A Product of IES Solutions tech
What CyberGuardian actually is
One page with the whole product on it: what it is, how it works, what it detects, and where it stops.
- Input formats
- 8
- Threat categories
- 13
- Languages
- 5
What CyberGuardian is
IES CyberGuardian App is a web tool by IES Solutions tech that analyses suspicious content and tells you, in plain language, whether it looks like fraud or a social engineering attempt, and what to do about it.
It is not an antivirus and not a blocker. You bring the content — a message, an email, a link, a phone number, an image, an audio file or a video — and you get back an explained assessment: a risk score from 0 to 100, a level (low up to 33, medium, high), a threat category, a confidence level, the red flags it found, concrete recommendations and technical notes written in vocabulary aligned with CompTIA Security+.
Around that there is a history with trends, a PDF report, automatic grouping by campaign, and a verifiable audit trail. It runs in five languages: English, Spanish, Portuguese, French and Arabic, with a right-to-left interface for Arabic.
How it works, in three steps
You bring the content
Paste the message, the email, the link or the phone number, or upload the image, the audio file or the video. Nothing to install, nothing to connect to your device.
The app analyses it
The content is normalised and run through the checklist built for its own format — what matters in an SMS is not what matters in a link or in an image — together with a hosted language model that answers in a fixed schema, so every analysis returns the same fields and can be compared with the next one.
You get something you can act on
A risk score, a level, a category, the red flags it found, recommended next steps and technical notes. It is saved to your history, grouped with other analyses that look like the same campaign, and written to the audit trail. Submitting the exact same content again returns the stored result and costs no points.
These three steps are the user-facing view of the five stages described on the methodology page — intake and normalisation, format checks, model evaluation, scoring and categorisation, delivery and recording. Same pipeline, shorter description. See the three steps
What it detects
Eight input formats, each with its own checklist, and thirteen result categories. What it looks for changes with the channel.
Image
Deepfakes · AI-generated images · Manipulated photos
Link
Phishing · Fake domains · Malicious sites
Phishing · Spear phishing · CEO fraud
SMS
Smishing · Shortened links · Bank impersonation
Phone
Vishing · Caller ID spoofing · Phone scams
Audio
Voice cloning · Synthetic audio · Recorded vishing
Video
Video deepfakes · Fake ads featuring celebrities
Text
Online scams · Social engineering · AI-generated text
The thirteen categories it can return
That "No Threat Detected" is a first-class category is deliberate. A tool that can only raise alarms is not useful; it has to be able to say that something is legitimate.
See it running
These are links into the live product, not mockups or marketing renders. Open any of them and you are looking at the real screen, with real data from your own account.
Privacy and limits
Privacy
- The content you analyse is stored only in your own account history, and it is never used to train any model.
- Campaign correlation stores one-way fingerprints only. The original senders, phone numbers and links are never kept as correlation data, and a fingerprint cannot be turned back into the value it came from.
- Campaigns never cross accounts. Your analyses are only ever compared with your own analyses.
- The audit trail records metadata, not content. When an account is created it records the email domain, not the address.
- There is no third-party tracking and no advertising telemetry.
It does not work offline
Every analysis needs a connection. There is no on-device model and no local signature database.
It does not inspect your device
It does not read installed apps, permissions, processes or network traffic. It only sees what you paste or upload.
It does not block anything in real time
It does not intercept calls, messages or connections. You bring the content, it gives you an assessment.
It does not produce forensic evidence
The PDF report is a readable summary. It has no chain of custody, no timestamping by a third party and no signature that a court would accept as unaltered.
Its campaign grouping is a heuristic, not attribution
Grouping compares one-way fingerprints of senders, domains and wording inside your own account. It never crosses accounts, it does not tell you who is behind a campaign, and its accuracy was measured on a small internal set of 17 messages in 9 groups.
Its audit trail is not notarised
The hash chain shows that the entries it recorded were not altered afterwards, and the database refuses updates and deletes. It does not prove that every event was recorded, and no third party timestamps or notarises the chain.
The limit underneath all the others: this is a second opinion, not a verdict. A low score does not guarantee that something is safe, and the hard cases in the benchmark show exactly where it gets things wrong.
Try it on something you actually received
The fastest way to judge this product is to give it a message you are unsure about and read what it says back.