skip to content
Scan. Stop. Earn. · 0.9.0 · internal preview
how it handles what it sees

local first

Guardly only works if the thing being shared is the threat and not the person who met it. This page is the whole of what goes out, field by field.

01

Scanning runs locally first

The address and signature checks happen in the extension, on the page you are already looking at. A page that is obviously fine never leaves your device.

02

A signal is a fingerprint, not a visit

When something looks wrong, what goes out is the host, the contract address and the prompt shape. Not the tab, not the session, not who you are.

03

Rewards are counted without a profile

Signals are attributed to a rotating key you can reset. Resetting it keeps your pending balance and drops the link to everything before it.

04

You can read every signal you send

The outbox is a list in the extension. Nothing is sent that is not in it, and you can turn any category off.

one signal, in full

This is every field in a protection signal. There is no sixth field, and the extension shows you this list before it sends anything.

hostarb-claim-portal.appthe domain that produced the finding
contract0x4d2E…77aFthe address the approval points at
prompteth_signTypedData_v4 · permit2 · unlimitedthe shape of the request, not its contents
first seen2026-10-09the day, not the time, not the session
keyrotating, resettableso a run of signals cannot be joined into a profile

what never leaves your device

  • your full browsing history
  • your seed phrase or private keys, ever, for any reason
  • page contents from sites that scanned clean
  • a persistent identifier tied to your wallet
  • anything sold to advertisers

Guardly never asks for a seed phrase, a private key or a wallet connection. If anything calling itself Guardly ever does, it is not Guardly.

more questions?