Windows security

Native protection controls without a crowded dashboard.

Windows 0.7.0 is an unsigned development preview available to authorized GitHub testers. It is designed around Smart Scan, file/folder inspection, a resilient user-space Guard, quarantine/recovery, history and verifiable update paths.

HEIMO SOFTWARE GALLERY

Preview the desktop experience.

Interface concept illustrations based on the native Win32 code and current features. These are not screenshots captured from a running Windows PC.

Current capabilities

What the Windows candidate is built to do.

✓
Smart ScanFast inspection of common high-risk locations and selected content.
✓
File and native folder scanSingle-file and recursive folder workflows with progress, cancellation and long Unicode path handling.
✓
User-space monitoringNative directory watchers monitor configured high-risk folders, with polling fallback; no kernel-level blocking.
✓
Local quarantine and restoreConfirmed malicious files can be moved to local quarantine and restored manually. Keep backups; full tamper-resistant storage is not yet certified.
✓
Signed application updatesHTTPS + Ed25519 + SHA-256 manifests with required signed expiration.
✓
Signed Threat Pack frameworkEd25519-based threat pack verification and rollback exist, but the production feed and public signing keys are not yet configured.
Truthful scope

What this page intentionally does not claim.

No kernel minifilter claim

Current realtime protection is user-space monitoring of configured high-risk locations, not full-disk kernel interception.

No ransomware rollback claim

Mass-encryption signals can support correlation, but the product does not claim automatic malicious-process termination or filesystem rollback.

No production ML/cloud reputation claim

Those capabilities are not presented as shipping production protections unless separately implemented and validated.

Stable is evidence-gated

x64/ARM64 lifecycle, Defender coexistence, DPI/Unicode, upgrade/rollback and controlled corpus evidence must be bound to the final release SHA.

Follow the verified Windows release path.

The beta builds are unsigned, require private GitHub repository access, and should not replace Microsoft Defender.

aq.kingai.work