# HeartSuite product documentation

> Root Lock by HeartSuite is kernel default-deny for programs, files, and outbound network, including as root. Unsealing Lockdown takes the maintenance kernel from a physical or serial console. sshd is stopped when Lockdown seals, unless you chose to leave it running before the seal, and SSH cannot lift the seal. After unseal, SSH is how you work in Setup Mode.

---

LLMS index: [llms.txt](/llms.txt)

---

This site is the documentation for HeartSuite products. Each product has its own section.

- [Root Lock by HeartSuite](rootlock/) — Kernel-level default-deny for programs, files, and outbound network. Start here.

Prototypes:

- [HeartSuite Firewall](firewall/) — Prototype. Inbound and host-path filter for a closed HeartSuite appliance.
- [HeartSuite Joint File System (HJFS)](hjfs/) — Prototype. Per-program file isolation on a standard unmodified kernel.
- [HeartSuite Exec](exec-lock/) — Prototype. HJFS UI for program install, update, and version selection.

The [Root Lock documentation](rootlock/) is the main product guide: overview, install, allowlisting, and Lockdown.

For support email support@heartsecsuite.com.

---

Section pages:

- [Root Lock by HeartSuite Documentation](/rootlock/): Complete guide for installing and configuring Root Lock by HeartSuite.
- [Blog](/blog/): Root Lock by HeartSuite notes on incidents, deployment, and kernel default-deny.
- [HeartSuite Exec](/exec-lock/): HeartSuite Exec is the planned HJFS interface for installing, updating, and selecting program versions. Kernel-level program and network control stays with Root Lock.
- [HeartSuite Firewall](/firewall/): A closed appliance that watches real traffic on this box, lets you approve a finite allowlist, and seals it. Prototype documentation.
- [HeartSuite Joint File System](/hjfs/): HJFS gives each program its own files. A word processor can no longer open every document you own. Prototype documentation.
