Skip to main content
Threat Cloud is Panguard’s collective defense network. Every blocked threat becomes a new rule. Every rule is shared anonymously. Every user strengthens the network.

Architecture

Skill Audit → Threat Report → Community Vote → LLM Review → ATR Rule → Guard Sync

Key Features

Anonymous Sharing

Only SHA-256 hashes and risk scores are shared. No skill content or user data leaves your machine.

Community Voting

Users confirm or reject threat reports through feedback, building consensus.

LLM Review

Claude Sonnet reviews proposed rules for accuracy before promotion.

Real-time Feeds

IP blocklist, domain blocklist, and ATR rules updated continuously.

API Endpoints

EndpointMethodDescription
/api/statsGETThreat intelligence statistics
/api/rulesGETBrowse all community rules
/api/atr-rulesGETFetch confirmed ATR rules
/api/skill-threatsPOSTSubmit skill audit results
/api/feeds/ip-blocklistGETIP blocklist feed
/api/feeds/domain-blocklistGETDomain blocklist feed

Deployment Guide

Deploy your own Threat Cloud instance.

Privacy

How we protect your data.