Security should be built around evidence, transparency, and user control.

ProtectKit is designed to help Windows users understand what their computer is doing, why something may deserve attention, and what evidence supports a finding.

1. ProtectKit's security approach

ProtectKit is built around a straightforward idea: security information is more useful when people can understand what was found, why it matters, what evidence supports it, and what they can do next.

Evidence before assumptions

An unfamiliar item or unusual behavior should be investigated rather than automatically declared malicious.

Explain the finding

ProtectKit aims to provide useful context instead of relying only on unexplained warnings or scores.

Communicate uncertainty

When available evidence is incomplete, ProtectKit can use states such as Unknown or Inconclusive rather than pretending certainty exists.

Keep the user in control

Security actions can have consequences. ProtectKit is designed to help users understand an action before making meaningful system changes.

ProtectKit does not treat “unfamiliar” as a synonym for “malicious.”

Legitimate applications can behave in unusual ways, while malicious software can attempt to look normal. Context and correlation matter.

2. ProtectKit complements Windows security

ProtectKit is not designed to replace Microsoft Defender, Windows Firewall, Windows Security, or other security technologies built into Windows.

Instead, ProtectKit brings important security information and supported Windows security functions into a more unified interface and adds investigation, monitoring, explanation, logging, privacy, and maintenance capabilities.

For example, ProtectKit can help users inspect Microsoft Defender, review firewall status and rules, evaluate DNS and hardening settings, examine startup programs and services, investigate network connections, and review system changes.

3. Local system analysis

Much of ProtectKit's analysis is based on information available directly from the Windows computer on which ProtectKit is running.

Depending on the feature, this can include Windows security configuration, processes, services, startup information, firewall configuration, network connections, executable information, digital signatures, system settings, and other local security or system data.

Keeping appropriate analysis local reduces the need to send ordinary system information to an external service simply to display or evaluate it.

4. When ProtectKit uses online services

Some ProtectKit functions require an internet connection because the requested information or service exists outside the computer.

Examples can include:

  • Optional reputation or threat-intelligence lookups.
  • IP address, domain, registration, or related investigation information.
  • Premium purchase and entitlement verification.
  • Subscription and account-management functions.
  • Microsoft Store services and application updates.
  • ProtectKit website and support services.

For an online investigation, the information necessary for the requested lookup may be sent to the relevant provider. Depending on the feature, this may include an identifier such as a file hash, IP address, or domain name.

Online reputation is supporting evidence.

A reputation result can be useful, but it should not automatically override all other evidence. External services can have incomplete data, false positives, false negatives, or no information about a new or uncommon item.

For more information about information handling, see the ProtectKit Privacy Policy.

5. Administrator permissions

ProtectKit normally runs without requiring administrator privileges for every operation. However, Windows restricts access to many security-sensitive settings and system-level functions.

When an operation requires elevation, ProtectKit may indicate that administrator permission is required. Windows may then display a User Account Control prompt as part of the requested operation.

Users should read the prompt and understand the action they initiated before granting elevated access.

Admin Required is a permissions state, not a threat classification.

It means ProtectKit cannot complete the requested protected Windows operation with the current permission level.

6. Findings, evidence, and confidence

ProtectKit uses available information to help distinguish ordinary conditions from items that deserve additional attention. Depending on the feature, users may see states such as Trusted, Protecting, Needs Attention, Suspicious, Unknown, Critical, Inconclusive, or Admin Required.

These labels should be interpreted together with the supporting evidence. Relevant evidence can include:

  • Executable or file location.
  • Publisher information.
  • Digital-signature information.
  • File hashes.
  • Startup and service behavior.
  • Associated processes.
  • Network connections and destinations.
  • System changes.
  • Available reputation information.
  • Timing and relationships between events.

ProtectKit's goal is to help users understand both the evidence and the confidence that can reasonably be placed in a conclusion.

Understanding ProtectKit Findings

7. Security logging and history

ProtectKit records important application and security activity to provide context, history, and troubleshooting information.

Logs can help answer questions such as what ProtectKit observed, what action was performed, and approximately when an event occurred.

Because security logs can contain information about the computer, users should review logs and exported reports before sharing them. Depending on the event, they may contain timestamps, file paths, process information, network information, findings, or actions performed in ProtectKit.

ProtectKit logs are not a substitute for specialized forensic evidence collection where legal, regulatory, or incident-response requirements apply.

8. ProtectKit and system changes

Some ProtectKit features are informational. Others can make meaningful changes to Windows when the user requests them.

Examples can include supported firewall configuration, security hardening, DNS configuration, startup or service actions, maintenance, repair, optimization, and recovery operations.

ProtectKit is designed to make the purpose of these actions understandable, but users should still consider the consequences before changing system configuration.

For significant changes, appropriate backups and Windows recovery options are recommended. A System Restore point can be useful for some configuration changes, but it is not a replacement for a proper backup of important personal data.

9. Application distribution and updates

ProtectKit is distributed through the Microsoft Store. Users should obtain ProtectKit through its official Store listing rather than unknown third-party download sources.

Application updates can contain security improvements, reliability fixes, feature changes, compatibility improvements, and other corrections. Keeping ProtectKit and Windows current is an important part of maintaining a supported environment.

Official Microsoft Store Listing

10. Security has limitations

ProtectKit does not guarantee that a computer is free from malware, spyware, stalkerware, unauthorized access, or other security threats. It also cannot guarantee that every suspicious activity will be detected or that every finding will be correct.

Security software can encounter false positives, false negatives, incomplete information, permission limitations, new threats, evasive behavior, and failures in operating-system or external services.

ProtectKit should be used as part of a broader security approach that includes supported Windows protections, software updates, strong account security, appropriate backups, careful handling of untrusted files and links, and informed user decisions.

No security product can provide absolute protection.

ProtectKit's purpose is to improve visibility, understanding, investigation, and response while working alongside the security technologies built into Windows.

11. Report a security concern

If you believe you have discovered a security issue specifically involving ProtectKit, please report it privately rather than publishing sensitive technical details before there has been a reasonable opportunity to investigate.

Include enough information to reproduce and understand the issue when possible, such as the ProtectKit version, affected feature, Windows version, steps to reproduce the behavior, expected result, actual result, and relevant error information.

Do not include passwords, authentication tokens, recovery codes, private keys, or complete payment-card information.

Security contact

Send ProtectKit security concerns to the official ProtectKit support address and clearly identify the message as a security report.

support@getprotectkit.com

Visit the ProtectKit Help Center →