Edition macOS Linux Sensor

The instant danger strikes,
your Mac
isolates itself.

At home or at a café, from your Wi-Fi perimeter to physical ports — autonomous Mac defense without complex setup. From public Wi-Fi eavesdropping protection to ransomware behavior detection with air-gap isolation and rogue USB guards, all from one menu bar app.

RoamSwitch for Mac: dangers such as untrusted Wi-Fi eavesdropping, port scans, ransomware and malicious USB are detected, and the Mac is automatically isolated. Apple Silicon only, Zero Telemetry, with a Free and a Pro Lifetime plan.
📋 Native Menu Bar & Submenu Preview (AppKit Native)
RoamSwitch menu bar in action (real screenshot)

Instant access to all 18 audit statuses, malware scans, and open port checks right from the menu bar

📊 15-Point Comprehensive Mac Security Report (100/100)
RoamSwitch Mac security diagnostic report (real screenshot)

Detailed status for FileVault, SIP, Gatekeeper, Firewall, ARP spoofing, and system integrity

Use Cases & Scenarios

Why You Need RoamSwitch
Autonomous Defense for Two Kinds of Users

Whether you travel with your MacBook or stay mostly at home or the office, you never have to think about security settings again.

Automatic protection at cafes and public Wi-Fi
☕ Scenario: Cafes & Coworking Spaces

Instant Maximum Lockdown Upon Public Wi-Fi Connection

Public Wi-Fi networks expose your Mac to untrusted devices, putting you at risk of port scanning, unauthorized AirDrop probes, and local file access.

RoamSwitch RoamSwitch Action: Detects unregistered Wi-Fi instantly and applies its Application Firewall lockdown. Drops all unsolicited incoming packets, rendering your Mac completely stealth. (Outbound communication, such as web browsing, continues to work as usual.)
Automatic blocking of dev servers and exposed ports
💻 Scenario: Engineers & Creators Workspace

Prevent Dev Server & Docker 0.0.0.0 Exposure Accidents

Running dev servers (Vite, Next.js, Node, Python, Docker) on 0.0.0.0 on public Wi-Fi exposes your unauthenticated local apps to everyone on the LAN.

RoamSwitch RoamSwitch Action: Passively audits open listening ports and drops unauthorized LAN connections at the kernel layer, keeping your development environment safe.
Safe automatic restore at home and the office
🏢 Scenario: Home & Trusted Office

Seamless Return to Home: Printers & NAS Restored with Zero Effort

In trusted networks, you need smooth access to printers, NAS file servers, and AirDrop. Toggling firewall settings manually is tedious and prone to forgetting.

RoamSwitch RoamSwitch Action: Identifies the router's gateway MAC address and automatically restores standard protection. Enjoy full productivity without friction or manual reconfiguration.
Ransomware detection and air-gap isolation on your home network
🔒 Scenario: Even on a “safe” home network

Trusted network or not, ransomware is a different threat

Ransomware from a phishing email or a sketchy download can't be stopped just because you're on your safe home Wi-Fi. Once it hits, file encryption can spread to your home NAS or other PCs in seconds.

🚨 What RoamSwitch does: The instant it detects ransomware-like behavior — such as sudden mass file encryption — it cuts your Mac off from the network in an emergency (air-gap isolation). It works regardless of whether the network is trusted, autonomously stopping the damage from spreading.
Core Capabilities

Multi-Layered Defense for Professional Macs

Autonomous cyber defense engineered for MacBooks carrying sensitive code and data.

🛡️

Automatic Wi-Fi Detection & Zero-Config Outing Defense

Securely recognizes the router's gateway MAC address. The instant you disconnect from trusted networks, the Application Firewall engages maximum lockdown. (Outbound communication, such as web browsing, continues to work as usual.)

📊

18-Point Comprehensive Mac Security Audit

Instant 100-point audit covering FileVault, SIP, Gatekeeper, Firewall, Wi-Fi encryption, ARP spoofing, stealth mode, and Apple Rapid Security Responses (RSR).

🔍

Zero-Day Port Auto-Block & Dev Server Audit

The moment a new port that wasn't seen before is exposed to the external LAN, it's auto-blocked — no signature needed (opt-in). Unauthenticated database services like Redis/MongoDB get an instant alert the moment they bind to 0.0.0.0, and dev servers such as Node.js/Vite/Docker are passively audited for CORS wildcards and missing auth.

📜

macOS Unified Logging Security Audit

Rapidly extracts sudo authentication failures, SSH intrusion attempts, Gatekeeper block history, and Apple XProtect remediation logs from macOS's internal unified log, visualized on a graphical timeline.

