About the Company

A security layer for the modern API, built in public.

Guard Core protects the application layer, the part of your infrastructure that existing security tools can't see. Open-source libraries at the middleware, hosted SaaS on top. Used in production by developers in tens of thousands.

Open-source core
12 frameworks
Python + TypeScript + Rust
Hosted SaaS live
01 · The Problem

Every production API is under constant automated attack. Most developers can't see it.

The gap between what generic firewalls catch and what application-layer attacks actually do.

API attacks have moved from the network to the application. Credential stuffing, path traversal, dotfile probing, injection attempts. These exploit application logic, not network topology. Generic firewalls can't read the context.

The market has tools for code security (Snyk), error tracking (Sentry), and infrastructure monitoring (Datadog). Runtime application-layer security, at the framework level, is an empty category.

The default posture for most APIs is "we're behind Cloudflare, we're fine." The traffic data says otherwise. Edge protection catches volumetric noise. Application-layer attacks, the ones that actually compromise systems, walk right through.

Guard Core closes that gap. Middleware that runs inside your application, sees the full request context, and blocks threats the edge can't recognize.

02 · Where We Are

Twenty months of real production use.

The fastapi-guard library launched in August 2024 as open source, now the flagship adapter in the Guard Core ecosystem. Commercial SaaS launched April 2026.

333K+
PyPI downloads
821
GitHub stars
61
Releases shipped
12
Frameworks supported
3
Languages live

The library has been battle-tested through three responsibly-disclosed CVEs, all patched and shipped. Test coverage stays at 100%. The architecture is built on a shared detection engine (guard-core + its guard-core-ts + guard-core-rs counterparts) with framework-specific adapters, making every new framework integration a matter of days, not months.

Guard Core Ecosystem

3 languages·12 adapters

Framework-agnostic security engine (Python)

158K downloads10 stars
uv add guard-core
03 · The Story

From a problem, to a library, to a company.

Twenty months of shipping, four chapters.

  1. August 2024

    The library

    fastapi-guard, Guard Core's FastAPI adapter, was created to solve a problem the founder kept hitting: no middleware-level security library existed for FastAPI. The first version handled IP filtering, rate limiting, and penetration detection. Released on PyPI the same month.

  2. Mid 2025

    Adoption accelerates

    Between version 2.0 and 3.0, download numbers grew from thousands to tens of thousands. Developers started filing substantive feature requests and contributing code. Three security researchers independently discovered and reported CVEs, all responsibly disclosed and patched within days.

  3. Late 2025 - early 2026

    Ecosystem expansion

    The core was abstracted into a framework-agnostic engine (guard-core). Adapters for Flask, Django, Tornado, the full TypeScript side (Express, NestJS, Fastify, Hono), and Rust (Actix, Axum, Rocket, Tower) followed. What had been a single-framework library became a security platform.

  4. April 2026

    The commercial platform

    The SaaS platform launched at app.guard-core.com. Centralized security monitoring, cross-tenant threat reputation, dynamic rule management, weekly threat reports, all built around the telemetry agent that ships inside the open-source library. The commercial product is live. Customer acquisition is underway.

04 · Who's Building It

Solo founder, two years deep, shipping daily.

RF
Renzo Franceschini
Founder & Engineer

Senior backend engineer. Built fastapi-guard (Guard Core's FastAPI adapter) solo from zero to +90K downloads over 20 months, while holding a full-time role. Currently engaged as a contract Senior Software Engineer for AI Evaluation, the contract income covers runway through the go-to-market phase, so the company isn't raising under pressure.

Fluent in Python, TypeScript, and Rust. The technical surface area of Guard Core, an ecosystem spanning 12 frameworks and 3 languages, is entirely his work.

05 · Where We're Going

The category is empty. The window is open.

Runtime application-layer security is a real category with no incumbent. Sentry proved the playbook - framework-native middleware, open-source distribution, hosted SaaS - can build a durable company in a technical category. Nobody has applied that playbook to security.

The near-term priorities are converting the existing user base, signing our first cohort of commercial design partners, and expanding Rust adapter adoption. Beyond that, the company follows what the data tells us.

The thesis

We're not trying to displace anyone. We're building the missing layer.

06 · Get In Touch

Talk to us.

Developers, security teams, and investors who understand the dev-tools space. We'd love to hear from you. The product is open source. The conversation is open too.