HeartSuite Firewall

A closed appliance that watches real traffic on this box, lets you approve a finite allowlist, and seals it. Prototype documentation.

HeartSuite Firewall | Prototype


Prototype: HeartSuite Firewall is under active development. Documentation reflects current design intent and is subject to change.

Overview: An inbound port that nobody approved is open by default. HeartSuite Firewall is the packet filter for traffic to and from a closed HeartSuite appliance: you observe real traffic, approve a finite allowlist, and seal it. The workload runs on the appliance image itself, and the filter judges packets by connection state.

Root Lock by HeartSuite is the hardened operating system under the filter, so execution, file access, and per-program outbound destinations stay under Root Lock’s control.

If execution control or per-program outbound allowlisting on an existing server is the requirement, stay with Root Lock and the OS or cloud inbound control already on that host. See Deployment scenarios for fit by environment.

Learn about HeartSuite Firewall

  • Introduction and overview — Core concepts, the inbound and host-path problem, and how HeartSuite Firewall differs from Root Lock.
  • Architecture and compatibility — Closed image, Linux netfilter on the nft path, and what sits under the filter.
  • Deployment scenarios — Where the appliance fits, where it fits alongside Root Lock, and where a campus NGFW still belongs.
  • How HeartSuite Firewall compares — Host-shaped sealed allowlist versus campus NGFW blades, and the complementary tools for each gap.
  • Recent firewall campaigns — What Cisco and Fortinet incidents in 2024–2026 depended on, and which of those surfaces stay off this appliance.
  • Roadmap — Current prototype scope and planned development.

About this documentation

Covers the HeartSuite Firewall prototype. Root Lock remains the shipped kernel product, and what the Root Lock pages say about inbound traffic still applies to it.


Inbound default-accept is the other Unix inheritance

Root Lock allowlists per-program outbound. HeartSuite Firewall is the host-path stateful filter for a closed appliance.

Where a host-shaped firewall belongs

When HeartSuite Firewall fits, when it sits beside Root Lock, and when a campus NGFW is still the right box for the edge.

What sits under a closed firewall image

HeartSuite Firewall is a closed image: a stateful host filter on Linux netfilter (nft). What is in the box.

What Cisco and Fortinet incidents needed to exist

2024–2026 Cisco and Fortinet campaigns depended on management planes and extra services. HeartSuite Firewall is designed without those surfaces.

A sealed host filter beside a campus NGFW

What HeartSuite Firewall is, what it complements, and why it sits beside a campus NGFW rather than replacing one.

What the firewall prototype covers today

Current HeartSuite Firewall prototype scope and the development work still ahead.


Last modified September 27, 2026: update (8e42cfd)