Product / RookHaven

Secure orchestration for remote testing outposts.

RookHaven is a security-hardened Linux production candidate for confidential, accountable penetration-testing operations on encrypted field appliances.

LifecycleAcceptance gated
Use boundaryAuthorized testing
AvailabilityControlled evaluation

What it provides

Remote access with identity, isolation, and review built into the path.

is the central experience for customer administration, licensed Rook enrollment, fleet operations, approvals, recovery, and evidence. The handles routing, policy, and without receiving the per-appliance application key used to open protected operator payloads.

Sensitive terminal and workspace streams leave the browser through a . Their plaintext stays between the operator workstation and the selected Rook, while and Citadel retain attributable lifecycle evidence without recording session content.

The same can identify the appliance before root is mounted, perform an exact , and return after with the same cryptographic identity. This flow has been demonstrated on a physical validation appliance.

RookHaven’s production acceptance baseline requires , , external witnessing and fencing, production exercises, and independent review. Those external controls are deployment gates, not properties inferred from source tests.

CONTROL PATH / PUBLIC MODELOPERATIONAL DETAIL WITHHELD
OperatorPortal + Secure BridgePasskey & attributable action
Control planeRookHaven CitadelPolicy & approval
relay
Field systemRook + ForgeVerified action boundary

This diagram communicates trust boundaries only. It intentionally omits secrets, credentials, ports, sensitive deployment details, and exploitable implementation specifics.

Operator experience

Authority and attention stay visible.

The RookHaven Portal is the role-aware home for product owners, customer administrators, engagement managers, operators, approvers, auditors, and client viewers. It makes each person’s role, permitted scope, limitations, and outstanding responsibilities immediately visible.

Critical actions bind an executor and a different approver to the exact target, purpose, parameters, policy generation, and short validity window. remain individually signed, justified, bounded, and durably audited.

Open the RookHaven Portal
01

Attention Center

Exact pending approvals, acknowledgements, remediation, recovery, enrollment, and security actions route to the affected record.

02

-guided inside an —not on the appliance host.

03

Customer control

Organizations set approval, business-purpose, attestation, HSI, workspace, and recovery policy within non-bypassable product safety boundaries.

04

Phishing-resistant access

Every normal sign-in requires an individual password and an origin-bound, user-verified passkey; privileged onboarding requires independent authenticators.

05

Evidence by default

Review, acknowledgement, approval, denial, resolution, override, and retirement remain distinct and attributable throughout the lifecycle.

06

The is a separately enabled emergency exception, disabled by default and stronger-controlled than routine workspace access.

Control layers

Protection is compositional.

RookHaven is designed so that no single label stands in for the complete security model. Controls have defined roles and deployment dependencies.

01Identity

Unique and individually attributable operator signatures

02Transport

and

03Authority

Time-limited authorization and

04Evidence

Durable and

Delivery status

Reviewed source and signed production generations move together.

Implemented

Portal-first tenant administration, licensed enrollment, exact approvals, Forge lifecycle, Secure Bridge handoff, recovery, and audit workflows are covered by automated, adversarial, integration, and controlled physical evidence.

Physically demonstrated

, , remote unlock, , and an audited root-terminal round trip.

Deployment qualified

Each production deployment is accepted against its exact hardware, operator custody, , recovery procedures, assessment scope, and independently reviewed risk record.

Product family

A common language across the operating model.

These names describe implemented binaries, services, workflows, or functional areas delivered through the RookHaven platform. Packaging, licensing, and support scope are defined by the applicable deployment agreement.

01

RookHaven Portal

Customer administration and operator control center

02

RookHaven Citadel

03

RookHaven Rook

Split transport and privileged field runtime

04

RookHaven Secure Bridge

Local end-to-end session and FIDO handoff

05

RookHaven Forge

Disposable, constrained penetration-testing workspace

06

RookHaven Vault

07

RookHaven Sentinel

Guided production acceptance and evidence verification

Operating assurance

Security strength continues after deployment.

Validated hardware, , operator accountability, network controls, continuous monitoring, and controlled maintenance preserve the RookHaven security baseline throughout the deployment lifecycle.

Review the assurance model