Verified masking
Press Alt+T. The Sentinel routes through your egress, then asks independent IP services what they see. It turns green only when the public IP is confirmed different from your own.
ZeroPulse · Windows desktop companion
Your Network. Your Control. Your Sentinel.
A mechanical hawk that perches on your desktop and routes your traffic through the proxy, rotating gateway or Tor egress you choose. Every masked IP and every rotation is independently verified before the Sentinel reports it — and if the route fails, it says so.
Capabilities
ApexHawk doesn't sell you IPs. It drives the egress you already have — and holds it to account.
Press Alt+T. The Sentinel routes through your egress, then asks independent IP services what they see. It turns green only when the public IP is confirmed different from your own.
A single scheduler hops your egress at random 5–10 minute intervals. A rotation counts only when a new IP is verified — same-IP results are flagged, never celebrated.
If the egress drops, proxied traffic is blocked instead of silently going direct. Health checks, failover and bounded recovery run in the background; Alt+T always restores your normal connection.
Point Stripe, GitHub or Clerk webhooks at your dev port + 10. The Sentinel lunges and screeches, checks the signature, and forwards the request untouched to your server on 3000, 5173, 8000 or 8080.
Double-click to lock the perch. Triple-click for flight mode and drag it anywhere — across monitors, at any DPI. It stays above your apps without stealing keyboard focus.
A procedural Three.js raptor with saccadic gaze, hydraulic respiration, twin thrusters and holographic reticles — every animation is driven by what the network is actually doing.
Meet the Sentinel
The same model and animation code that ships in the desktop app. Try each state below.
Cyan optics, slow hydraulic breathing, head tracking your cursor. The dock pill shows your verified direct IP.
This is a demonstration running in your browser. It does not touch your network, and the IPs shown are reserved documentation addresses (RFC 5737). Real masking happens only in the Windows app.
How it works
Add a proxy pool, a rotating gateway with per-session credentials, or a local Tor client. Credentials are encrypted with Windows DPAPI.
ApexHawk starts a loopback proxy, connects to a candidate exit, and points your Windows proxy setting at it — snapshotting the old one first.
At least two public IP services must see an address that differs from your direct IP, measured through the exact path your traffic takes.
Every 5–10 minutes it requests a new exit. New verified IP → rotation complete. Same IP or failure → degraded, retried with backoff, never faked.
Download
Windows 10 & 11 · 64-bit. Installs per user — no administrator rights required.
Compare the SHA-256 above with PowerShell:
Get-FileHash .\ApexHawk-Sentinel-Setup-1.1.0.exe -Algorithm SHA256
This release is not code-signed, so Windows SmartScreen may show “Windows protected your PC”. Choose More info → Run anyway only after verifying the checksum.
Right-click the hawk → Network & Webhook Settings… to add your egress, then Reload Settings and press Alt+T.
FAQ
No. ApexHawk controls and verifies an egress you already have the right to use: a list of proxies, a rotating proxy gateway, or a Tor client running on your PC. Without one configured, pressing Alt+T shows a clear “no egress configured” error rather than pretending.
Before the Sentinel turns green, at least two independent public IP services are queried through the same route your browser uses. The observed IP must differ from your direct IP. The dock pill shows that verified address — never a guess, a hostname or a random number.
It's reported as “provider returned the same IP”, the previous verified egress is kept, and the retry backs off (1, 2, 4… minutes). The Sentinel turns amber instead of claiming success.
By default ApexHawk fails closed: proxied traffic is blocked rather than leaking out of your real connection, and recovery is attempted automatically. Press Alt+T at any time to restore your normal connection. You can switch to fail-open in settings.
No. ApexHawk snapshots your settings before changing them and restores them when you disengage or quit. If the app is killed or the PC loses power, the snapshot is restored on the next launch.
Your dev server keeps its port. ApexHawk listens on port + 10 (3010 → 3000, 5183 → 5173, 8010 → 8000, 8090 → 8080), reacts to Stripe, GitHub and Clerk webhooks, optionally verifies their signatures with your secrets, and forwards every request unchanged. It only listens on 127.0.0.1.
No. The Meet the Sentinel controls are an in-browser animation demo. Nothing on this site talks to your network settings.
Only what's needed to do its job: connections through your configured egress, and IP checks to public services (ipify, icanhazip, Cloudflare, AWS, ifconfig.me). There is no telemetry, account or analytics in the app.