Introduction and Overview
Overview of Root Lock by HeartSuite, setup process, and system requirements.
Root Lock by HeartSuite | Humans in Command
Overview: Every attack does three things: run a program, access files, make a network connection. Root Lock by HeartSuite enforces default-deny on all three at the kernel, per program, including as root.
In Lockdown, anything not on the allowlist is blocked before it can act. By design, remote root has no intended path to change the sealed allowlist while the machine is running. Unsealing takes the maintenance kernel from a physical or serial console. Lockdown covers activation. Circumvention and recovery covers residual risk.
On a single host, Root Lock supports two setup paths. Cloud Path and Local Path both arrive at the Dashboard after initial setup.
Pre-installed on AWS, Google Cloud, Azure, DigitalOcean, Linode, and other providers. The Dashboard appears on first login.
Manual installation with a guided setup across several reboots.
Many hosts still install through Cloud Path or Local Path on each machine. Ansible, Terraform, and GitOps apply allowlist policy after that install — see Central Policy.
Root Lock fits production servers, regulated workstations, build and CI infrastructure, and AI agent sandboxes. Shared-kernel container guests, local eBPF tooling, and rootless containers are not a fit by design: the kernel omits overlay filesystems, user namespaces, and the BPF syscall because those are the features attackers use to hide, shadow directories, and reach root. See Deployment Scenarios.
Start with Quick Start — it covers Cloud Path and Local Path and links each step in order: prerequisites, download, install, verify, and allowlist.
The pages below are the individual steps, linked from Quick Start:
Already have a subscription? Follow the Quick Start — the Dashboard guides you from there.
Evaluating? Cloud instances and the Local Path package are available at heartsecsuite.com.
About this Documentation: Covers Root Lock v1.6.4.
Overview of Root Lock by HeartSuite, setup process, and system requirements.
Choose your setup path and begin installation.
Download and installation steps for Root Lock by HeartSuite.
Initial setup checks that you booted the Root Lock kernel and the Dashboard is ready. What complete looks like on cloud and on local.
Linux lets any program run, read any file, and connect anywhere. Root Lock requires an allowlist entry for all three — per program, not per user.
If python3 may use the network, every Python script inherits that. Secure Script Launchers give each script its own allowlist entry.
Outbound connections are allowlisted per program and per address. Approving a destination for curl does not approve it for wget.
In Lockdown a blocked program fails silently unless you set alerts. Email, syslog, and webhook for denied execution, files, and network.
Setup Mode records; Lockdown blocks and seals. The Dashboard checklist, the YES confirmation, the probe reboot, and how Maintenance unseals from the console.
Lockdown requires an active subscription. What the Dashboard shows, how to place and register the subscription file, and what you can still do without one.
Setup Mode logs but stops blocking; the maintenance kernel unloads Root Lock. How to make changes without leaving a hole.
Most failures are a missing allowlist entry, Setup vs Lockdown, or the maintenance kernel. How to tell which, and how to recover.
How Root Lock differs from anti-malware, who it is for, AI agents, containers, VM versus metal install, and what happens when something is blocked.
How Root Lock by HeartSuite scores kernel CVEs: absent surface is 0.0, live paths keep a residual. Catalog and disabled-feature groups are child pages.
Root Lock compiles out the subsystems attackers use to bypass controls. Buyer briefs, scanner hygiene, distro fit, and measured evidence.
How program allowlisting, Lockdown, file versioning, and script launchers were designed as one architecture — and what is still ahead.
CLI tools included with Root Lock by HeartSuite. Which ones the Dashboard runs for you, and which ones you run yourself.
Direct answers for sales, briefings, and customer GRC preparation, with links to the NIST, ISO 27001, and SOC 2 maps.
How Root Lock by HeartSuite maps to NIST CSF 1.1 and ISO 27001:2022 Annex A controls.
AICPA Trust Services Criteria mapped to Root Lock capabilities — for customers preparing a SOC 2 Type I or Type II audit.
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.