Built for people who run Linux servers
Official advisories
Installed packages and the running kernel are checked against each distribution’s own security data: Ubuntu OVAL, the Debian Security Tracker, Red Hat OVAL and Amazon Linux ALAS.
More than packages
Optional checks verify system files against the package manager, look for malware and compromise indicators, review security configuration, and scan for malware with ClamAV, or ClamAV and YARA rules, which the installer sets up.
Agents with no open ports
Agents connect out to your server over HTTPS and trust only its certificate. Scanned machines need no inbound ports and no internet access.
Read-only and predictable
Every command a scan runs is a fixed, read-only string in DeaconGuard’s source. Scans never install software or change the system they check.
Honest results
A skipped, partial or failed check is never shown as clean, and missing advisory data is never reported as zero vulnerabilities.
Signed, self-hosted, open source
One Go binary under the MIT license. You run the server; your data stays with you. Every release is signed with Sigstore.
How it works
Install the server
One command installs the package, creates the first dashboard account and starts the HTTPS dashboard on port 8443.
Enroll machines
The dashboard gives you a one-line command with a single-use token. Run it on each machine to install and enroll the agent.
Scan and review
Start scans from the dashboard or the CLI. The server evaluates each machine’s packages against current advisories and keeps the history.
Supported distributions
Ubuntu 18.04 – 26.04 LTS · Debian 12 and 13 · Red Hat Enterprise Linux 8 and 9 · Amazon Linux 2023 — on amd64 and arm64.