When your laptop disappears,
your data shouldn't.

Cerberus is a silent dead-man's-switch for Windows. If you fail to check in for too long — because your laptop was stolen, lost, or seized — it automatically encrypts your protected folders and, eventually, securely wipes them. So your client files, source code, contracts and trade secrets never become someone else's leverage.

Why Cerberus exists

Modern professionals carry their entire working life on a single laptop. A bag stolen from a parked car, a forgotten device on a train, a hotel break-in — these aren't hypothetical. They happen every day, and they don't just cost a piece of hardware. They expose client confidentiality, intellectual property, regulatory compliance, and sometimes the entire future of a project or company.

!

Disk encryption isn't enough

BitLocker protects you against an offline disk reader, not against a thief who gets the password through a sticky note, a phishing call, or a logged-in session. Cerberus assumes the password is compromised.

You don't always know it's gone

The window between losing a laptop and realizing it can be hours. With Cerberus, the device is already protecting itself by then — on its own, on a schedule you set.

Two-stage protection

First the data is encrypted (still recoverable if you find the laptop). Then, after a longer silence, it is securely destroyed. You decide both timers.

How it works

A small Windows service runs quietly in the background. It checks in with your dashboard on a schedule you control. As long as it can phone home, nothing happens. The moment it can't, the countdown starts.

1

Install

One PowerShell command on the laptop. The agent registers itself with the dashboard and stores its credentials encrypted with the local hardware key (Windows DPAPI).

2

Pick the folders

Mark the folders that contain anything sensitive. Documents, source code, contracts, exports. Everything else is left alone.

3

Set the rhythm

Decide how often the agent must check in (every 6 hours? every 24?), and how long after silence it should encrypt and then destroy. Defaults are sensible; you tune them.

4

Get on with your life

The agent sleeps. As long as you keep using your laptop normally, you'll never notice it's there.

5

Phase 1 — Encrypt

If silence exceeds the first threshold, files become .cerberus archives, encrypted with AES-256-GCM and a key derived from your Master Password (Argon2id). Recoverable, if you ever get the laptop back.

6

Phase 2 — Destroy

If silence persists past the second threshold, the encrypted blobs are securely overwritten using a multi-pass procedure. Data is gone — for good and on your terms.

Privacy by design zero-knowledge

Cerberus protects your data from us, too. Encryption and decryption happen entirely on your PC, with a key only you know. Our server never sees the contents of your files — not in transit, not at rest, not in backups. We can't hand your data over because we don't have it.

What we never see

  • The contents of your protected files — never transmitted to our server.
  • Your master password — set it directly on the agent and the server never sees it. Only a verification hash is stored, never the password itself.
  • Your encrypted .cerberus archives — they live on your PC. We don't upload, store or back them up.
  • Your decryption key — without your master password, even we cannot decrypt your files. There is no backdoor.
i

What we do see

The minimum needed to make the service work. Nothing more.

  • Folder and file names in your protected paths — so the dashboard can show what's protected and let you exclude subfolders.
  • Device telemetry: heartbeat, IP, Wi-Fi network name, agent version — to detect anomalies (e.g. a device suddenly online from an unknown network).
  • An 8-KB partial fingerprint per file (4 KB head + 4 KB tail, hashed) — used only to detect copies of your files outside the protected folders. Not enough to reconstruct anything.
  • Account email + a bcrypt hash of your login password.

Read the full details in the Privacy Policy.

Who needs Cerberus?

Anyone whose laptop holds something they would not want to read in tomorrow's headlines. A small sample of the people who already sleep better because of it.

Lawyer The firm partner

Your laptop holds privileged communications, deal drafts, witness statements, internal notes on opposing counsel. A breach isn't just embarrassing — it can vacate cases and trigger bar complaints.

"On the train back from a client meeting in Frankfurt, I realised my bag was gone. Until I got home and reset everything, I knew Cerberus was already counting down."

Files are encrypted within hours, destroyed within days — all without you touching anything.

Accountant The tax advisor

Tax filings, banking credentials, signed PoAs, client P&L spreadsheets. A lost laptop on a conference floor is a regulatory event — you have legal duties to notify, to investigate, to remediate. None of which you can do well while panicking.

