Controller
- Controller ID
- Fingerprint
Create short-lived, signed approvals for a Guardian-protected PC. Everything happens on this device; no account, cloud, or network is required.
The encrypted controller bundle is opened only while signing. The decrypted key and passphrase are never saved.
Load the encrypted bundle your family already uses, or create one once and back it up carefully.
Choose the private .guardian-controller.json file. Loading it does not decrypt the signing key.
Import the public device identity exported by the enrolled Windows PC. It contains no private key or password.
An approval works once, on one Guardian PC, for one exact action, during the short period you choose.
Load the encrypted controller bundle and select an enrolled Guardian device.
Guardian Controller is intentionally small, offline, and explicit. Its job is authorization—not surveillance.
No Guardian server exists in this app. A strict content-security policy blocks network requests, analytics, advertising, and remote code.
If every encrypted controller-bundle backup or its passphrase is lost while a PC remains in managed mode, this app cannot manufacture a replacement approval. Test your backups before enrollment.