🍏

Apple XProtect & ClamAV Dual Malware Defense

Beyond verifying Apple's official XProtect status, checks file and app notarization signatures and quarantine attributes, and can run on-demand scans with the open-source ClamAV engine. Every external storage connection — including allow-listed devices — is automatically scanned, switching to full access only once confirmed safe.

📡

Automatic ARP Spoofing Response (Blocks MITM Attacks)

On an untrusted network it pins the gateway, IPv6 router and on-link DNS MAC into the neighbour table, so a spoofed ARP/NDP cannot move the route (preventive lock). On top of that, the instant the gateway's physical address (MAC address) changes suspiciously, communication is cut off in an emergency (air-gap isolation) to prevent eavesdropping and tampering. Opt-in, and can be released anytime once safety is confirmed.

🚨

Ransomware Behavior Detection & Autonomous Isolation

Detects ransomware-specific behavior — like sudden mass file encryption — without relying on signatures. The instant it's detected, your Mac is cut off from the network (air-gap isolation) to autonomously stop the damage from spreading to other devices on your home LAN.

🔌

Rogue USB / BadUSB Physical Port Guard

Intercepts and blocks keystrokes from unapproved USB keyboards and modified cables (Rubber Ducky, etc.) to prevent malicious automated command injection. Automatically performs full ClamAV scans when USB storage is connected.

📥

Web & Mail Download Auto Protection Guard

Monitors file downloads from Safari, Chrome, Mail, Slack, and Discord via FSEvents. Scans quarantined files with ClamAV and quarantines infected files immediately.

🌐

DNS Threat Guard & URL Safety Auditor

Automatically switches to secure DNS (Quad9 / Cloudflare Security) on untrusted Wi-Fi to block name resolution of malware C2 and phishing domains. The scope (untrusted only / always on) is configurable.

🔒

VPN tunnel + kill-switch (WireGuard / Tailscale)

Away from trusted networks, route all traffic through an encrypted WireGuard config or a Tailscale exit node. A pf kill-switch drops any clear-text leak outside the tunnel and never fails open if the tunnel drops. The primary man-in-the-middle defense (opt-in).

🎣

Passive link guard (blocks phishing connections)

Determines the destination of outbound connections from the DNS name, the TLS SNI and the HTTP Host header, and warns about or blocks connections to phishing / scam sites (block by default, and it works for DoH browsers). A NEFilter system extension inspects the real post-resolution flow, so it never edits /etc/hosts. In warn mode a no-answer is fail-closed. Verdicts are local.

🔎

Static Signature Detection & New Autostart Monitoring

Checks downloaded files against the industry-standard EICAR test signature and well-documented reverse-shell one-liners — works even without ClamAV installed. Also watches for new LaunchAgent/LaunchDaemon registrations in real time, flagging any that invoke a raw script interpreter directly. Requires no EndpointSecurity entitlement.

🖥️

ClickFix Defense: Catches and Clears Malicious Commands at Copy-Time

Defends against "ClickFix" — a fake error or verification screen that talks you into pasting and running a command yourself in Terminal. Regardless of where you paste it (Terminal, Script Editor, Spotlight, or anywhere else), RoamSwitch watches the clipboard and, the moment a known-malicious pattern is copied, clears it and warns you. Pro adds an optional layer that also watches command history and can emergency-lockdown the network on detection.

🔔

Notification History (Past 7 Days)

Look back through the notifications RoamSwitch has sent (security log-audit anomalies, ClickFix detections, and the like) instead of only catching them the moment they appear. Entries older than the retention window are pruned automatically.

🐳

Docker Risk Detection Guard (Container-Escape Alerts)

Detects the instant a container starts with --privileged mode or a /var/run/docker.sock bind-mount, and sends a notification (Pro, opt-in). Flags the risky configuration only — no automatic blocking.

🔑

Secret/API-Key Leak Auditor (Paste Check & Whole-Folder Scan)

Paste text to instantly audit it for leaked API keys and tokens. Also recursively scans an entire folder — like a source checkout — automatically skipping .git, node_modules, and similar directories. Everything runs entirely on-device.

📦

Package CVE Scan (Homebrew + dependencies)

Checks installed Homebrew packages and your project's dependencies (npm, PyPI, crates.io, and 4 more ecosystems) against a locally-held known-CVE map. No network activity at all.

🚨 Air-Gap Emergency Disconnect

The instant ransomware is detected, your Mac is physically cut off from the network

No signatures required — it judges and acts autonomously based on behavior alone.

