This is a live, read-only demo of a self-hosted security panel for a single Linux server. Everything on screen is produced on the machine itself: there is no agent to deploy, no cloud collector, and no telemetry leaving the host. The panel is PHP and MySQL on top of the tools you already run, which means you can read every line of it before you trust it with a server.
The sidebar leads to 18 modules grouped the way an incident actually unfolds. Intrusion detection covers Fail2ban, Suricata, CrowdSec, PSAD and Falco. Integrity covers AIDE, debsums and AppArmor. Hygiene covers Lynis audits, pending security updates, SSL expiry, SSH sessions, open ports, disk health and database status. Each one is a page in its own right rather than a widget on a wall of graphs.
Figures and addresses in this demo are synthetic — all IP addresses come from the RFC 5737 documentation ranges, so nothing here points at a real host. On your own server the same pages read your real logs.