It doesn't read encrypted traffic.
It sees names, destinations, timing and volume, not content. That is enough to recognise a proxy or a regular heartbeat. It is not enough to know what was said.
The cameras, printers, access readers, room displays and sensors in a company run software nobody audits. Terrain Secure is a firewall for them: it puts them in a segment of their own, limits what each one can reach, and shows you what it actually did, with the evidence next to it.
A camera, a badge reader or the controller a vendor left behind joins the network and often reaches whatever an office laptop reaches: the servers, the router's admin page, every other device. Nobody asks what firmware it runs, who updates it, or who it talks to.
From the outside, you can't tell one that behaves from one that doesn't. Both work. The difference is in the traffic: where it connects, how often, how much it uploads, whether it tries to reach other devices on the network.
So the question isn't which one to unplug. It's what each one is allowed to reach, and how you'd find out if that changed.
It doesn't try to guess which device is bad before acting. Everything you can't vouch for goes into the contained segment from day one, and the rules apply whether it behaves or not.
Forced DNS, blocklists, intrusion detection, caps and quarantine.
A segment of its own. Devices can't see each other.
Stays as it is, untouched.
The segment is the idea; how devices reach it is part of the installation. Today it runs as a pilot on one site.
A separate network and subnet, with isolation between devices: a contained device can't reach your computers, the router's admin page, or the other devices in its own segment.
Whenever a device asks where a site lives, Terrain Secure answers, locally, even if the device has another one written into its code. The usual ways around it are cut, so the name of every destination stays visible. (Technically: port 53 is redirected, DoT, DoQ and known DoH resolvers are cut, and QUIC falls back to TLS.)
Malware and command-and-control lists (abuse.ch, Spamhaus DROP, Hagezi) checked against every query and connection. If one fails to download, the previous one stays.
With quarantine on, a device nobody has approved gets an address and DNS but goes nowhere, until you approve it: for good, or for 24 hours.
Speed caps, pauses, schedules, blocked countries and blocked apps, per device or per network, applied without cutting anyone off.
Every hour, a probe inside the contained segment tries to reach the router, the machine it runs on and the rest of your network. If anything answers that shouldn't, you hear about it.
And it says, in plain words, what is unusual for that particular device, with the evidence next to it: which device, what it did, against which rule, and when.
A firewall that promises everything is easier to sell and harder to believe. These are its edges.
It sees names, destinations, timing and volume, not content. That is enough to recognise a proxy or a regular heartbeat. It is not enough to know what was said.
Deviation warnings start after 48 hours of history, and only where the device is predictable. A phone that roams half the internet won't trigger an alert every day.
Nor your router: it sits next to them and covers the devices you put in its segment. Today it runs as a pilot on one site; it has no packaged way to deliver it yet, it doesn't manage several sites, and it isn't sold yet.
A contained device keeps its internet, filtered, until you cut it. It shows you what the device does and the evidence; cutting it, approving it or throwing it out is your call.
The same firewall fits a house: the devices you can't vouch for go into a segment of their own, next to the provider's router, and the rest of the home stays where it was. Same rules, same alerts, same evidence per device.
Terrain Report audits company networks from the devices themselves and hands over a report where every finding sits next to its evidence. Terrain Secure applies the same rule to the devices you put in its segment: show only what was measured, name the device, put the proof next to it.
Audits company networks: switches, routers and firewalls, over SSH and without ever writing.
terrain.reportA firewall for IoT and the devices nobody audits: it contains them and shows what each one does.
You are hereTerrain Secure runs today as a pilot on one site, on hardware we chose, and it isn't sold as a product yet. If you want something like it for your company or your home, or you have a device that behaves oddly, tell us about your network.
We reply by email, and tell you plainly whether it fits.
Or write to us: [email protected]