HeartSuite Joint File System

HJFS gives each program its own files. A word processor can no longer open every document you own. Prototype documentation.

HeartSuite Joint File System | Prototype


Prototype: HJFS is under active development. Documentation reflects current design intent and is subject to change.

Overview: Every program you run gets full access to your files by default, including malware. HeartSuite Joint File System (HJFS) changes this at the filesystem layer.

Each program has its own storage area. No other program can read or write its files, including programs running as root. File isolation is per program and per version. No custom kernel is required.

Which programs run and which network connections they open stay with Root Lock by HeartSuite. On a Root Lock kernel, both can share the host. HJFS also runs on a standard unmodified kernel.

If execution or network control is the primary requirement, see Deployment scenarios — that job is Root Lock (or existing host controls on a stock kernel).

See it in action

Learn about HJFS

  • Introduction and overview — Core concepts, design goals, and how HJFS differs from traditional file permission models.
  • Architecture and compatibility — Technical implementation, OS support, and application compatibility notes.
  • Advanced protection — An optional level that adds system-managed file dialogs and separates internal from user files, requiring application updates.
  • Deployment scenarios — Where HJFS fits, where it sits beside Root Lock, and where another control owns the workload.
  • How HJFS compares — What HJFS isolates, what it complements, and when to run it alone versus beside Root Lock.
  • Attack examples — How HJFS is designed to confine a separate encryptor or a tainted version, and the residual when a program hurts files it already owns.
  • Roadmap — Current prototype scope and planned development.

About this documentation

Covers HeartSuite Joint File System prototype.


The OS still treats every program as you

File permissions are granted to users, not programs. HJFS isolates each program’s files on a stock kernel. Start here for the prototype.

Where per-program file isolation fits

When HJFS alone is enough, when it should sit beside Root Lock, and when a different control is the right one for the workload.

HJFS on a stock kernel

How HJFS isolates files without replacing the kernel, which operating systems it targets, and how the prototype sits on the host filesystem.

The OS holds the file dialog, not the program

Advanced HJFS: separate internal and user files, OS-mediated dialogs, and export/import — so programs never hold custody of your documents.

When ransomware cannot reach another program's files

How HJFS is designed to contain a separate ransomware binary or a tainted update’s files, and the residual when a program hurts files it already owns.

What HJFS isolates — and what it complements

Per-program file isolation on a stock kernel, the tools that own execution and network, and when to run HJFS alone versus beside Root Lock by HeartSuite.

What the HJFS prototype covers today

Current HeartSuite Joint File System prototype scope, what the first cut includes, and what is planned next.