WORM-INTEGRATED ENDPOINT SECURITY
Security on the endpoint. Recovery beyond its reach.
Arivaran Aran is designed to unify endpoint protection with remote, WORM-protected recovery in one agent, one console, and one vendor—from detection and containment through recovery. Current evidence is audit-oriented; containment, enforcement, and recovery choreography remain planned. WORM protection requires the supported S3 adapter with Object Lock enabled; unsupported backends fail closed.
Detect. Contain. Recover. One platform.
Arivaran Aran protection
Setup neededThe diagram shows the mechanism, its current result, and the limit that remains in force.
Step 1 of 3Detect and record a local decision
Deterministic checks produce a disposition and policy action; the endpoint records the result under the current audit-oriented boundary.
Step 2 of 3Contain and recover — planned choreography
The approved future path coordinates containment with recovery in one platform; current runtime evidence does not make that an available outcome.
Step 3 of 3Evidence boundary
Unknown defaults to AllowWithAlert, not fail-closed block. Coordinated protection and recovery remain planned. WORM applies only to the supported S3 adapter with Object Lock explicitly enabled; other backends fail closed.
Mechanism
Deterministic checks produce a disposition and policy action; the endpoint records the result under the current audit-oriented boundary.
Platform state
Current live endpoint behavior is audit-oriented; real-time endpoint exec-deny remains deferred and platform-specific.
Evidence boundary
Unknown defaults to AllowWithAlert, not fail-closed block. Coordinated protection and recovery remain planned. WORM applies only to the supported S3 adapter with Object Lock explicitly enabled; other backends fail closed.
Before you start
Accepted agent distribution, policy mode, baseline and publisher inputs, audit sink, and platform support.
Evidence reviewed 2026-08-26