Halonex // Execution control

Trust policy · default deny

Refused

0048

Verified

0008

Halonex PQC Migration Report — what a routine database migration exposes in transit, and what post-quantum cryptography changes.Get the report

Our Approach

We removed the attack path instead of getting better at spotting it. This page is the argument for that decision, and what it means for a deployment on your estate.

The argument

Why we build the boundary.

Most of the industry is trying to raise a detection rate. We think that is the wrong number to be optimising, and the reasoning is short enough to check.

Detection needs a prior

A signature engine has to have seen something like the attack before. A behavioural model has to have been trained on something like it. Both are asking the same question — does this resemble a thing we already know? — and a genuinely novel intrusion is defined by the answer being no.

A boundary does not

An exploit nobody has published still cannot reach a kernel it has no route to. Each process runs inside its own virtualised environment, enforced at ring 0, so a compromise stays inside the box it started in. The boundary does not need to recognise what it is holding back.

Built where it runs

The engine, the telemetry pipeline and the Argon hosting layer are built and operated in India. For government and defence work we will run entirely on your hardware instead, with no telemetry leaving your jurisdiction and no foreign vendor in the trust chain.

In practice

How a deployment actually goes.

Enforcement that breaks a payroll system gets switched off by Friday, so the sequence matters more than the engine.

01

We look at what you run

Before anything is installed we go through the estate with you — what is on it, what cannot be patched, what nobody is allowed to restart. The systems people are nervous about are usually the ones worth enforcing around first.

02

Enforcement goes on in observe mode

The driver is installed and reports what it would have blocked, without blocking it. This is the part that tells you whether a policy is going to break a line-of-business application, and it is cheaper to learn here than in production.

03

Prevention is switched on, in stages

Enforcement is turned up per group rather than per fleet. Where a rule is refused, the device records why — so a policy that is not actually in force shows up as a finding rather than as a silent assumption.

04

You audit containment instead of triaging alerts

Once the boundary holds, the daily work changes shape. There is a log of what was contained and what was refused, and reading it is a different job from working an alert queue.

Limits

What this does not do.

Worth reading before a trial, because these are the questions that otherwise surface in month three.

Process isolation stops code from reaching what it has no route to. It does not stop a user typing their password into a convincing page — that is what the browser layer and credential monitoring are for.

A device that has stopped checking in is not the same as a device that is protected. Until it reports, we say we cannot tell the difference rather than showing you a green tick.

Absence from a threat blocklist is not an assertion that something is safe. It means nobody has listed it yet, and we report it that way.

An agent running a version that predates a reporting feature says nothing either way about that feature. We would rather show a gap than infer a result.

Bring us the environment that worries you.

Tell us what you run and which part of it you would rather not think about. We will show you where the enforcement points land and what the first ninety days look like.