A correlated intrusion-detection system for the threats signature scanners miss.
Most security tools tell you what already happened. This one catches mass file-encryption while it's still happening, and shuts it down automatically. Ubwiru Privacy Agent watches for actual behavior — a ransomware attack encrypting your files right now, personal data already sitting exposed on your computer, a scam message built to manipulate you, or a new device quietly joining your home network. Related findings are automatically correlated into a single incident instead of a wall of separate alerts, and a behavioral baseline learns what's normal for your network so it can flag what isn't. One license, one unified detection system.
Ubwiru Privacy Agent is in open beta (Beta v0.1). The free 14-day trial doubles as beta testing — your feedback shapes what ships in the 1.0 release.
Detects the mass file-encryption pattern of an active attack and shuts it down automatically — no signature database to maintain.
Finds SSNs, card numbers, plaintext passwords, and API keys already sitting exposed on your computer — before someone else finds them first.
Related findings that share a device or timeframe are automatically grouped into one incident instead of scattering across separate, disconnected alerts.
A behavioral baseline flags genuinely new destinations and beaconing-style patterns — the kind of subtle signal a one-off scan would miss entirely.
Paste in a suspicious message for a plain-language breakdown of exactly why it's manipulative — not just a block/allow decision.
Plant deception files in sensitive-looking spots; any attempt to read one is a near-certain sign something is snooping where it shouldn't be.
See every device on your network laid out as a live topology graph, not just a list.
Every finding gives you two remediation options, per file — nothing happens automatically.
Any business or individual who wants protection that goes beyond what traditional antivirus catches — especially anyone handling sensitive customer or financial data on the same computer they use every day.
Runs entirely on your own computer — here's what that computer needs.
| Requirement | Minimum | Recommended |
|---|---|---|
| Windows | 10 (64-bit) | 11 |
| macOS | 12 | 14+ |
| Linux | Ubuntu 20.04 LTS, Debian 11, or equivalent (glibc 2.31+) | Ubuntu 22.04 LTS or newer |
| Memory (RAM) | 8 GB | 16 GB |
| Free Disk Space | 10 GB | 20 GB |
| Graphics Card (GPU) | Not required | Any dedicated GPU speeds up replies |
Python and the local AI engine are installed automatically during setup — nothing to install yourself. Internet is only needed during setup and updates; everything runs offline day to day.
Scanning and detection need no AI at all — a G-LOC G3 is plenty, and makes the optional "Explain this" feature feel instant too.
Quick Scan checks the common spots in minutes; Deep Scan covers your entire home folder.
Related alerts are grouped into one incident with a plain-language explanation — pull up Analyst Mode any time for the raw event data underneath.
Enable the ransomware watchdog, network baselining, and decoy files to stay protected around the clock.
Nothing is ever deleted or encrypted automatically — every remediation choice is made by you, per file
Detection is fully offline; the AI explanation features only ever talk to the model already running on your own computer
Deliberately narrow and honest about its limits — for example, the ransomware watchdog stops the spread the moment it fires, but doesn't recover files already encrypted before that point, and the decoy-file tripwire only catches an attempt to read the file, not every possible intrusion
It's a complementary layer, not a replacement — it's built to catch behavior-based threats (an active ransomware attack, already-exposed data, manipulative messages, anomalous network activity) that signature-based antivirus is not designed to catch.
No — every finding gives you two choices, shred or encrypt, and nothing happens until you pick one, per file.
SSNs, card numbers, plaintext passwords, and API keys already sitting exposed in files on your computer — the kind of thing an attacker would go looking for first.
It watches for the behavior itself — the mass file-encryption pattern of an active attack — and shuts it down automatically, with no signature database to keep updated.
Yes — every Ubwiru AI tool runs entirely on your own computer using local, open-source AI models. Nothing is sent to our servers or any third party.
A one-year license, activated on one computer. It briefly needs internet during setup to activate, then runs fully offline. Moving to a new computer is a quick email to hello@ubwiruai.com.
Explore the rest of the Ubwiru AI lineup, or talk to us about what fits your business.