Halonex // Execution control
Trust policy · default deny
Refused
0047
Verified
0012
00Why Halonex
We remove the path instead. That is a different conversation with a board than another percentage point of detection rate, and it is the only claim on this page that the rest of it exists to support.
01The difference
Every item below is a consequence of choosing a boundary over a classifier. None of them is a feature bolted on afterwards.
i
A detection tool has to recognise an attack to stop it, which is why novel ones get through. A boundary does not, which is why the boundary is where the engineering went.
ii
Each process runs inside its own virtualised environment. A compromise stays in the box it started in — no neighbour to reach, no host to pivot onto.
iii
Policy is applied at the deepest hardware privilege level, before an instruction is permitted to run, rather than evaluated after it already has.
iv
Indicators from 200+ feeds are normalised, enriched and matched to your assets, so what reaches an analyst is the subset with a path to something you own.
v
Isolation sits below the layer people interact with. Applications behave normally, and nobody files a ticket asking why their machine got slower.
vi
Engine, telemetry pipeline and Argon hosting are built and operated in India. Nothing crosses a border because of where a vendor happened to put its region.
02Who it is for
The enforcement layer does not change between these. What changes is how much of it you run, and who operates it.
Your credentials are already sitting in someone’s dataset. Checking them should not cost money or require an account, so with us it does neither.
You do not have eighteen months to rebuild customer trust, and you do not have a security team to spare. Kernel enforcement that runs without one.
Your adversaries rehearse. Process isolation across the fleet, plus agents that attack your own stack continuously so the rehearsal happens on your side too.
Citizen data should not transit infrastructure you cannot audit. Deploy on your own hardware, inside your own jurisdiction, with no telemetry leaving it.
03Figures
No adoption counts, no efficacy percentages, no customer logos. Everything here is something we can produce a number for, and there is nothing else.
0
Systems in production
0+
Intelligence feeds aggregated
0B+
Credential records indexed
Ring 0
Enforcement depth
<0s
Asset isolation time
India
Built and hosted in
04Standards
These are formats and frameworks the products interoperate with. They are not certifications, and we do not hold any.
Findings mapped to tactics and techniques
Threat feed interchange
Severity scoring
05Limits
Worth reading before a trial, because these are the questions that otherwise surface in month three. A vendor who cannot answer them has not thought about the failure modes.
Process isolation stops code from reaching what it has no route to. It does not stop somebody typing their password into a convincing page — that is what the browser layer and credential monitoring are for.
A device that has stopped checking in is not the same as a device that is protected. Until it reports we say we cannot tell the difference, rather than showing a green tick.
Not appearing on a threat list is not an assertion that something is safe. It means nobody has listed it yet, and the product reports it that way.
An agent on a build that predates a reporting feature says nothing either way about that feature. We would rather show a gap than infer a result from one.
06Next
Not a scripted demo on our hardware. Bring the estate you would rather not think about and we will show you where the enforcement points land, what breaks in observe mode, and what the first ninety days look like.