M A L P H A S

On-device endpoint security for Windows. Local AI scores every file and process on your machine. The verdict lands in a fraction of a millisecond, and nothing is sent to the cloud.

AI INFERENCE 0.15ms
FILE → VERDICT ~60ms
CLOUD CALLS 0

Timings as tested on recommended hardware specs.

MLP-01 // WHAT IT IS

Runs where you can't see it.

Malphas is endpoint security for Windows that runs entirely on your own machine. Every file, download and program is checked by a local AI the instant it appears. The verdict arrives in under a millisecond, a full file scan finishes in about sixty, and nothing ever leaves your PC.

Timings as tested on recommended hardware specs.

Ordinary security software ships your files to its cloud to decide if they're safe. Malphas doesn't. The judgment happens here, and it stays here.

  • WHERE IT DECIDESON YOUR PC
  • YOUR FILES SENT OUTNONE
  • WHEN OFFLINESTILL ARMED
NOTHING LEAVES THIS MACHINE

MLP-02 // HOW IT WORKS

Three steps. No internet required.

  1. 01

    It's always watching

    The moment a file lands or a program starts, Malphas catches it down at the Windows kernel, before it gets to run.

  2. 02

    It decides, on your PC

    The Local AI examines the file on your PC and delivers its verdict in a fraction of a millisecond. No upload, no account, no server.

  3. 03

    It contains & explains

    Everything already runs inside a sealed sandbox, so a threat only ever touches a throwaway copy. Anything dangerous is stopped and locked away there, and you get a plain-English reason why.

Timings as tested on recommended hardware specs.

MLP-03 // ON-DEVICE AI · NO CLOUD IN THE LOOP

The models run on your machine.

This is the part people don't expect: the AI itself lives on your PC. Three small models split the work: one decides, one reads text, one explains. None of them ever phone home.

THE DECIDER

LightGBM

Looks at a file's structure and calls it malware or safe. That's the main verdict. A gradient-boosted model trained on a huge malware dataset.

  • TRAINED ON2,381 EMBER
  • ACCURACY (AUC)0.9961
  • INFERENCE~0.15 ms

THE READER

DistilBERTINT8

Reads the text of links and pages to catch phishing, but only when the decider is unsure, so it never slows down the obvious cases.

  • SIZE ON DISK67 MB
  • CHECK TIME~15 ms
  • STEPS INFOR BORDERLINE CASES

THE EXPLAINER

Gemma 4E2B

Writes the plain-English reason a file was flagged. It only narrates. It's never allowed to overturn the verdict.

  • RUNS LOCALLY3.1 GB
  • ROLEEXPLAIN ONLY
  • CAN OVERRULENEVER

MLP-04 // DETECTION · CATCH IT IN THE ACT

Caught before it ran.

Here's how a threat moves through Malphas, stage by stage: inspected, judged, boxed in, then explained. An illustrative walkthrough; scroll to step through it.

01 STATIC ANALYSIS

The file is dissected without running it: headers, imports, entropy, section layout.

  • READS 2,381 TRAITS OF THE FILE
  • SPOTS CODE PACKED TO HIDE ITSELF
  • EXAMPLE FILE · 4 IMPORTS LOOK SUSPICIOUS
02 LIGHTGBM VERDICT
  • SCORED BY LIGHTGBM, THE DECIDER
  • 0.994 / 1.00 = 99.4% SURE IT'S MALWARE
  • EXAMPLE FILE · JUDGED IN ~0.15 MS ON YOUR PC
03 SANDBOX DETONATION
  • THE FILE RUNS IN A SEALED SANDBOX
  • IT ONLY EVER TOUCHES A DISPOSABLE COPY
  • YOUR REAL SYSTEM STAYS UNTOUCHED
04 GEMMA EXPLAINS

Posed as a system process, tried to inject, persist, and call out. Caught before it ran.

LightGBM decides · Gemma only explains · it can never downgrade a verdict

NEUTRALIZED

Timings as tested on recommended hardware specs.

MLP-05 // CONTAINMENT

Every app runs in a cage. Not just the suspicious ones.

Most security software waits until it decides something is bad. Malphas doesn't wait. Out of the box, every program you launch runs inside a sandbox: your browser, your editor, the installer you just downloaded. Nothing runs loose on your real system unless you personally say it can.

THE CAGE

It writes to a copy.Never to your disk.

A sandboxed app sees a normal Windows machine. It isn't one. Every file it writes goes to a private copy; every registry key it sets lands in a fake hive of its own. Malware that tries to survive a reboot writes its startup key into nothing. Your real files are never touched. And if a caged app launches another program, that one is caged too, so nothing sneaks out through a side door.

app copy disk

FAIL-CLOSED

If the cage won't hold,it never runs.

