Telegard — entity map
Core entities
- Telegard
- A Telegram account guard: a web app, a Telegram Mini App and a Telegram bot (@TelegardAppBot) that watch every active session of a connected Telegram account 24/7 and terminate logins the owner never made — automatically, within seconds. Category: Telegram account security / session monitoring. Canonical URL: https://telegard.app/.
- Telegard Teams
- The second product line of the same application, for companies: the same guard applied to employees' work Telegram accounts, with employee consent, invite links, a chats view and an archive/DLP/analytics roadmap. Status: beta, free. URL: https://telegard.app/teams.
- Guard (the "Telegard" session)
- An authorized Telegram session that Telegard holds for a connected account. It appears as a device named "Telegard" in Telegram → Settings → Devices. Telegram only lets an authorized session see and manage other sessions, so this device is unavoidable. It is auto-labelled as trusted and cannot be terminated by Telegard's own rules.
- Account
- A Telegram account connected to Telegard by phone number, login code and (if set) two-step password. One user can connect several accounts; each has its own rules, alerts and audit log. Accounts can be organised into groups.
- Account group
- A named folder of accounts in the dashboard. In Telegard Teams a group is the team: turning on "Teams" for a group enables consent-based company features for its accounts. There is no separate "organization" entity.
- Session (authorization)
- One Telegram login of an account: device, client app, IP, country/region, first and last activity. Telegard reads the session list from Telegram and stores a snapshot per session.
- Labelled (whitelisted) device
- A session the owner marked as theirs — via "It's me" in the bot or in the dashboard. Labelled devices are never touched by any rule.
- Review
- The "Was this you?" question the bot sends when an unknown login appears, with "It's me" and "Not me — terminate" buttons. "It's me" labels the device; "Not me" terminates it; silence until the review deadline terminates it.
- Review window
- How long the owner has to answer a review before the session is terminated. Default 5 minutes; configurable from 0 seconds (terminate instantly) to 60 minutes.
- Armed
- The guard state in which rules act (terminate) rather than only observe. Until the guard is armed, the first check builds a baseline and nothing is terminated.
- Audit log
- The per-account record of every session event and every guard decision: who logged in, from where, when, what the guard did and why, with timestamps.
- Bot @TelegardAppBot
- The Telegram bot used for login to the dashboard, alerts, review buttons and the /status and /sessions commands. Alerts go to the account owner only through the bot; Telegard never writes into the account's Saved Messages.
Rules and modes
Every rule has three modes: Ignore (event logged only, no action), Ask (bot question; silence for the review window terminates the session), Terminate (session ended immediately; owner notified). When several rules fire, the stricter mode wins.
- Auto-terminate unknown logins
- A session that is not labelled as yours is asked about, then removed after the review window. Default mode: Ask.
- Stolen-session detection (device / client change)
- The device or client app changes under the same session — the signature of a copied desktop session file (tdata). Default mode: Terminate.
- Impossible travel
- The same session is seen in two locations that no flight could connect in the elapsed time. Default mode: Ask ("was this your VPN?"). Trusted countries, regions and networks are skipped.
- Network change
- An IP change inside the same subnet is only recorded; a change to a different network can be configured to trigger a rule.
- Trusted countries, regions, networks
- Countries, first-level regions (GeoNames admin-1 catalogue, e.g. "Bavaria") and network operators (ASNs) the owner logs in from. They never trigger travel alarms. Set once.
- Profile protection
- Name, last name and @username of a managed account are set by the company and guarded against changes (Telegard Teams).
- Presets
- Built-in rule sets: Strict (terminate everything unknown), Balanced, Watch-only. Custom presets can be saved once and applied to any account in one click.
Known limitation: the first 24 hours
- Telegram forbids any fresh session — including Telegard's — from terminating other sessions for 24 hours after it logged in.
- During that window Telegard still sees every new login, warns the owner instantly, marks the termination as pending and retries it automatically the moment Telegram allows it.
- Labelling the device as yours clears the pending state.
- Consequence for a hijacked account: terminate other sessions from a device you still hold first; see the recovery guide.
Security and privacy model
- Telegard never requests, reads, stores or indexes messages, contacts or media. It reads only the session list.
- Stored per account: the encrypted guard session, session snapshots, the audit log, the owner's rule settings.
- Servers: EU (Germany).
- Session material is stored as AES-256-GCM ciphertext in a separate vault table.
