Observer v1.0 is live — AI-powered log security, free during launch

Learn more
Security products for the moments modern tooling misses

Stop the exfiltration.
Catch the intrusion.

Modern defense fails in two places: nobody stops exfiltration early enough, and nobody explains noisy runtime behavior fast enough. VaultGuardian is building both halves of that answer.

9 daysChange Healthcare went undetected
6 TBExfiltrated from MGM before encryption
165Companies breached via Snowflake
$2.5BCost of one breach (UHG)
THE REAL THREAT

Encryption is the distraction. Data theft is the attack.

Our analysis of 8 high-profile breaches from 2023–2025 reveals a pattern the industry is ignoring: attackers exfiltrate first, encrypt second — if they encrypt at all.

Change HealthcareEXFIL → ENCRYPT
9 days undetected

6 TB exfiltrated. 192.7 million records. No MFA on the Citrix portal. Ransomware came after the data was already gone.

$2.5B total cost
MGM ResortsEXFIL → ENCRYPT
6 TB stolen in 3 days

A 10-minute phone call. Okta Super Admin. Data exfiltrated via Mega.nz and Dropbox before ransomware hit 100+ servers.

$100M total cost
Snowflake CampaignEXFIL ONLY
165 companies breached

Ticketmaster (560M records), AT&T (109M records), Santander. All from stolen credentials. No encryption deployed — pure data theft.

669M+ records stolen
MOVEit / Cl0pEXFIL ONLY
3,000+ organizations

58 million individuals affected. Zero-day SQL injection. No ransomware deployed. Pure exfiltration at industrial scale.

58M+ individuals exposed
Caesars EntertainmentEXFIL ONLY
65M loyalty records

Social engineering of an outsourced IT vendor. 20-day dwell time. Complete database stolen. No encryption. Paid $15M ransom for data alone.

$15M ransom paid
Microsoft / Midnight BlizzardEXFIL ONLY
7 weeks undetected

Russian SVR compromised a test tenant, pivoted to production via OAuth, read senior leadership email for 7 weeks. No encryption. Pure espionage.

Source code accessed

In the 8 breach case studies highlighted here, only 2 involved encryption.

In every case, exfiltration happened first or was the entire attack. Detection came from manual investigation, outside reporting, or the attack itself — not automated tooling.

THE DETECTION GAP

When did they find out?

Real detection times from real breaches. None were caught by automated security tooling.

Salt Typhoon
3+ years
Microsoft
7 weeks
Caesars
20 days
Okta
20 days
Change Healthcare
9 days
MGM Resorts
3 days
DEC-1Milliseconds

Severs the connection at the moment of exfiltration

ObserverSeconds

Classifies the intrusion attempt and verifies the outcome

DEFENSE IN DEPTH

Three layers. Three different threats.

No single product stops everything. Your infrastructure needs defense at every layer — behavior, egress, and persistence.

AGAINST ABNORMAL BEHAVIOR

Observer

Watches every log line. Classifies suspicious behavior using AI. Captures evidence of what the server actually returned. Catches the intrusion attempt before it becomes exfiltration.

Private beta
AGAINST EXFILTRATION

VaultDEC-1

Deterministic egress enforcement at the network level. If an attacker tries to upload your data, the connection is severed in milliseconds. The kill event doubles as instant breach detection.

Pre-order open
AGAINST ENCRYPTION

Immutable Snapshots

ZFS, btrfs, or WORM storage. If an attacker encrypts your files, yesterday's snapshot is untouched. Well-understood and widely deployed. You probably already have this.

Many solutions exist
USE CASES

Where data loss is not an option

Backup Infrastructure

Protect NAS, SAN, and dedicated backup servers. Snapshots protect against encryption. DEC-1 protects against exfiltration. Observer catches the intrusion that triggered it.

Docker / Container Hosts

Observer watches every container's stdout/stderr without agents or sidecars. Classifies threats, captures evidence, learns what's normal for your deployment.

Healthcare & Compliance

Change Healthcare lost 192.7M patient records. Hardware-enforced egress control with auditable logs. Observer adds evidence-backed alerting for compliance documentation.

START WITH THE LAYER YOU NEED

Protect your infrastructure

DEC-1 for egress enforcement. Observer for log intelligence. Or both — they're designed to work together.

$349

DEC-1 hardware, one-time

Pre-Order
$29/mo

Observer Pro, unlimited servers

Coming Soon
Compare all plans →