🔍

1. Detect the behavior

Detects ransomware-specific behavior, like sudden mass file encryption, in real time — without relying on known virus signatures.

2. Air-gap in 0 seconds

The instant it's detected, your Mac is cut off from the network in an emergency — halting communication with command servers and the encryption itself, no delay.

🛡️

3. Stop it from spreading

Autonomously stops the infection from spreading to other devices, like a home NAS or a family member's or colleague's PC. You can lift it anytime once it's confirmed safe.

AI & Developer Extensions

Bring RoamSwitch into your own workflow

Diagnostics don't have to stay inside RoamSwitch. Read them straight from an AI client, or straight from your own app.

🤖
AI Integration & Incident Response (MCP)

Ask AI to Explain Alert Messages and Guide Incident Recovery

Encountered an unfamiliar warning, an emergency air-gap disconnection, or an unexpected USB ejection? Built-in official MCP server allows AI assistants (Claude, OpenCode, Antigravity) to provide root-cause analysis and step-by-step remediation advice using RoamSwitch's knowledge base. Supports 100% offline querying with local LLMs (such as Ollama) even during network lockdowns.

MCP server and detection logic — source published (GitHub, MIT) →

Explore Troubleshooting Use Cases →
📦
Developer SDK

Bring RoamSwitch's diagnostics straight into your own Mac app

RoamSwitchKit is a free, open-source client that lets you read RoamSwitch's security diagnostics directly from Swift. No need to build your own ARP monitoring or port scanning — just ask “is this network safe right now?” from your own app. One line via Swift Package Manager, read-only.

See how it works →
📄
Security Whitepaper

The privilege boundary, the network paths, the crypto — all disclosed

The complete list of operations the root helper can run, every outbound network path, the license-activation cryptography, and the threat model with its non-goals — documented at a level you can check against the code. Includes commands to verify it against the shipping binary.

Read the whitepaper →
18-Point Security Matrix

18-Point Mac Security Audit Criteria

Comprehensive coverage of system integrity, perimeter defense, and listening ports.

🔐
FileVault Full Disk Encryption
XTS-AES 128 storage encryption preventing physical data theft upon device loss.
🛡️
SIP (System Integrity Protection)
Restricts root permissions from modifying critical macOS system and kernel files.
🚫
Gatekeeper App Execution Control
Blocks execution of non-notarized apps and tampered executable binaries.
🧱
Kernel Firewall (pf)
Automatically drops unsolicited inbound TCP/UDP packets at the kernel layer.
📡
Wi-Fi Encryption Verification
Validates WPA2-AES / WPA3 encryption and alerts on risky open Wi-Fi networks.
👥
ARP Spoofing Detection
Detects rogue devices attempting Man-in-the-Middle (MitM) router impersonation.
🥷
Stealth Mode (Ping Cloaking)
Ignores ICMP Ping and port scan probes, cloaking your Mac from external visibility.
🔄
Rapid Security Response (RSR)
Verifies that macOS critical vulnerability security patches are installed automatically.
🍏
Apple XProtect Malware Definitions
Checks active operational status of Apple's built-in XProtect & Remediator engines.
🔌
Listening Port Exposure Audit
Scans all sockets bound to 0.0.0.0 to ensure firewall containment.
📥
Web & mail download protection
New files landing in Downloads, Desktop, and Documents are auto-scanned with ClamAV; threats go to the Quarantine Vault.
🌐
DNS Threat Guard (malicious site / C2 block)
Away from trusted networks, switches to secure DNS (Quad9 / Cloudflare Security) to block name resolution of malware C2 and phishing domains.
🎣
Phishing / malicious-link protection (Safari & link guard)
Safari's fraudulent-site warning plus NEFilter-based phishing detection and blocking of outbound connections (works for DoH browsers too).
⌨️
Rogue USB / BadUSB port guard
An unapproved USB storage device is held for approval; a keystroke-injection keyboard has its input suppressed.
🔗
macOS accessory-connection protection
Data from a new USB / Thunderbolt accessory is blocked at the OS layer while the Mac is locked (Apple Silicon).
📡
Gateway ARP Pinning (Preventive MITM Defense)
Statically pins the router's MAC address in the neighbor table on untrusted networks, preventing ARP spoofing before it can happen rather than only detecting it.
🔑
SSH Remote Login Configuration Audit
When Remote Login is enabled, verifies root login is disabled and password authentication is rejected in favor of key-only auth.
🗝️
Sudo Privilege Escalation Audit (NOPASSWD)
Audits for NOPASSWD entries that would allow root privilege escalation without a password.
Product Comparison

Comparison with Other Security Solutions

Defends the critical perimeter blind spot when transitioning across Wi-Fi networks.

