A Product of IES Solutions tech

What CyberGuardian actually is

One page with the whole product on it: what it is, how it works, what it detects, and where it stops.

Input formats
8
Threat categories
13
Languages
5

What CyberGuardian is

IES CyberGuardian App is a web tool by IES Solutions tech that analyses suspicious content and tells you, in plain language, whether it looks like fraud or a social engineering attempt, and what to do about it.

It is not an antivirus and not a blocker. You bring the content — a message, an email, a link, a phone number, an image, an audio file or a video — and you get back an explained assessment: a risk score from 0 to 100, a level (low up to 33, medium, high), a threat category, a confidence level, the red flags it found, concrete recommendations and technical notes written in vocabulary aligned with CompTIA Security+.

Around that there is a history with trends, a PDF report, automatic grouping by campaign, and a verifiable audit trail. It runs in five languages: English, Spanish, Portuguese, French and Arabic, with a right-to-left interface for Arabic.

How it works, in three steps

1

You bring the content

Paste the message, the email, the link or the phone number, or upload the image, the audio file or the video. Nothing to install, nothing to connect to your device.

2

The app analyses it

The content is normalised and run through the checklist built for its own format — what matters in an SMS is not what matters in a link or in an image — together with a hosted language model that answers in a fixed schema, so every analysis returns the same fields and can be compared with the next one.

3

You get something you can act on

A risk score, a level, a category, the red flags it found, recommended next steps and technical notes. It is saved to your history, grouped with other analyses that look like the same campaign, and written to the audit trail. Submitting the exact same content again returns the stored result and costs no points.

These three steps are the user-facing view of the five stages described on the methodology page — intake and normalisation, format checks, model evaluation, scoring and categorisation, delivery and recording. Same pipeline, shorter description. See the three steps

What it detects

Eight input formats, each with its own checklist, and thirteen result categories. What it looks for changes with the channel.

Image

Deepfakes · AI-generated images · Manipulated photos

Link

Phishing · Fake domains · Malicious sites

Email

Phishing · Spear phishing · CEO fraud

SMS

Smishing · Shortened links · Bank impersonation

Phone

Vishing · Caller ID spoofing · Phone scams

Audio

Voice cloning · Synthetic audio · Recorded vishing

Video

Video deepfakes · Fake ads featuring celebrities

Text

Online scams · Social engineering · AI-generated text

The thirteen categories it can return

Social EngineeringPhishingSpear PhishingSmishingVishingDeepfakeVoice CloningIdentity ImpersonationMalware / Malicious LinksFraudulent AdvertisingOnline ScamAI-Generated ContentNo Threat Detected

That "No Threat Detected" is a first-class category is deliberate. A tool that can only raise alarms is not useful; it has to be able to say that something is legitimate.

Privacy and limits

Privacy

  • The content you analyse is stored only in your own account history, and it is never used to train any model.
  • Campaign correlation stores one-way fingerprints only. The original senders, phone numbers and links are never kept as correlation data, and a fingerprint cannot be turned back into the value it came from.
  • Campaigns never cross accounts. Your analyses are only ever compared with your own analyses.
  • The audit trail records metadata, not content. When an account is created it records the email domain, not the address.
  • There is no third-party tracking and no advertising telemetry.

It does not work offline

Every analysis needs a connection. There is no on-device model and no local signature database.

It does not inspect your device

It does not read installed apps, permissions, processes or network traffic. It only sees what you paste or upload.

It does not block anything in real time

It does not intercept calls, messages or connections. You bring the content, it gives you an assessment.

It does not produce forensic evidence

The PDF report is a readable summary. It has no chain of custody, no timestamping by a third party and no signature that a court would accept as unaltered.

Its campaign grouping is a heuristic, not attribution

Grouping compares one-way fingerprints of senders, domains and wording inside your own account. It never crosses accounts, it does not tell you who is behind a campaign, and its accuracy was measured on a small internal set of 17 messages in 9 groups.

Its audit trail is not notarised

The hash chain shows that the entries it recorded were not altered afterwards, and the database refuses updates and deletes. It does not prove that every event was recorded, and no third party timestamps or notarises the chain.

The limit underneath all the others: this is a second opinion, not a verdict. A low score does not guarantee that something is safe, and the hard cases in the benchmark show exactly where it gets things wrong.

Try it on something you actually received

The fastest way to judge this product is to give it a message you are unsure about and read what it says back.