Root Lock Firewall

A closed appliance that watches real traffic on this box, lets you approve a finite allowlist, and seals it. Prototype documentation.

Root Lock Firewall | Prototype


Prototype: Root Lock Firewall is under active development. Documentation reflects current design intent and is subject to change.

Overview: An inbound port that nobody approved is open by default. Root Lock Firewall is the host-path packet filter on a closed HeartSuite appliance: observe real traffic, approve a finite allowlist, seal it.

The workload runs on the image. Packets are judged by connection state.

Execution, files, and per-program outbound destinations stay Root Lock by HeartSuite. Root Lock is the hardened operating system under the filter.

If execution control or per-program outbound allowlisting on an existing server is the requirement, stay with Root Lock and the OS or cloud inbound control already on that host. See Deployment scenarios for fit by environment.

Learn about Root Lock Firewall

  • Introduction and overview — Core concepts, the inbound and host-path problem, and how Root Lock Firewall differs from Root Lock.
  • Architecture and compatibility — Closed image, Linux netfilter on the nft path, and what sits under the filter.
  • Deployment scenarios — Where the appliance fits, where it fits alongside Root Lock, and where a campus NGFW still belongs.
  • How Root Lock Firewall compares — Host-shaped sealed allowlist versus campus NGFW blades, and the complementary tools for each gap.
  • Recent firewall campaigns — What Cisco and Fortinet incidents in 2024–2026 depended on, and which of those surfaces stay off this appliance.
  • Roadmap — Current prototype scope and planned development.

About this documentation

Covers Root Lock Firewall prototype. Root Lock remains the shipped kernel product; its inbound language is unchanged.


Inbound default-accept is the other Unix inheritance

Root Lock allowlists per-program outbound. Root Lock Firewall is the host-path stateful filter for a closed appliance.

Where a host-shaped firewall belongs

When Root Lock Firewall fits, when it sits beside Root Lock, and when a campus NGFW is still the right box for the edge.

What sits under a closed firewall image

Root Lock Firewall is a closed image: a stateful host filter on Linux netfilter (nft). What is in the box.

What Cisco and Fortinet incidents needed to exist

2024–2026 Cisco and Fortinet campaigns depended on management planes and extra services. Root Lock Firewall is designed without those surfaces.

A sealed host filter beside a campus NGFW

What Root Lock Firewall is, what it complements, and why it sits beside a campus NGFW rather than replacing one.

What the firewall prototype covers today

Current Root Lock Firewall prototype scope and the development work still ahead.