Every program starts out paused, before it can run a single line of code. Malphas builds the sandbox around it, checks the seal, and only then lets it run. If the sandbox can't be built, the paused program is quarantined instead of started: locked away where it can't do anything, and kept there, so you can restore it yourself if you know it's safe. Nothing gets to run first and be contained later.

THE BROKER

Contained,without being broken.

A sandbox that breaks your apps is a sandbox you'll turn off. So before Malphas cages an app, the broker works out what that app is. A virtual machine is meant to reach the disk. A code editor is meant to launch build tools. Software that can prove what it is — properly installed, registered with Windows, signed by a publisher Malphas knows — gets exactly the room its job needs. Anything unidentified stays fully caged.

app id? fits held

YOUR WORK

The internet still works.So does your work.

Sandboxing usually breaks things. This one doesn't. Caged apps still reach the internet, so your browser browses and your apps update as normal; only programs Malphas can't identify get cut off. And nothing you save in the cage is thrown away — close a sandboxed app and Malphas shows you what changed, so you keep what you want. If something you trust still won't run right, one click runs it normally.

net ok kept

MLP-07 // LOCAL vs CLOUD

Your security shouldn't depend on someone else's cloud staying up.

Same job, two places to do it. Cloud-based security sends your files off to a server to decide; Malphas decides on your machine. Here's what that changes.

  CLOUD-BASED MALPHAS
VERDICT PATH round-trip to a datacenter on your machine
LATENCY 50–300 ms round-trip ~60 ms local scan, no network
YOUR DATA uploaded as telemetry your files never leave
IF THE CLOUD IS DOWN you are unprotected still fully armed, offline
TYPICAL CLOUD ROUND-TRIP ~50–300 ms
MALPHAS · LOCAL SCAN ~60 ms

Timings as tested on recommended hardware specs.

MLP-08 // FLEET · MALPHAS ENTERPRISE

One dashboard. Every computer in your company.

The USER version protects one machine. ENTERPRISE adds a single console to see and manage every endpoint in an organisation, with the audit trail and signed updates a security team needs.

Malphas Control Plane

d.monga Super Admin

Devices

WS-0114

Windows 11 Pro

online

LT-0083

Windows 11 Pro

online

WS-0271

Windows 10 Pro

online

SRV-002

Windows Server 2022

online

WS-0027

Windows 11 Pro

online

WS-0356

Windows 11 Pro

online

LT-0219

Windows 10 Pro

online

SRV-004

Windows Server 2019

online

WS-0412

Windows 11 Pro

online

LT-0055

Windows 11 Pro

online

WS-0188

Windows 10 Pro

online

LT-0140

Windows 11 Home

last seen 2h ago

ONE CONSOLE · EVERY ENDPOINT

MLP-09 // DOWNLOAD

Two doors.

MLP // MALPHAS

For your machine. Private.

  • Full local detection engine
  • Download scanner + own-execution sandbox
  • On-device AI verdict & explanation
↓ DOWNLOAD FOR WINDOWS

macOS & Linux · coming soon

  • VERSIONv1.1.9.2
  • SIZE3.98 GB
  • REQUIRESWINDOWS x64

Ships with the on-device AI models. That's why it's a big download, and why it never needs the cloud.

MLP // MALPHAS

For the fleet. Admin server included.

  • Everything in Malphas
  • One console, every endpoint
  • Fleet RBAC · audit log · signed updates
  • VERSIONv1.0.0
  • SIZE~4.2 GB
  • REQUIRESWIN SERVER 2019+

Everything in Malphas, plus the fleet console. Models included, no cloud dependency.

MLP // ENTERPRISE · CONTACT

Tell us about your fleet.

Every machine still protects itself. The AI runs on each PC exactly as it does in the USER version, and no file ever leaves the device. ENTERPRISE adds a console on top of that: one screen where you see every machine in your organisation, set the rules they follow, review a tamper-evident audit log, and push signed updates.

The console runs on your own Windows Server. There is no Malphas cloud and nothing is sent to us. We install it and set it up for you, end to end.

  1. 01SEND THIS FORM
  2. 02SCOPING CALL · WE MAP YOUR FLEET
  3. 03WE INSTALL THE CONSOLE ON YOUR SERVER
  4. 04ENDPOINTS ENROLLED · HANDOVER & TRAINING

FLEET ENQUIRY · FIELDS MARKED * ARE REQUIRED

We reply within one business day · prefer email? [email protected]

WINDOWS x64 · NO ACCOUNT · TELEMETRY OFF BY DEFAULT