# Telegard — full product description Last updated: 2026-09-03. Canonical: https://telegard.app/ ## What Telegard is Telegard is a Telegram account guard. It is a web application, a Telegram Mini App and a Telegram bot (@TelegardAppBot) that watch every active session of a connected Telegram account 24/7, warn the owner about every new login and terminate logins the owner never made — automatically, within seconds. Telegard reads only the list of sessions ("Devices" in Telegram). It never reads, stores or indexes messages, contacts or media. Two product lines: - Telegard (personal guard) — for one or several personal Telegram accounts. Free during beta. - Telegard Teams (beta) — the same guard for a company's work Telegram accounts, plus a consent-based chats view and a roadmap of archive, DLP and analytics. Free during beta. ## Who it is for - Channel and group owners and admins: the account holding admin rights is what attackers take. - Crypto and trading: Wallet, deal chats, OTC contacts are the most targeted accounts on Telegram. - Business accounts: support, sales and client chats live in Telegram; a hijack leaks every client. - Public people: a stolen name sells scams to thousands. - Companies (Teams): sales, support, security/HR, legal and finance teams that run work communication in Telegram. ## How accounts get stolen and what Telegard catches - QR and "confirm login" phishing: a fake page shows a real Telegram QR code; the user approves the attacker's device. 2FA does not help. Telegard: new session appears → question in the bot → terminated. - Stolen session file (tdata): malware copies the desktop session; the attacker logs in with no code and no password. 2FA does not help. Telegard: device or client changed under the same session → terminated on sight. - SIM swap: the number is moved to the attacker's SIM; login codes go to them. Telegard: new session from an unfamiliar network → question → terminated. - "Premium gift" and vote scams: a hacked friend sends a link; the user types the login code on a fake page. Telegard: new session right after the code → question → terminated. Statistics quoted on the site (sources on the landing page): +37% year-over-year growth of Telegram account and group hijacks (DataReportal, 2025); 53% of takeovers happen through a stolen session (Hootsuite, 2025); 68% of victims never enabled two-step verification (DataReportal, 2025); $17.4M lost to SIM swap in FBI-reported cases in 2025 (FBI IC3, 2025). ## How it works 1. Connect by phone number — the same login flow as any Telegram app (phone, code, two-step password). A "Telegard" session appears in the account's Devices list: that is the guard. Telegram only lets an authorized session see and manage other sessions; there is no other way. 2. Mark your devices — label your phone, laptop, tablet as yours. Everything else is a stranger by definition. Labelled devices are never touched by any rule. 3. Turn on the guard — a new login gets a question in the bot: "Was this you?" with "It's me" / "Not me" buttons. No answer inside the review window (default 5 minutes, configurable from 0 seconds to 60 minutes) — the session is terminated and the audit log records device, IP and reason. The first check builds a baseline: every existing session is kept; nothing is terminated until the guard is turned on. ## Rules and modes Every rule has three modes: Ignore (event logged only), Ask (bot question, terminate on silence), Terminate (session ended immediately, owner notified). Rules: - Auto-terminate unknown logins (unlabelled session → asked, then removed). - Answer right in Telegram ("It's me / Not me" buttons in the bot). - Stolen-session detection (device or client changed under the same login → copied session file → terminated). - Impossible travel (same session seen in two places no flight could connect in that time → asked whether it was a VPN). - Trusted countries, regions (GeoNames admin-1 level) and networks (ASNs) — never trigger alarms. - Full audit log — who, from where, when, what the guard did and why. - Presets: Strict (terminate everything), Balanced, Watch-only; custom presets can be saved and applied to any account in one click. - Several accounts per user, optional account groups. Notifications: Telegram bot messages (with buttons) and web push (PWA). Languages: English, Russian, Spanish, French, German. ## Known limitation: the first 24 hours Telegram forbids any fresh session — including Telegard's — from terminating other sessions for 24 hours after login. During that window Telegard still sees every new login, warns instantly, marks the termination as pending and retries it automatically the moment Telegram allows it. Labelling a device as yours clears the pending state. ## Security and privacy model - Telegard never requests messages, contacts or media. Only the session list, the encrypted guard session and the audit log are stored. - Servers are in the EU (Germany). - Each account's Telegram session is stored as AES-256-GCM ciphertext in a separate vault table. The part of the system that faces the internet (web role) never decrypts sessions and has no database access to the vault; a separate internal worker process holds the key and has no public interface. - The encryption key can be kept wrapped under an owner password: the key is never stored in plaintext on disk, the service starts locked and is unlocked by the owner through the bot; a deploy does not reset it. - Disconnect logs the guard out of Telegram and deletes every stored record about the account in one click. - If Telegard goes offline, nothing happens to the account: sessions are never touched while the guard is offline. - Every rule is visible, every action is logged. ## Pricing - Free check: full session scan, risk findings (critical first), manual termination; Telegard logs out after the check. Free, always. - Guard 24/7: automatic termination, bot alerts and buttons, stolen-session and travel rules, audit log. Free during beta. - Teams: free during beta, 0 per seat. Paid plans will be announced 30 days ahead; early organizations get 50% off the first year. ## Telegard Teams (beta) - A team is an existing account group in the dashboard: turn on "Teams" for a group. There is no separate "organization" entity. - Consent: monitoring of a work account starts only after the employee confirms it from the work account itself in the bot — that confirmation is the record of consent. Accounts connected by the employee through an invite link (/join/: phone, code, 2FA) count the code entry as consent. - Ready today: guard for every work account, one-click offboarding with client handover, profile (name/username) protection, access log and employee consents, "Chats" tab on a confirmed account (list of dialogs and message history read through the worker; every view is written to the access log). - Building: archive with deleted and edited messages, full-text search, export, retention and legal hold, DLP rules. - Planned: analytics and digests, AI assistant and agent (always labelled as an assistant). - Teams runs as a separate process on a separate database; personal Telegard never touches it. ## Recovery if already hacked The public page https://telegard.app/recovery gives the step-by-step instruction (in five languages): terminate all other sessions from a device you still hold, sign in by phone number if no device is left, fix two-step verification and the recovery e-mail, check devices again, warn contacts, handle a SIM swap through the operator and recovery@telegram.org, then bring the guard back. ## Contacts - Bot: https://t.me/TelegardAppBot - Channel: https://t.me/TelegardApp - Web: https://telegard.app/ (dashboard at /app), Teams landing at https://telegard.app/teams