Skip to content
DEFYNTA

Defynta Overseer

Know what your apps are talking to.

Overseer names the program behind every connection, flags what is out of character for it, and lets you allow or block it in one click.

  • Windows dev build
  • Metadata only
  • No TLS interception
Development build - not for sale

There is no signed installer, no macOS or Linux client, and nothing that can hold a connection open while it asks you. Everything here describes what exists today, not what is planned.

What it does

01

Every connection has a name

See the program behind each flow, not just an address. Overseer records its SHA-256 and signature state, and labels shared Windows service hosts as shared instead of blaming the wrong app.

02

Alerts that explain themselves

Every finding shows what was seen, what was expected, and how confident it is. Reason codes like DESTINATION_NEW_FOR_EXECUTABLE keep their meaning across releases.

03

One click to decide

Allow or block from a single panel. Before a rule sticks, Overseer shows you the sentence it becomes, so “allow this app” never quietly means “allow one address that changes tomorrow”.

Watch one program

Pick anything that is running and record it for a set time. You get a timeline of what it contacted, on which ports, how much data moved, and where it drifted from its usual pattern. Yellow marks suspicious, red marks high risk, and every mark opens the evidence behind it.

Recordings capture metadata only. Full packet capture is an opt-in local setting with an explicit warning, and packet data is never uploaded to Defynta.

How it learns what is normal

First it compares a program to itself on your machine: the destinations, ports and volumes that executable has used here before.

A hive adds context from other installs - an anonymous baseline of how one program usually behaves. It is not a list of people, devices or destinations. Only bucketed traits are shared: direction, port range, country, rough volume. Your domains and addresses are not, and no comparison is returned until enough independent installs exist to hide any single one of them. Hives are not live in this build.

What it will not do

  • Read your traffic. No TLS interception, no local root certificate.
  • Upload executables, packet contents, file paths or command lines.
  • Block something for being new, rare, foreign or unsigned alone.
  • Pretend to replace antivirus, EDR or a managed enterprise firewall.
  • Ask for a licence key or take a payment inside the app.

A hash identifies bytes, not intent, and a valid signature proves who signed a file, not that it is safe - malware can ride inside a trusted process without changing anything on disk. Overseer states those limits in the interface rather than implying a certainty it does not have.

Getting it

Overseer is included with Defynta Silver and every higher plan - no licence key, no separate purchase. You approve the installation once in your browser, and the app receives a credential bound to a key it generated locally.

Windows has a working development build. macOS and Linux clients do not exist yet. See system requirements for what each platform can do today, and what Overseer sends us for the data boundary.

Common questions

No. It records metadata: the program, the direction, the address and port, the protocol, byte counts, and the TLS details that are visible without decrypting anything. There is no TLS interception and no local root certificate.

So real findings are not buried under routine noise. A component is only quietened when the Microsoft signature, the protected location and the package identity all agree - a copy of a system binary in a writable folder inherits none of that. Hidden components are still fingerprinted, still checked against threat verdicts, and one click shows their traffic.

Your rules keep working and nothing local is deleted. Cloud lookups and new recording sessions stop. Unknown traffic is allowed rather than blocked, so an expired plan can never cost you network access.

It is built so it cannot. If the service, the interface or the filter fails, Overseer keeps the rules it can safely keep, allows unknown traffic, and tells you it is in a degraded state. Uninstalling removes the filtering before it removes anything else.

No, and Overseer never claims it does. Equal hashes only mean equal bytes. Reputation, peer comparison and behaviour are separate signals, each with its own confidence and its own expiry.

Copyright © 2024-2026

All rights reserved.