Skip to main content
Every Panguard agent connects to the public Threat Cloud automatically. No configuration, no API key, no account required.

Default Connection

When you start Guard, it connects to tc.panguard.ai automatically:
That’s it. Your agent is now part of the collective intelligence network.

What Happens Automatically

Custom Endpoint

To point your agent at a different Threat Cloud instance:
Or set the environment variable:
Or in ~/.panguard/config.json:

Offline Mode

Guard works fully offline. If Threat Cloud is unreachable:
  • Bundled ATR rules (768) continue to function
  • Local AI (Ollama) handles analysis
  • Events queue locally and sync when connectivity returns
  • Protection never stops

Private Instances

For organizations requiring isolated infrastructure or data sovereignty compliance, private Threat Cloud instances are available as a managed service.

Contact for Private Instance

Organizations can deploy dedicated Threat Cloud infrastructure with custom feeds, retention policies, and network isolation.

Verify Connection

Check your agent’s Threat Cloud status:
Or view it in the dashboard at http://127.0.0.1:9100 (Threat Cloud page).