ZeroPulse · Windows desktop companion

ApexHawk Sentinel

Your Network. Your Control. Your Sentinel.

A mechanical hawk that perches on your desktop and routes your traffic through the proxy, rotating gateway or Tor egress you choose. Every masked IP and every rotation is independently verified before the Sentinel reports it — and if the route fails, it says so.

  • Alt+T instant toggle
  • Verified 5–10 min rotation
  • Fail-closed by default
  • Local webhook radar

Capabilities

A companion that never fakes a green light

ApexHawk doesn't sell you IPs. It drives the egress you already have — and holds it to account.

Verified masking

Press Alt+T. The Sentinel routes through your egress, then asks independent IP services what they see. It turns green only when the public IP is confirmed different from your own.

Autonomous rotation

A single scheduler hops your egress at random 5–10 minute intervals. A rotation counts only when a new IP is verified — same-IP results are flagged, never celebrated.

Fail-closed protection

If the egress drops, proxied traffic is blocked instead of silently going direct. Health checks, failover and bounded recovery run in the background; Alt+T always restores your normal connection.

Webhook radar

Point Stripe, GitHub or Clerk webhooks at your dev port + 10. The Sentinel lunges and screeches, checks the signature, and forwards the request untouched to your server on 3000, 5173, 8000 or 8080.

Perch & flight

Double-click to lock the perch. Triple-click for flight mode and drag it anywhere — across monitors, at any DPI. It stays above your apps without stealing keyboard focus.

A real mecha rig

A procedural Three.js raptor with saccadic gaze, hydraulic respiration, twin thrusters and holographic reticles — every animation is driven by what the network is actually doing.

Meet the Sentinel

Every mood is a network state

The same model and animation code that ships in the desktop app. Try each state below.

198.51.100.24 ALT+T TO MASK
Demonstration

Idle

Cyan optics, slow hydraulic breathing, head tracking your cursor. The dock pill shows your verified direct IP.

This is a demonstration running in your browser. It does not touch your network, and the IPs shown are reserved documentation addresses (RFC 5737). Real masking happens only in the Windows app.

How it works

Trust, but verify — every single hop

  1. 01

    Bring your egress

    Add a proxy pool, a rotating gateway with per-session credentials, or a local Tor client. Credentials are encrypted with Windows DPAPI.

  2. 02

    Press Alt+T

    ApexHawk starts a loopback proxy, connects to a candidate exit, and points your Windows proxy setting at it — snapshotting the old one first.

  3. 03

    Verify independently

    At least two public IP services must see an address that differs from your direct IP, measured through the exact path your traffic takes.

  4. 04

    Rotate or report

    Every 5–10 minutes it requests a new exit. New verified IP → rotation complete. Same IP or failure → degraded, retried with backoff, never faked.

Browser & appsWindows proxy setting ApexHawk proxy127.0.0.1 · fail-closed Your egresspool · gateway · Tor Internetsees the egress IP independent IP verification ≥ 2 services · must differ from direct IP
Masked traffic path. DNS for proxied sites is resolved at the egress, not on your PC.

✓ Routed through your egress

  • Edge, Chrome and Firefox (system proxy)
  • Most apps that honor Windows proxy settings
  • HTTPS, WebSockets and HTTP over TCP
  • DNS lookups for proxied sites

— Not covered — by design

  • Apps that ignore system proxy settings
  • UDP traffic, including some WebRTC
  • Local network & localhost (bypassed)
  • It's a proxy controller, not a full-tunnel VPN

Download

Deploy ApexHawk Sentinel

Windows 10 & 11 · 64-bit. Installs per user — no administrator rights required.

Verify your download

Compare the SHA-256 above with PowerShell:

Get-FileHash .\ApexHawk-Sentinel-Setup-1.1.0.exe -Algorithm SHA256

Unsigned build

This release is not code-signed, so Windows SmartScreen may show “Windows protected your PC”. Choose More info → Run anyway only after verifying the checksum.

First run

Right-click the hawk → Network & Webhook Settings… to add your egress, then Reload Settings and press Alt+T.

FAQ

Straight answers

Does ApexHawk give me IP addresses or a VPN service?

No. ApexHawk controls and verifies an egress you already have the right to use: a list of proxies, a rotating proxy gateway, or a Tor client running on your PC. Without one configured, pressing Alt+T shows a clear “no egress configured” error rather than pretending.

How do I know it's really masked?

Before the Sentinel turns green, at least two independent public IP services are queried through the same route your browser uses. The observed IP must differ from your direct IP. The dock pill shows that verified address — never a guess, a hostname or a random number.

What happens when a rotation doesn't change my IP?

It's reported as “provider returned the same IP”, the previous verified egress is kept, and the retry backs off (1, 2, 4… minutes). The Sentinel turns amber instead of claiming success.

What if my proxy dies while I'm masked?

By default ApexHawk fails closed: proxied traffic is blocked rather than leaking out of your real connection, and recovery is attempted automatically. Press Alt+T at any time to restore your normal connection. You can switch to fail-open in settings.

Will it leave my Windows proxy settings broken?

No. ApexHawk snapshots your settings before changing them and restores them when you disengage or quit. If the app is killed or the PC loses power, the snapshot is restored on the next launch.

How does the webhook radar work with my dev server?

Your dev server keeps its port. ApexHawk listens on port + 10 (3010 → 3000, 5183 → 5173, 8010 → 8000, 8090 → 8080), reacts to Stripe, GitHub and Clerk webhooks, optionally verifies their signatures with your secrets, and forwards every request unchanged. It only listens on 127.0.0.1.

Does this website change my network?

No. The Meet the Sentinel controls are an in-browser animation demo. Nothing on this site talks to your network settings.

What does the app send, and to whom?

Only what's needed to do its job: connections through your configured egress, and IP checks to public services (ipify, icanhazip, Cloudflare, AWS, ifconfig.me). There is no telemetry, account or analytics in the app.