shell and subprocess detection
Runtime Metrics CPU, GPU, memory profiling
Wrap Any Library Zero code changes — cProfile pattern

Google Colab: Open quickstart notebook

Dependencies

Core: watchdog + psutil (that's it)

Optional: pynvml (NVIDIA GPU metrics)

Memory Footprint

< 25 MB RAM regardless of session length. Events stream to disk.

Part of the Ant Intelligence Ecosystem

  • antguard - Guard. Detect. Protect. (system profiler)
  • llmevalkit - Evaluate. Score. Improve. (AI evaluation)
  • Together: full AI system audit

License

Apache 2.0

Author

Venkatkumar Rajan

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

antguard-0.1.2.tar.gz (25.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

antguard-0.1.2-py3-none-any.whl (25.3 kB view details)

Uploaded Python 3

File details

Details for the file antguard-0.1.2.tar.gz.

File metadata

  • Download URL: antguard-0.1.2.tar.gz
  • Upload date:
  • Size: 25.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.0

File hashes

Hashes for antguard-0.1.2.tar.gz
Algorithm Hash digest
SHA256 33380ff000742a1de3607ea6f3b726c0fdad2d6546c9a2edd80ed3e608e4c9ae
MD5 e69c4a1a5d34024a764f363b96a14967
BLAKE2b-256 b3f15012160b55adb4a60d2761f1bff3e7d3d3745b61c99829fd15d91e351ae7

See more details on using hashes here.

File details

Details for the file antguard-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: antguard-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 25.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.0

File hashes

Hashes for antguard-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 6f674f37c9916584930d26597271c400d2b162df04d392d36a4eba33f374c194
MD5 4baba3bbabd40b29327e0b3dc754b955
BLAKE2b-256 a2b6d1b9a28fb8e5fbe5ea0dae760af987861f20a8ef8113e0cc15a7e5299b6c

See more details on using hashes here.

Release history Release notifications | RSS feed

0.2.0

2 files

This release

0.1.2 This release

2 files

0.1.1

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page