Protection watches programs.
cybee checks program behaviour, known threat signatures and local content for threats. Hardening strengthens the Mac’s settings.
Understand the three jobs
Protection and a settings score are free. The score compares your Mac with the CIS Benchmark, a public security checklist. Applying and maintaining hardening is paid.
No detection engine or configuration guarantees that every attack will be prevented. A useful security record makes the observed state and the limits visible.
Read an alert without guessing
- Identify the device and the time of the event.
- Read what the program did and what triggered the finding.
- Distinguish a detection from a completed response.
- Check whether a next step needs your confirmation.
- Keep missing context visible instead of treating it as a clean result.
Explain this alert. Which Mac is affected, what was observed, what action happened and what needs my confirmation?
Alerts can reach the admin through Slack, Microsoft Teams or SMS. The notification brings the finding to the team. The assistant is where you ask about the alert and review any next action. Receiving an alert is not approval to change a device.
What runs on the Mac
Detection, hardening and remediation run locally. Device protection uses Apple’s user space security framework, with signatures and content inspection alongside behavioural detection.
Security events, control states, inventory facts and alerts are telemetry that can leave the device. The product is not an employee monitoring tool. Productivity tracking is not part of it.
See the processing boundariesAI tools and recorded activity
See AI tools, mapped external MCP connections and recorded tool activity. MCP connects assistants to external tools. Connection records name the agent, server, transport and endpoint. Activity records show time, tool, action and phase. An attempt is not a completed action. Visibility does not restrict agent permissions.
Explore AI visibilitySeparate access limits for each agent are planned. Google Workspace monitoring covers connected accounts separately from the Mac record. Microsoft 365 monitoring is in development.
Keep existing protection in context
cybee is intended to sit alongside existing tools. Keep a clear inventory of what protects each Mac and confirm compatibility before changing an existing setup. An MDM, an endpoint product and a dated evidence record solve different parts of the problem.
See what hardening addsThe next step is one command.
Protect your Mac, strengthen its settings and keep a dated record of the results.
For supported Macs. cybee is a Swiss company, independent, privacy first.
curl -sSf https://get.cybee.dev | sh