"After a colleague had a laptop stolen at a conference, our firm spent six weeks notifying clients and the data protection authority. We installed Cerberus across the team that month."

Documents are auto-encrypted before the breach window even closes. Fewer notifications, lower exposure, calmer auditors.

Developer The engineer

Source code, signing certificates, AWS keys, .env files, database snapshots. Even with everything stored in version control, your dev laptop has the keys to the kingdom — the kind of credentials that, in the wrong hands, become a competitor's product launch.

"My laptop got lifted from a co-working space at lunch. Without Cerberus I would have spent a week revoking and rotating every credential I had. Instead I rotated the strict minimum and let the encryption do the rest."

Repositories, secrets, and unpushed branches become unreadable to whoever finds the machine.

Project Manager The PM in client services

Roadmaps, vendor contracts, customer pipelines, internal estimates. Compliance officers want assurance that mobile devices are protected. Stakeholders want assurance they're not the next data breach press release.

"Compliance asked us how we protect client data on roaming devices. Cerberus was the first answer that satisfied both legal and IT in the same meeting."

Auditable evidence of automated protection: a real, demonstrable answer to "how do you handle laptop loss?"

Founder The startup CEO

Pitch decks, cap tables, term sheets, IP filings, customer lists, fundraising correspondence. Your laptop isn't a productivity tool — it's the company. Lose it badly and you can lose the round.

"My laptop is my company. If it disappears, the cap table is gone, the IP is gone, the trust of investors is gone. Cerberus is cheap insurance against an existential threat."

Sleep at night during demo trips, road shows, and conferences — knowing the worst case is bounded.

Consultant The independent advisor

You don't have an IT department. You don't have a CISO. You have one laptop and a dozen clients, each of whom signed an NDA assuming you'd take care of their secrets.

"As a one-person consultancy, my laptop being compromised would mean a chain of difficult phone calls to clients. I needed something that didn't depend on me being awake."

Set it once, forget it. The agent is the IT department you don't have.

Researcher The academic / R&D lead

Years of unpublished data, draft papers, peer-review communications, embargoed findings. Disclosure before publication can cost a citation, a grant, sometimes a career.

"My fieldwork data took five years to collect. The laptop with the only working copy was stolen in a hotel. The thief got nothing readable."

Embargoed work stays embargoed. Co-authors stay protected.

What people say

Real situations from professionals who use Cerberus on their daily-driver laptops. (Names and locations changed where requested.)

"I used to keep client files on a separate encrypted drive that I only plugged in on demand. It was a mess and I forgot to unplug it half the time. With Cerberus the data lives where I work, and the protection is automatic. Much closer to how I actually want to work."
Marco T. · IP Lawyer, Milan
"Last year a colleague at the firm had her laptop stolen in a hotel lobby. We spent six weeks on incident response and lost two clients. After that I pushed for Cerberus across the partnership. Worth every minute of the rollout."
Anna B. · Senior Tax Advisor, Verona
"As a backend engineer my laptop has signing keys, dev secrets, and unpushed work. Knowing it self-encrypts if I drop offline for too long means I can travel light without a paranoid checklist. The peace of mind is worth more than the tool itself."
Luca M. · Senior Backend Engineer
"We're in a regulated industry. The procurement team was about to ban personal-laptop usage entirely. Cerberus, plus Bitlocker, plus our MDM, gave us a defensible posture. Nobody had to give up their preferred tools."
Giulia P. · Project Manager, Consulting
"As a founder, my laptop is the cap table, the term sheets, the unsent emails. I don't even want to imagine what an investor would say if all of that surfaced somewhere it shouldn't. Cerberus removes that whole class of nightmare."
Davide R. · SaaS Founder, London
"I'm a freelance researcher. I work alone, I move a lot, and I'm the last line of defense for years of data. Cerberus is the closest thing I have to a colleague who watches my back."
Chiara F. · Independent Researcher

Why thinking about this now matters

Short reads on the threat models Cerberus addresses — and the ones it doesn't, because honesty is part of the design.