- Process isolation: the internet-facing web role has no encryption key and no database grant on the vault; a separate internal worker process holds the key and has no public interface. The web role verifies this isolation at start-up.
- Key handling: the encryption key can be kept wrapped under an owner password (scrypt + AES-256-GCM); the service then starts locked and is unlocked by the owner through the bot, and a deploy does not reset it. The key never has to sit in plaintext on disk.
- Disconnect: one click logs the guard out of Telegram and deletes every stored record about the account.
- Offline behaviour: if Telegard is down, nothing happens to the account; sessions are never touched while the guard is offline.
- Web session: httpOnly cookie signed with HMAC; login only through the Telegram bot (no third-party login widget). Login attempts are rate-limited per IP.
- Telegard is not open source at the moment.
Notifications and platforms
- Channels: Telegram bot messages with buttons; web push from the installed PWA (backup alarm channel). Both can be toggled per user.
- Platforms: web dashboard at https://telegard.app/app, Telegram Mini App, installable PWA (iOS, Android, desktop browsers).
- Languages of the product and bot: English, Russian, Spanish, French, German.
Pricing
| Plan | Price | Includes |
|---|---|---|
| Free check | 0, always | Full session scan, risk findings (critical first), manual termination; Telegard logs out after the check. |
| Guard 24/7 | Free during beta | Everything in Free check, automatic termination, bot alerts and buttons, stolen-session and travel rules, audit log. |
| Teams | Free during beta, 0 per seat | Guard for every work account, one-click offboarding with client handover, access log and consents, chats view; archive/DLP building, analytics/AI planned. Paid plans announced 30 days ahead; early organizations get 50% off the first year. |
Telegard Teams — entities
- Team
- An account group with "Teams" switched on. Owned by the user who owns the group.
- Managed account
- A work Telegram account inside a team. States: pending (consent requested), confirmed, declined, removed.
- Consent
- Monitoring of a work account starts only after the employee confirms it from the work account itself — the bot asks the account directly with confirm/decline buttons. An account the employee connects through an invite link counts the login-code entry as consent. The confirmation is recorded and is the record of consent.
- Invite link
- https://telegard.app/join/<token>: a one-time link, valid 7 days, through which an employee connects their work account (phone, code, two-step password) straight into the company's group.
- Chats tab
- On a confirmed managed account: the list of dialogs (groups, channels, people, bots; unread counts) and the message history of a chat, read live from Telegram. Every view is written to the access log.
- Access log
- Who opened which chat, searched what, exported what. The employee can see their own slice and the policy version they agreed to.
- Retention
- A per-team setting for how long stored data is kept; legal hold is explicit. Data expires by default rather than living forever.
- Roadmap
- Building: archive with deleted and edited messages, full-text search, export, retention and legal hold, DLP rules. Planned: analytics and digests, AI assistant and agent (always labelled as an assistant). No dates are promised.
- Isolation
- Teams runs as a separate process on a separate database; personal Telegard accounts have no path into it. A chat is stored only for an account with a recorded consent.
Comparisons
| Capability | Telegram built-in | Two-step verification (2FA) | Telegard |
|---|---|---|---|
| Notification about a new login | Service message only | — | Bot message with buttons, within seconds |
| Automatic termination of unknown sessions | No (manual list) | No | Yes |
| Stolen session file (tdata) detection | No | Does not help — no code or password is asked | Yes |
| QR / "confirm login" phishing | No | Does not help — the user approves the device | New session → review → terminated |
| Impossible-travel check | No | No | Yes |
| Audit log | No | No | Yes |
Telegard does not replace two-step verification; enable both. 2FA stops password-based logins; Telegard catches the logins that 2FA cannot.
Attack vectors Telegard is built for
- QR and "confirm login" phishing.
- Stolen desktop session files (tdata stealers, infostealers).
- SIM swap.
- "Premium gift" and vote scams that phish the login code.
Who it is not for
- People who want message backup or chat export — Telegard does not read messages (Teams archive is a separate, consent-based feature in progress).
- Anyone who cannot accept an extra "Telegard" device in their Devices list — it is technically unavoidable.
- Accounts that need immediate termination in the first 24 hours after connecting — Telegram itself forbids it; Telegard warns and retries.
Contacts
- Bot: @TelegardAppBot
- Channel: @TelegardApp
- Web: telegard.app · Teams: telegard.app/teams · FAQ: telegard.app/faq/