The license expires. The network keeps running.
FireSecurity is one panel for firewall, NAT, multi-WAN, WireGuard VPN, monitoring, logs and inventory. Uzbek, Russian and English, priced in som, data stays in country. You can try it against your real traffic in shadow mode without touching the network you already run.
One administrator, ten tools
In a mid-sized organization one or two people run the network, and the budget does not stretch to subscriptions priced in foreign currency. The toolset assembles itself.
How it looks today
Kerio Control or pfSense/OPNsense, Zabbix or Grafana on top, Graylog for logs, Nginx Proxy Manager for publishing, Wazuh for security — each with its own install, its own login and its own upgrade cycle.
The real competitor is the free OSS stack
It costs nothing to license and administrators already know it. But the cost is not in the license: disconnected events, no warranty or SLA, manual work on every upgrade, and a single person who holds it together. That is where TCO grows.
What changes
One install, one login, connected events: a rule change, its log, the audit entry and the inventory in one place. Your existing firewall configuration is imported, cutover follows a runbook, and rollback is part of that runbook.
Modules, and when each ships
Taken from the roadmap. A module that has not shipped is not shown as available — the release it arrives in is stated next to it.
| Module | Release | What it does |
|---|---|---|
| Firewall Core, NAT | 1.0 | Zones, rules, NAT; the rule set is replaced atomically |
| Multi-WAN | 1.0 | Several uplinks, health probes, automatic failover |
| WireGuard VPN | 1.0 | Site-to-site tunnels |
| Monitoring, metrics, dashboards | 1.0 | Node and interface state, uptime |
| Logs and search | 1.0 | Verdict logs and external syslog, search and aggregation |
| Inventory | 1.0 | The devices on your network |
Proxy Manager, fsctl CLI | 1.0 | Reverse proxy; every panel action exists in the terminal too |
| Identity, NAC (monitor), DNS, DHCP, IPAM | 1.0 (Pro) | Users, access control, address management |
| IPS (Suricata-based) | 1.0 (Pro) | Attack detection |
| Server Manager, certificates, reports | 1.0 (Pro) | Servers and PKI work |
| PKI base, gateway HA, eBGP base | 1.0 (Enterprise) | High availability and routing |
| WAF (Coraza), config backup | 1.1 | Web application protection |
| Remote access, password vault, NAC closed | 1.2 | Access from outside, and secrets |
| TLS Inspect | 1.3 | Inspecting encrypted traffic |
| ZTNA, MFA Server, JIT Access, SIEM correlation | 2.0 | Zero-trust and SOC foundations |
| Fleet Manager, sublicensing (MSSP) | 2.0 | Many customers from one place |
Why a local product
Three languages
Panel and documentation in Uzbek, Russian and English. Support in the same languages.
Priced in som
Contract and payments are not tied to an exchange rate.
Data stays in country
Logs and configuration stay in your installation; the product runs without internet access.
No sanctions exposure
Licensing and updates are local: a foreign vendor's decision cannot stop your network.
Plans
Price on request. During Early Access a discount off list applies, and the move to 1.0 is free.
Start
Small office, branch
Price on request
- Firewall Core, NAT, multi-WAN
- WireGuard VPN
- Monitoring, metrics, dashboards
- Logs, inventory, uptime
- Proxy Manager,
fsctl
Pro
Mid-sized organization, educational institution
Price on request
- Everything in Start
- Identity, NAC (monitor), DNS, DHCP, IPAM
- IPS (Suricata-based)
- IPv6 dual-stack
- Server Manager, certificates, reports
Enterprise
Bank, large organization, public sector
Price on request
- Everything in Pro
- PKI base, gateway HA, eBGP base
- Four-eyes rule and an action budget
- 1.1–2.0: WAF, remote access, TLS Inspect, ZTNA, SIEM correlation
MSSP
Integrators and service providers
Price on request
- Enterprise + Fleet Manager
- Sublicensing and per-customer reporting
- Monthly billing model
- From release 2.0
In every plan: the notification center (Telegram, email, webhook), the audit log and the rollback log.
Early Access terms
The product is pre-1.0, and we do not hide it: selling a security product on full commercial terms before an independent review would be the wrong thing to do, so the terms are written out separately.
| Term | Value |
|---|---|
| Modules | Only the modules shipped and proven in a pilot — the list is an annex to the contract |
| Status | "Beta": limitation of liability and warranty disclaimer are stated in the contract |
| Price | A discount off list; the move to 1.0 is free |
| SLA | Best-effort: P1 response within 4 hours, during business hours |
| Security | Internal security review done; external penetration test of the gateway and panel is planned, not yet performed |
Security and trust
Everything below is in the product and backed by a test. What is not backed by one is not written on this page.
Licensing never stops traffic
An expired license, a missing license file or an unreachable license server do not affect forwarding, NAT, VPN, monitoring or logs. This is the product's first rule.
QA-T-500 — sabotage test, release gate
Atomic rule replacement
New rules are applied in a single transaction — there is no half-applied state. The product never touches another program's firewall rules on the host.
nft -c check plus golden files, in the gate
Commit-confirm and automatic rollback
Every change is applied with a confirmation window: without confirmation the node returns to its previous state by itself. Even if you lock yourself out, the network comes back.
measured in a netns lab, in the gate
Audit and rollback logs
Who changed what, and when, in a hash-chained audit log. A rolled-back revision records its reason too.
chain integrity test, in the gate
Shadow mode
A new policy first runs in observation mode: you get a "what would have been blocked" report while traffic is untouched. Cutover comes after that.
shadow report in the product
Vulnerability reporting
The product serves /.well-known/security.txt (RFC 9116), so a
researcher who finds a flaw knows who to write to.
RFC 9116, in the product
Frequently asked questions
What happens when the license expires?
Traffic keeps flowing. Forwarding, NAT, VPN, monitoring and logs do not depend on license state — licensing limits panel capabilities only. The rule is guarded by a sabotage test that runs in every release.
How do we migrate from our existing firewall?
The old device's configuration is imported and you get a report: what migrated, what did not, and why. Then shadow mode shows what would have been blocked without touching traffic. Cutover follows a runbook; the way back is in that same runbook and has been measured in the lab.
What hardware do we need?
For a small office, an x86-64 server in the 4-core / 8 GB RAM / SSD class; for a mid-sized organization, 8 cores / 16 GB. Exact throughput figures are not published until they have been measured on reference hardware.
How does a pilot run?
One organization, one site, one gateway. Install and shadow mode first, then an observation period, then cutover and a rollback drill. What it takes: real traffic, an export from the old device, and a window for the cutover.
Does it work without internet access?
Yes. Installation, licensing and updates can all be done offline; logs and configuration never leave your installation.
Request a demo
There is no form on this site — your message reaches us directly, and there is no button that falsely claims "sent". Tell us your organization, the size of your network and the firewall you run today.