FireSecurity · FireSec
Early Access · pre-1.0 product

The license expires. The network keeps running.

FireSecurity is one panel for firewall, NAT, multi-WAN, WireGuard VPN, monitoring, logs and inventory. Uzbek, Russian and English, priced in som, data stays in country. You can try it against your real traffic in shadow mode without touching the network you already run.

One administrator, ten tools

In a mid-sized organization one or two people run the network, and the budget does not stretch to subscriptions priced in foreign currency. The toolset assembles itself.

How it looks today

Kerio Control or pfSense/OPNsense, Zabbix or Grafana on top, Graylog for logs, Nginx Proxy Manager for publishing, Wazuh for security — each with its own install, its own login and its own upgrade cycle.

The real competitor is the free OSS stack

It costs nothing to license and administrators already know it. But the cost is not in the license: disconnected events, no warranty or SLA, manual work on every upgrade, and a single person who holds it together. That is where TCO grows.

What changes

One install, one login, connected events: a rule change, its log, the audit entry and the inventory in one place. Your existing firewall configuration is imported, cutover follows a runbook, and rollback is part of that runbook.

Modules, and when each ships

Taken from the roadmap. A module that has not shipped is not shown as available — the release it arrives in is stated next to it.

ModuleReleaseWhat it does
Firewall Core, NAT1.0Zones, rules, NAT; the rule set is replaced atomically
Multi-WAN1.0Several uplinks, health probes, automatic failover
WireGuard VPN1.0Site-to-site tunnels
Monitoring, metrics, dashboards1.0Node and interface state, uptime
Logs and search1.0Verdict logs and external syslog, search and aggregation
Inventory1.0The devices on your network
Proxy Manager, fsctl CLI1.0Reverse proxy; every panel action exists in the terminal too
Identity, NAC (monitor), DNS, DHCP, IPAM1.0 (Pro)Users, access control, address management
IPS (Suricata-based)1.0 (Pro)Attack detection
Server Manager, certificates, reports1.0 (Pro)Servers and PKI work
PKI base, gateway HA, eBGP base1.0 (Enterprise)High availability and routing
WAF (Coraza), config backup1.1Web application protection
Remote access, password vault, NAC closed1.2Access from outside, and secrets
TLS Inspect1.3Inspecting encrypted traffic
ZTNA, MFA Server, JIT Access, SIEM correlation2.0Zero-trust and SOC foundations
Fleet Manager, sublicensing (MSSP)2.0Many customers from one place

Why a local product

Three languages

Panel and documentation in Uzbek, Russian and English. Support in the same languages.

Priced in som

Contract and payments are not tied to an exchange rate.

Data stays in country

Logs and configuration stay in your installation; the product runs without internet access.

No sanctions exposure

Licensing and updates are local: a foreign vendor's decision cannot stop your network.

Plans

Price on request. During Early Access a discount off list applies, and the move to 1.0 is free.

Start

Small office, branch

Price on request

  • Firewall Core, NAT, multi-WAN
  • WireGuard VPN
  • Monitoring, metrics, dashboards
  • Logs, inventory, uptime
  • Proxy Manager, fsctl
Send a request

Pro

Mid-sized organization, educational institution

Price on request

  • Everything in Start
  • Identity, NAC (monitor), DNS, DHCP, IPAM
  • IPS (Suricata-based)
  • IPv6 dual-stack
  • Server Manager, certificates, reports
Send a request

Enterprise

Bank, large organization, public sector

Price on request

  • Everything in Pro
  • PKI base, gateway HA, eBGP base
  • Four-eyes rule and an action budget
  • 1.1–2.0: WAF, remote access, TLS Inspect, ZTNA, SIEM correlation
Send a request

MSSP

Integrators and service providers

Price on request

  • Enterprise + Fleet Manager
  • Sublicensing and per-customer reporting
  • Monthly billing model
  • From release 2.0
Send a request

In every plan: the notification center (Telegram, email, webhook), the audit log and the rollback log.

Early Access terms

The product is pre-1.0, and we do not hide it: selling a security product on full commercial terms before an independent review would be the wrong thing to do, so the terms are written out separately.

TermValue
ModulesOnly the modules shipped and proven in a pilot — the list is an annex to the contract
Status"Beta": limitation of liability and warranty disclaimer are stated in the contract
PriceA discount off list; the move to 1.0 is free
SLABest-effort: P1 response within 4 hours, during business hours
SecurityInternal security review done; external penetration test of the gateway and panel is planned, not yet performed

Security and trust

Everything below is in the product and backed by a test. What is not backed by one is not written on this page.

Licensing never stops traffic

An expired license, a missing license file or an unreachable license server do not affect forwarding, NAT, VPN, monitoring or logs. This is the product's first rule.

QA-T-500 — sabotage test, release gate

Atomic rule replacement

New rules are applied in a single transaction — there is no half-applied state. The product never touches another program's firewall rules on the host.

nft -c check plus golden files, in the gate

Commit-confirm and automatic rollback

Every change is applied with a confirmation window: without confirmation the node returns to its previous state by itself. Even if you lock yourself out, the network comes back.

measured in a netns lab, in the gate

Audit and rollback logs

Who changed what, and when, in a hash-chained audit log. A rolled-back revision records its reason too.

chain integrity test, in the gate

Shadow mode

A new policy first runs in observation mode: you get a "what would have been blocked" report while traffic is untouched. Cutover comes after that.

shadow report in the product

Vulnerability reporting

The product serves /.well-known/security.txt (RFC 9116), so a researcher who finds a flaw knows who to write to.

RFC 9116, in the product

What we do not promise. There are no throughput numbers on this page (such as "1 Gbit/s"): they have so far been measured only in a virtual environment with no physical network card, which makes them a target rather than a measurement. The product is not certified and has not been through an independent penetration test. Reference-hardware measurements and an external pentest are on the roadmap.

Frequently asked questions

What happens when the license expires?

Traffic keeps flowing. Forwarding, NAT, VPN, monitoring and logs do not depend on license state — licensing limits panel capabilities only. The rule is guarded by a sabotage test that runs in every release.

How do we migrate from our existing firewall?

The old device's configuration is imported and you get a report: what migrated, what did not, and why. Then shadow mode shows what would have been blocked without touching traffic. Cutover follows a runbook; the way back is in that same runbook and has been measured in the lab.

What hardware do we need?

For a small office, an x86-64 server in the 4-core / 8 GB RAM / SSD class; for a mid-sized organization, 8 cores / 16 GB. Exact throughput figures are not published until they have been measured on reference hardware.

How does a pilot run?

One organization, one site, one gateway. Install and shadow mode first, then an observation period, then cutover and a rollback drill. What it takes: real traffic, an export from the old device, and a window for the cutover.

Does it work without internet access?

Yes. Installation, licensing and updates can all be done offline; logs and configuration never leave your installation.

Request a demo

There is no form on this site — your message reaches us directly, and there is no button that falsely claims "sent". Tell us your organization, the size of your network and the firewall you run today.