Halonex // Execution control
Trust policy · default deny
Refused
0047
Verified
0011
00About
Kernel enforcement, process isolation, automated containment. For two decades this layer was licensed from somewhere else, and a country that licenses it inherits every assumption inside it. We started in Tirunelveli on the premise that it had to be built here instead.
Registered
Halonex Labs Private Limited
Founded
June 2025
Head office
Tirunelveli, Tamil Nadu
Entities
Halonex · ZMatrix · Zenosec
01The argument
Most of the industry is trying to raise a detection rate. We think that is the wrong number to be optimising, and the reasoning is short enough to check.
i
A signature engine has to have seen something like the attack before. A behavioural model has to have been trained on something like it. Both ask the same question — does this resemble a thing we already know? — and a genuinely novel intrusion is defined by the answer being no.
ii
An exploit nobody has published still cannot reach a kernel it has no route to. Each process runs inside its own virtualised environment with policy applied at ring 0, before an instruction is permitted to run. The boundary does not need to know what it is holding back.
iii
Isolation sits below the layer people interact with, so applications behave normally. What changes is that a compromise stays inside the box it started in — and the daily work becomes reading containment logs rather than working an alert queue.
02The group
Halonex Labs operates as three entities. Research becomes product, product meets the field, and what the field learns goes back into research.
01
Research & platform
The lab, and the layer everything else stands on. Original research into how intrusions are actually constructed, turned into the isolation engine the products ship against. Engine, telemetry pipeline and the Argon hosting layer are built and run here.
02
Enterprise platform
Research turned into shipping software. One correlation engine across the desktop somebody works on, the fleet you run, and the handset in their pocket — so a decision made in one layer becomes enforcement in the others.
03
Infrastructure research
The Center for Advanced Cybersecurity Research. Exposed ports and services found and closed before anyone reaches them, with detection and response collapsed into a single loop and every action written to a signed audit log.
03What we ship
Nothing on this page is a roadmap item. Each of these has a live property you can open from here.
Enterprise
Personal
Intelligence
04Where it runs
The engine, the telemetry pipeline and the Argon hosting layer are built and operated in India. Nothing crosses a border because of where a vendor happened to put its region.
i
For government and defence work we will run entirely on infrastructure you control — air-gapped, with no telemetry leaving your jurisdiction and no foreign vendor anywhere in the trust chain.
ii
For the systems nobody is allowed to touch. It wraps a legacy box in a modern enforcement boundary from the outside — without patching it, recompiling it, or changing a line of what runs inside. The vendor contract stays intact.
05Recognition
We hold no security certifications and we do not publish customer names. What follows is the whole list of external recognition, and each item can be checked.
Recognised startup
Department for Promotion of Industry and Internal Trade, Government of India.
Inception member
Selected into NVIDIA’s programme for companies building on accelerated computing.
Research MoU
A working agreement on isolation primitives, and a hiring pipeline out of the department. Students ship code that reaches the engine.
06People
Dominic Walter T
Founder
Vijay J
Co-founder
Denis Walter T
Director
Sweety Nirmala R
Director
Founded by an IIT Madras dropout and an Anna University CS engineer. The head office and research lab are in Tirunelveli. We did not move to Bengaluru, and the work has not suffered for it.
07Timeline
Jun 2025
Started in Tirunelveli on the premise that the enforcement layer had to be built here rather than licensed.
Aug 2025
The browser layer ships: malicious hosts, phishing kits and drive-by downloads stopped before the page draws.
Sep 2025
A free credential check against the breach corpus, hashed client-side, with nothing retained after the answer.
Mar 2026
A formal research agreement covering joint work on isolation primitives.
May 2026
The process isolation and ring 0 enforcement engine enters active development — the component the rest sits on.
Jun 2026
The telemetry pipeline behind the threat map runs continuously and streams publicly rather than sitting behind a login.
Tell us what you run and which part of it you would rather not think about. We will show you where the enforcement points land and what the first ninety days look like.