Attention Center
Exact pending approvals, acknowledgements, remediation, recovery, enrollment, and security actions route to the affected record.
Product / RookHaven
RookHaven is a security-hardened Linux production candidate for confidential, accountable penetration-testing operations on encrypted field appliances.

What it provides
is the central experience for customer administration, licensed Rook enrollment, fleet operations, approvals, recovery, and evidence. The handles routing, policy, and without receiving the per-appliance application key used to open protected operator payloads.
Sensitive terminal and workspace streams leave the browser through a . Their plaintext stays between the operator workstation and the selected Rook, while and Citadel retain attributable lifecycle evidence without recording session content.
The same can identify the appliance before root is mounted, perform an exact , and return after with the same cryptographic identity. This flow has been demonstrated on a physical validation appliance.
RookHaven’s production acceptance baseline requires , , external witnessing and fencing, production exercises, and independent review. Those external controls are deployment gates, not properties inferred from source tests.
This diagram communicates trust boundaries only. It intentionally omits secrets, credentials, ports, sensitive deployment details, and exploitable implementation specifics.
Operator experience
The RookHaven Portal is the role-aware home for product owners, customer administrators, engagement managers, operators, approvers, auditors, and client viewers. It makes each person’s role, permitted scope, limitations, and outstanding responsibilities immediately visible.
Critical actions bind an executor and a different approver to the exact target, purpose, parameters, policy generation, and short validity window. remain individually signed, justified, bounded, and durably audited.
Open the RookHaven PortalExact pending approvals, acknowledgements, remediation, recovery, enrollment, and security actions route to the affected record.
-guided inside an —not on the appliance host.
Organizations set approval, business-purpose, attestation, HSI, workspace, and recovery policy within non-bypassable product safety boundaries.
Every normal sign-in requires an individual password and an origin-bound, user-verified passkey; privileged onboarding requires independent authenticators.
Review, acknowledgement, approval, denial, resolution, override, and retirement remain distinct and attributable throughout the lifecycle.
The is a separately enabled emergency exception, disabled by default and stronger-controlled than routine workspace access.
Control layers
RookHaven is designed so that no single label stands in for the complete security model. Controls have defined roles and deployment dependencies.
Delivery status
Portal-first tenant administration, licensed enrollment, exact approvals, Forge lifecycle, Secure Bridge handoff, recovery, and audit workflows are covered by automated, adversarial, integration, and controlled physical evidence.
, , remote unlock, , and an audited root-terminal round trip.
Each production deployment is accepted against its exact hardware, operator custody, , recovery procedures, assessment scope, and independently reviewed risk record.
Product family
These names describe implemented binaries, services, workflows, or functional areas delivered through the RookHaven platform. Packaging, licensing, and support scope are defined by the applicable deployment agreement.
Customer administration and operator control center
Split transport and privileged field runtime
Local end-to-end session and FIDO handoff
Disposable, constrained penetration-testing workspace
Guided production acceptance and evidence verification
Operating assurance
Validated hardware, , operator accountability, network controls, continuous monitoring, and controlled maintenance preserve the RookHaven security baseline throughout the deployment lifecycle.
Review the assurance model