Your network trusts every device on it. Terrain Secure doesn't.

The cameras, printers, access readers, room displays and sensors in a company run software nobody audits. Terrain Secure is a firewall for them: it puts them in a segment of their own, limits what each one can reach, and shows you what it actually did, with the evidence next to it.

Verdict2 min ago
2 devices to look at
  • Reception camera Odd Since yesterday it contacts the same server every 5 minutes, on the dot. Never once in its previous 7 days. See the evidenceCut its internet
  • New device New Asked for an address 5 min ago. In quarantine: it has DNS, but goes nowhere until you approve it.
  • Meeting room 3 display In order
  • Temperature sensor, storeroom No data
Illustration · invented data

The devices nobody audits sit on the same network as everything else.

A camera, a badge reader or the controller a vendor left behind joins the network and often reaches whatever an office laptop reaches: the servers, the router's admin page, every other device. Nobody asks what firmware it runs, who updates it, or who it talks to.

From the outside, you can't tell one that behaves from one that doesn't. Both work. The difference is in the traffic: where it connects, how often, how much it uploads, whether it tries to reach other devices on the network.

So the question isn't which one to unplug. It's what each one is allowed to reach, and how you'd find out if that changed.

Contain first. Then watch.

It doesn't try to guess which device is bad before acting. Everything you can't vouch for goes into the contained segment from day one, and the rules apply whether it behaves or not.

The segment is the idea; how devices reach it is part of the installation. Today it runs as a pilot on one site.

A segment of its own

A separate network and subnet, with isolation between devices: a contained device can't reach your computers, the router's admin page, or the other devices in its own segment.

Your DNS, not theirs

Whenever a device asks where a site lives, Terrain Secure answers, locally, even if the device has another one written into its code. The usual ways around it are cut, so the name of every destination stays visible. (Technically: port 53 is redirected, DoT, DoQ and known DoH resolvers are cut, and QUIC falls back to TLS.)

Blocklists, refreshed every day

Malware and command-and-control lists (abuse.ch, Spamhaus DROP, Hagezi) checked against every query and connection. If one fails to download, the previous one stays.

New devices wait at the door

With quarantine on, a device nobody has approved gets an address and DNS but goes nowhere, until you approve it: for good, or for 24 hours.

Limits per device

Speed caps, pauses, schedules, blocked countries and blocked apps, per device or per network, applied without cutting anyone off.

And proof that the walls hold

Every hour, a probe inside the contained segment tries to reach the router, the machine it runs on and the rest of your network. If anything answers that shouldn't, you hear about it.

On top of containment, it watches what each one does.

And it says, in plain words, what is unusual for that particular device, with the evidence next to it: which device, what it did, against which rule, and when.

DNS

  • Names on a blocklist
  • Names that look machine-generated (DGA)
  • Data hidden in long subdomains (tunnels)
  • Attempts to use encrypted DNS elsewhere

Traffic

  • The residential-proxy shape: uploads nearly as much as it downloads, to many destinations
  • Contact at regular intervals (beaconing)
  • Scans toward your network or the internet
  • Connections to known command-and-control IPs

Each device's own baseline

  • Ports, countries, how much it uploads and how it introduces itself when encrypting (JA4 fingerprint), against its own previous 7 days
  • Warns only where the device is predictable: one that always talks to the same two servers yes, a laptop roaming the internet no

Intrusion detection

  • Suricata listening on the contained segment, passively
  • Doors left open on each device: remote-control and debugging ports get flagged (telnet, ADB, TR-069, SMB)

Evidence

  • Packet capture on demand, per device, in standard pcap
  • History stays on the firewall, and any device's history can be erased
  • Hourly detail for 30 days, daily summary for 12 months

Health

  • Internet outages, and whether they were the provider's
  • What couldn't be measured shows grey, "no data", never green
  • A watchdog that brings back whatever fell over, every minute

What it can't do.

A firewall that promises everything is easier to sell and harder to believe. These are its edges.

It doesn't read encrypted traffic.

It sees names, destinations, timing and volume, not content. That is enough to recognise a proxy or a regular heartbeat. It is not enough to know what was said.

It doesn't call a device infected on a hunch.

Deviation warnings start after 48 hours of history, and only where the device is predictable. A phone that roams half the internet won't trigger an alert every day.

It doesn't replace your perimeter firewall.

Nor your router: it sits next to them and covers the devices you put in its segment. Today it runs as a pilot on one site; it has no packaged way to deliver it yet, it doesn't manage several sites, and it isn't sold yet.

It doesn't decide whether a device stays.

A contained device keeps its internet, filtered, until you cut it. It shows you what the device does and the evidence; cutting it, approving it or throwing it out is your call.

Also for home.

The same firewall fits a house: the devices you can't vouch for go into a segment of their own, next to the provider's router, and the rest of the home stays where it was. Same rules, same alerts, same evidence per device.

Same suite as Terrain Report.

Terrain Report audits company networks from the devices themselves and hands over a report where every finding sits next to its evidence. Terrain Secure applies the same rule to the devices you put in its segment: show only what was measured, name the device, put the proof next to it.

Meet Terrain Report

terrainreport

Audits company networks: switches, routers and firewalls, over SSH and without ever writing.

terrain.report
terrainsecure

A firewall for IoT and the devices nobody audits: it contains them and shows what each one does.

You are here

Got devices on your network you can't audit?

Terrain Secure runs today as a pilot on one site, on hardware we chose, and it isn't sold as a product yet. If you want something like it for your company or your home, or you have a device that behaves oddly, tell us about your network.

We reply by email, and tell you plainly whether it fits.

Or write to us: contact@terrain.report