The 24-hour gap nobody talks about

Most "lost laptop" stories share a single pattern: hours pass before the owner realizes something is wrong. By the time the device is reported, marked stolen, and remote-wiped through MDM (if at all), the most damaging window has already closed. Sophisticated thieves don't keep the laptop online for you to wipe — they pull the disk and read it offline, or hold it for ransom.

Cerberus is built around that asymmetry. It doesn't need you to log in, locate the device, or click "wipe." If the agent can't reach home for a window you defined, it acts on its own. You're free to discover your laptop is gone after the data has already been protected.

Encryption that survives a stolen password

Full-disk encryption protects against a thief who steals the disk while the device is off. It does not protect against a thief who shoulder-surfed your password, who saw your sticky note, who phished your colleague, or who simply grabbed the laptop while it was unlocked at a café table.

Cerberus uses a Master Password stored only on your machine and only in memory until the first encryption fires — never on our server, never in the dashboard. After Phase 1 the password is purged from local cache. Even an attacker who steals the laptop and the dashboard credentials cannot decrypt your files: they would also need a secret you remember in your head and keep stored separately (a password manager, a sealed envelope, anywhere but on the laptop).

GDPR, NIS2, and the cost of "we couldn't have known"

Modern privacy regulation does not reward ignorance. Under GDPR a data controller has 72 hours to notify the supervisory authority of a personal-data breach — and a duty to demonstrate the technical and organisational measures in place. "My laptop was stolen and I didn't have anything in particular to prevent the data from being read" is increasingly an indefensible posture.

An automated, documented, time-bounded encryption + destruction policy is exactly the sort of "appropriate technical measure" regulators look for. Cerberus produces a defensible record: when the agent last checked in, when encryption was triggered, when destruction completed.

What Cerberus is not

Cerberus is not anti-virus, not endpoint detection, not a VPN, not a backup tool. It does one job and tries to do it without getting in your way. We strongly recommend you keep using full-disk encryption (BitLocker), a real password manager, and a real backup strategy. Cerberus is the last line of defense for the moment after something has gone wrong.

It also cannot recover encrypted files for you remotely. By design. If you forget your Master Password, the data is gone. That's the price of a key the server cannot help an attacker recover either.

Frequently asked questions

Does Cerberus see my files?

No. The server only knows: that your agent checked in, when, from which IP and Wi-Fi (if you allow it), how many files are under protection. The files themselves never leave your laptop. Encryption happens locally; destruction happens locally.

What if I lose my Master Password?

Then you cannot recover your encrypted files. This is intentional: a server-side recovery mechanism would also be a target for whoever steals your laptop. Store the Master Password somewhere safe and separate from the device — a password manager on your phone, an envelope in a drawer at home, a key recovery file with your lawyer.

Will the agent slow down my laptop?

No. The agent does almost nothing during normal operation: it phones home on a schedule (a single HTTPS request) and runs a periodic file inventory in the background with low I/O priority. Encryption and destruction only run when triggered.

What happens if my laptop is just offline for a long trip?

You can issue an offline reassurance token from the dashboard before you leave: a small one-time code that, written into a specific file on the laptop, resets the timer locally. Designed for flights, sailing, fieldwork, prison visits — situations where Internet is genuinely absent.

Can someone trigger destruction maliciously?

Triggering destruction from the dashboard requires you to be logged in (with email + OTP). The agent honors only signed JWT instructions from the server. If you suspect the dashboard account is compromised, change the password and revoke the device session immediately — the agent will refuse the next instruction.

Which Windows versions are supported?

Windows 10 and Windows 11, 64-bit. The agent ships as a self-contained binary — no .NET runtime required on the target machine.

Is Cerberus open source?

The cryptographic format is fully documented and the decryption tool is a small standalone binary you can audit. The protocol between agent and server is plain JSON over HTTPS. Full code release for the agent is on the roadmap.

Get in touch

Cerberus is currently in private beta — free for early adopters in exchange for honest feedback. Tell us a bit about yourself and we'll get back to you within one business day.

We respect your inbox. Your details are used only to reply to your enquiry.