GURDN

About

Why GURDN exists

Almost everything a machine does depends on a network it was told to trust. That layer is where GURDN works, and the reason it works there is that very little else does.

01Rules

The constraints the code is written under

Not aspirations. These decide what the product is allowed to say, and they are enforced by tests rather than by intention.

Never assert safety
The product may describe what it observed or could not observe. No message claims the user is secure, because no application can know that.
Unknown is real
A question GURDN could not answer is reported as unanswered, never folded into a healthy result to make a screen look calmer.
Verify by reading the machine
A call that returned success is not evidence. Every change is confirmed against the same source the product reports state from.
Ask before changing anything
Authorisation is a separate, recorded stage, never implied by a rule having fired.
Fail closed
Installation and configuration run as transactions that walk themselves back rather than leaving a machine in a state nobody chose.
Publish the limits
The limitations are specific, public and unsoftened. A boundary that is hidden cannot be assessed.

02State

Where the work is

GURDN version 0.2.0 is in release qualification.

The engine, the privileged service, the installer, the update verification and the release tooling are implemented and covered by automated tests, with no known product defects. What remains is validation on real Windows machines and release signing, both of which need environments the development machine does not provide. The product computes that verdict itself from recorded evidence rather than taking anyone's word for it.

Release status explains the difference between engineering complete, qualification complete, signed and released.

03Name

GURDN, for Guardian for Digital Networks

The short name is used everywhere in the product and the documentation. The expanded name is used where the shorter one needs explaining. There is no third variant: the application, the installer, this website and the documentation all use the same two.