PUBLIC DOCUMENTATION • EN

What CyberDefender is — and what it is not.

CyberDefender is a Security-First Autonomous XDR / Distributed Security Control System. Its design separates evidence and risk from authorization so that detection, AI or a high score cannot silently become unrestricted privileged action.

Current stage: commercial pilot / engineering validation. Public documentation intentionally separates current or verified behavior from planned target capabilities.

How CyberDefender can help users

VisibilityOrganize endpoint, process and network-related security signals so operators can understand what is happening.
Detection & correlationConnect separate signals into findings and incident context instead of treating each event in isolation.
Risk prioritizationHelp identify what deserves attention first without turning risk into permission.
Safer response designKeep high-impact response behind policy, Safety Core and independent verification boundaries.
ContinuityAim to preserve bounded local protection when cloud or central connectivity is unavailable.
Recovery evidencePreserve audit/recovery semantics and verify important post-action state on governed response paths.

How protection is designed

Telemetry → Trusted Admission → Detection → Correlation → Attack Graph / Context → Risk → Policy → Safety Core → Bounded Response → Independent Verification → Recovery / Audit.

  • Risk ≠ Authorization. High risk raises priority; it does not grant permission.
  • AI ≠ privileged authority. AI analyzes and recommends, but does not directly execute privileged OS actions.
  • Fail safely. Critical uncertainty should constrain or deny action rather than silently expand authority.
  • Offline does not mean unrestricted. Connectivity loss should not increase authority.

What CyberDefender does not promise

×
No “100% secure” guarantee. No product can guarantee prevention or detection of every zero-day, insider event, new attack or misconfiguration.
×
No hack-back. CyberDefender is defensive; it is not a retaliation system.
×
No blind AI execution. AI confidence or recommendation is not privileged permission.
×
No replacement for customer governance. Backups, patching, identity hygiene, authorization and incident-response procedures remain necessary.
×
No unearned compliance claims. Certifications are not claimed unless independently obtained.

Planned pilot scope

The planned pilot is observe-first: endpoint onboarding, telemetry and health validation, detection, correlation, risk, alerts and recommendations. Destructive autonomous actions are intentionally excluded from the initial commercial pilot.

Public AI Assistant boundary

The public assistant works in EN / UZ / RU. It cannot access Owner credentials, fleet tokens, private keys, endpoint command channels or private customer telemetry and does not execute OS commands.

Data & privacy

Public forms should contain only business contact and non-sensitive scope information. Do not submit passwords, tokens, private keys, customer secrets or sensitive incident evidence. Real pilot telemetry requires an explicit scope and data-handling agreement.

FAQ

Is CyberDefender an antivirus?

It is positioned as a Security-First XDR / distributed security control system rather than a simple consumer antivirus.

Does it automatically block everything suspicious?

No. Detection and risk are separated from authorization.

Can it work when cloud connectivity is unavailable?

The architecture is designed to preserve minimum local protection where technically possible and not increase authority merely because connectivity is lost.