Skip to content
All tools

Guard · Govern

Run a Cybersecurity Scan

Scan the Tableau Server and Cloud estate and assets for cybersecurity risk.

Deterministic, end to endVersion 3.4.3

Platform guarantee

Your audit trail writes itself while you work.

Verifiable by your auditor

Governed changes land in a hash-chained ledger using plain SHA-256 with no secret key, so your auditor can re-verify its integrity from the export with their own tools.

In the product

Guard, as it actually looks.

The Guard tool running inside TabTotal.
Guard 3.4.3, behind the shared login to TabTotal. Your own Tableau permissions come with you. You see what you already have rights to and nothing else.

The register

What Guard does for you.

Every line below was read out of the product’s own source on 14 August 2026.

  • Every finding is tagged with a CIS Controls v8.1 Safeguard ID and a NIST CSF 2.0 function, deterministically.

  • That tag travels into the CSV, the SARIF 2.1.0 export, the PDF and the interface, so it reaches your scanner and your auditor unchanged.

  • Twelve mapped rules across three CIS Safeguards and three CSF functions.

  • A rule outside those twelve is still tagged rather than left blank, from a declared default.

  • It produces mapped audit evidence, and says so plainly. It is not a certification of compliance.

Specification

  • Version3.4.3

    Shipping at the 24 August 2026 research pass.

  • Packageboreon-tabguard

    The repository this behaviour lives in. Every claim above has somewhere to be checked.

  • Model useDeterministic, end to end

    Rules in code from start to finish. A result is reproducible.

Assurance

Certainty you can hand to an auditor.

Guard is one of the tools in the suite that reaches every finding from rules written in code, with no model anywhere in it.

There is no provider key to procure, no prompt to review and no sampling temperature to explain to a risk committee. Every run agrees with the one before it.

Run it twice, and get the same answer twice.

Deterministic, end to end

Guard reaches every finding from rules written in code, with no model anywhere in the tool. The same input produces the same result today, next quarter, and in front of your auditor. Anyone can re-run it and compare.

Govern

Prove what changed, who can reach it, and what it exposes.

Guard sits with these, and one login opens all of them with your Tableau permissions.

See Guard in your own Tableau Environment.

A month on your own content is a better test than any description of it.