OUTBOUND VISIBILITY
A breached tool does not stay quiet
It reaches out — for instructions, or to send data somewhere. nuDefend records every destination each AI workload on your server reaches, and how much left for it.
You can see what comes in. What goes out is invisible.
Firewalls are built around who may reach your server. Almost nothing watches the other direction. So when a tool is compromised, the part that matters most — where it now talks to, and how much it is sending — is the part nobody is looking at.
Every destination, per tool
Not one list for the whole machine: what Ollama reaches, what n8n reaches, each on its own. Direct on the server or inside a container.
How much left, not how often
Connection counts alone do not tell the story. A short connection that moved a few kilobytes and one that moved tens of gigabytes can look identical if all you count is connections. So nuDefend shows the volume per destination, to bring forward the ones that received an unusual or significant amount of data.
When the destination was first seen, and how the traffic to it was identified
When a destination first appeared, how it was observed, and whether that observation is a full record or a sample.
The destination is named, not just numbered
An address on its own tells you nothing. Where nuDefend recognises the destination it says what it is in plain words, and where a setting turns it off it shows you that too. Where it does not recognise a destination it says so, rather than leaving you to guess from an address.
What nuDefend does not determine
The value of this page is that you can trust what is on it, which means being exact about its limits:
- It records and shows; nothing here is blocked on its own. When a destination should be closed, you can block it for that workload only — with a preview first, and one click to undo.
- It does not decide that traffic is a data leak. A large transfer can be a legitimate backup, a model download, or malicious activity, and traffic alone does not always reveal its purpose. nuDefend shows what was sent, where and how much — the context and the meaning are yours to judge.
- Tools inside containers are sampled every few seconds rather than recorded continuously, so brief connections can be missed — and every line that came from a sample says so.
Included, not an upsell
Part of nuDefend at the price you already pay. No separate tier, no per-workload charge, no agent to install beyond the one you have.
See where your AI tools connect
One command. Read-only, and it changes nothing in your server's configuration.