How DataStun works

One login. All your machines. Kept separate. Here's how the pieces fit together — before you sign up.

One login. All your machines. Kept separate.

DataStun isn't a one-device app. Most people have more than one machine to look after — a laptop and a couple of desktops, the family's computers, maybe a company fleet. One DataStun login covers all of it, organized into separate spaces called tenants — your personal devices in one, the company's in another — that never mix.

How DataStun accounts work — one login covers many tenants and your machines, with a tier ladder from Individual to Enterprise.
One machine, one space. Each agent belongs to a single tenant — the one it was enrolled into — so the same machine never reports into two spaces at once. To move a machine to a different space, you re-enroll its agent there.

Rooted in forensic analysis

DataStun isn’t a dashboard with alarms bolted on. It’s a set of forensic methods — built over four decades of packet-level breach work by our founding team — turned into a product you run yourself.

The whole platform rests on one idea our team learned the hard way, walking into breach after breach: the network is the witness. A vendor dashboard shows you what it was built to show. The packets show you what actually crossed the wire. DataStun reads the wire and reports what it finds — for every machine you put an agent on.

An agent is an endpoint — one of your computers, servers, or workstations. You install a small agent on each one, and from then on that machine is a witness too: it watches its own traffic and reports up.

PacketMan explains — hover to play

The executable behind every session

For every connection a machine makes, DataStun resolves the full program path on disk — not just a process number. Malware tends to announce itself by its own filename, and the same method surfaces lateral movement by which executable fanned out across your fleet, not just which device. That comes straight from breach forensics.

Metadata, never content

We read destination, program, byte counts, and timing — never the content of your traffic, no deep inspection, no decryption. It’s a deliberate discipline: small enough that nobody has to trust us with your content, rich enough to flag a program quietly beaconing out of a temp directory.

Two witnesses, never merged

What each agent passively observes on its own machine, and what our reputation system actively probes from the outside, stay separate evidence tracks. Two independent witnesses corroborate each other; they don’t get blended into one.

Plans that grow one machine at a time

What “up to 3” looks like

Three machines — a laptop, a desktop and a Mac — and they don't have to share a roof. Mom's laptop in one city, Dad's desktop in another, Grandma's Mac across the country: one plan covers all three, wherever they are. Any mix of Windows, macOS and Linux.

The Individual plan covers up to three machines — a laptop, a desktop and a Mac — in one household or in three different cities, for $9/month.

Need a fourth machine on Individual? Add it — and when a bigger plan would actually cost you less, we tell you, so you only ever pay the lower price.

Some machines are servers — they answer requests from the open internet instead of just reaching out. Those take more work to protect (a server is under constant probing), so a machine we detect as a server is $15/month — and we always show you why and let you confirm before anything changes.

Who runs your account

Every account has an admin — the person who set it up, or someone they add. The admin looks after all the machines in the account: adding and removing agents, seeing what each one reports, and acting on anything that needs attention.

The admin also owns support for everyone on the account. The people whose computers are protected bring their questions to the admin, who handles the day-to-day — and when something needs us, the admin escalates to DataStun. Support flows the way it should: the person who knows your setup leads, with our team behind them.

Decide who your admin is up front. For a company, name at least two, so the account is never stuck behind one person — the admin owns the agents and the support relationship for the whole account.

Be your own M — or hand it to a pro

DataStun is a managed service you can run yourself. You appoint your own admins, and they manage every agent in your fleet from one console. No outside party is required to get full value.

PacketMan explains — hover to play

You can be your own M — your own managed-service provider — or have a professional MSSP run your account for you. The switch goes either direction, and it’s easy and reversible: you don’t re-deploy a single agent to change who’s at the controls.

Start where you are. Many teams begin self-managed to learn the system hands-on, then hand off to an MSSP once they know what they want from it. Others start managed and bring it in-house later. Both paths are first-class, and neither one strands your agents.

Signing in

Signing in with LinkedIn is the quickest way in for your personal and family spaces. For a company, set the account up under a company email with a second admin, so the fleet stays with the company, not one person.