On-prem security appliance · agents inside

Security that doesn't wait to be told.

NK Node is a security appliance with an agent swarm inside. It sweeps your network, proves which findings are real, and answers questions about your environment in plain English. It runs on a box you own, against a model that stays local.

Local model
Read-only by default
Every action audited
The name

Named after the cell that doesn't need a briefing.

Natural killer cells are your immune system's first responders. They don't wait for a signature or a previous infection. They notice something is wrong, make contact, and end it.

That is the job description we wrote for NK Node. Most security tooling assumes a SOC, a budget line and a spare year. If you are the IT department, NK Node is the analyst who takes the night shift and shows their work in the morning.

How it works

Here's what it does while you're asleep.

It starts by walking the network and writing down every machine that answers, and what each one is running. Then it checks that list against the public vulnerability database.

This is where most scanners stop and hand you a few hundred rows. NK Node keeps going. It tests each finding to see whether it's real. The ones that hold up get reported. The ones it couldn't settle are flagged for a person. The false alarms are thrown out, and you never see them.

Along the way it notices which machines everything else leans on, by watching who talks to whom. Those go to the top of the list.

By morning there's a report on the box. It's short, it's written for a person, and it says what to fix first and why.

Morning reportSAMPLE · FICTIONAL SITE

3 things need you. 26 didn't.

Larkspur Dental · 23 hosts checked overnight

Critical
Install the missing Windows update on the file share.Confirmed. 19 other machines depend on it and it holds patient records.
High
Update OpenSSH on the practice-management server.Confirmed. A fix has been available since July 2024.
High
Change the admin password on the front-desk printer.Confirmed. It's still the factory default.

One more finding is waiting on a human look. 26 others were tested and dropped as false alarms.

Autonomy

You set the leash.

An agent is only useful if it has exactly as much authority as you decided to give it. NK Node ships read-only. Changing that takes a typed confirmation, and the change itself goes in the audit log.

Run viewer · threat huntSAMPLE RUN

        
      
Ask

Ask your network a question.

The Ask console is a local model with four read-only tools and nothing else. This demo runs on a made-up dental office, so go ahead and poke at it.

Environment Q&ASCRIPTED DEMO · FICTIONAL DATA
Security first, then AI

We did the boring parts first.

We are security engineers who build with AI, in that order. An agent on your network is an attack surface before it is a feature, so this is what it is built on.

The model stays home
Ask runs against a local model endpoint on your own hardware. Questions about your environment are answered where your environment lives.
Read-only at the connection
The model's tools open the databases read-only. A prompt injection can't write, because the connection can't.
An audit log you can't edit
Every proposal, approval, rejection and execution is an immutable row. So is every login, and every change to the autonomy level.
A two-item allowlist
Even in autonomous mode, agents can do two things: isolate a host and block an IP. Each one records before-and-after evidence.
No false-positive theatre
Findings that fail validation are never shown. A shorter list you can trust beats a longer one you learn to ignore.
Unglamorous auth, done properly
Hashed passwords, rate-limited logins and sessions that expire after 12 hours.
Deploy

One box. One command.

NK Node installs on a Mac mini that sits on your network. The installer is safe to re-run, has a dry-run mode that prints every action without taking it, and starts everything on boot.

WAZUH AGENTSNVD 2.0ROUTER LOGSPDF + MARKDOWN REPORTS
TerminalmacOS
$ ./install.sh --dry-run   # print every action, change nothing
$ ./install.sh
ok  prerequisites checked
ok  backend environment created
ok  console built
ok  TLS certificate generated
ok  services installed, start on boot
--  console ready on your network
!!  change the default password before you do anything else
A Tech Guard product

Put a first responder on your network.

NK Node is built and run by Tech Guard, a managed security firm in Virginia. Tell us about your network and we'll show you what it finds.

Email Tech Guard info@techguard.io