Features & Defense Scope
RoamSwitch RoamSwitch
macOS Built-in Commercial VPN Traditional Antivirus
Auto Wi-Fi Switching Zero-Config Defense ✅ Fully Automatic (Gateway MAC / 0s) ❌ Requires Manual Steps ⚠️ Requires VPN (LAN exposed) ❌ Unsupported (Scan only)
Dev Port (0.0.0.0) LAN Blocking ✅ Kernel-level Drop ⚠️ Requires Manual Rules ❌ Cannot Defend LAN ❌ Unsupported
ARP Spoofing (MitM) Monitoring ✅ Real-time Detection ❌ Unsupported ⚠️ Partial Encryption Only ❌ Unsupported
18-Point Comprehensive Audit ✅ 100-Point Score & Report ❌ Scattered Across Settings ❌ Unsupported ❌ Unsupported
Ransomware behavior detection & autonomous isolation ✅ Emergency air-gap on detection ⚠️ Known variants only (XProtect) ❌ Unsupported ⚠️ Only in some behavior-monitoring products
Rogue USB / BadUSB physical port defense ✅ Auto-block + full ClamAV scan on connect ❌ Unsupported ❌ Unsupported ❌ Not supported (some premium tiers only)
VPN tunnel + kill-switch (fail-closed) ✅ WireGuard / Tailscale + pf kill-switch (no leak if it drops) ❌ Unsupported ⚠️ Provides the tunnel; kill-switch depends on the client ❌ Unsupported
Privacy (Zero Telemetry) ✅ Zero Telemetry (100% Local) ⚠️ Telemetry to Apple ❌ Logs Kept on VPN Servers ❌ Cloud Telemetry Uploads
Battery & CPU Impact ⚡ Practically Zero (Event-driven) ⚡ Zero ⚠️ Constant Crypto Drain ❌ Heavy Background Scans
Pricing & Editions

Simple Pricing

No recurring subscription fees. Own lifetime protection for your Macs with a single payment.

Free Edition
$0 / Completely Free

Essential Mac defense and manual security audits for everyday users.


  • Zero-config firewall blocking on Wi-Fi switch
  • 18-Point Mac manual security audit (100-pt score)
  • Apple XProtect audit & manual ClamAV malware scan
  • Basic open listening ports & USB device list inspection
  • 100% Local processing & Zero Telemetry
Free Download

Setup takes about 2 minutes, with one macOS approval step.

Lifetime License • 2 Macs
💎 Pro Lifetime License
$19.99 / Lifetime Access

For engineers and professionals carrying MacBooks. Advanced autonomous defense stopping threats instantly.


  • 🚨 Ransomware Behavior Detection & Autonomous Isolation (Air-Gap Emergency Cutoff)
  • 🛡️ One-click 0.0.0.0 dev server isolation guard
  • 🚪 Auto-block unknown listening ports (signature-free zero-day defense)
  • ⚡ Real-time Notification Center alerts for ARP spoofing & MITM attacks
  • 📡 Automatic network cutoff on ARP spoofing detection (air-gap isolation)
  • 🔌 Physical port guard against unauthorized USB / BadUSB insertion
  • 🦠 Automatic ClamAV scan on USB storage connection (scans every device, even allow-listed ones)
  • 🤖 Autonomous background sentinel & auto virus definition updates
  • 📄 Export security audit logs & reports to CSV
  • 💻 Valid for 2 Macs forever (Main + Secondary Mac)
  • 📥 Real-time Web & Mail download monitoring with ClamAV auto-scan & isolation
  • 🌐 DNS Threat Guard (Blocks C2 & malicious domains via Quad9/Cloudflare)
  • 🔗 Email & Web link safety auditor (Phishing & Unicode homograph detection)
  • 🔵 Automatic Bluetooth Off Guard on Untrusted Networks
💎 Get Pro Lifetime License

One-time purchase, no subscription. As a digital product, refunds are generally not available — please confirm it works in your environment with the free version first. Payment is completed on Stripe’s secure page.

Compatible with macOS 13.0 Ventura or later. Set up in minutes from download.

Apple Silicon (M1/M2/M3/M4+) Native | macOS 13.0 and later
Supports Japanese, English, Korean, Chinese (Simp/Trad), German, French, Spanish, Italian, Portuguese
🔒

100% Local Processing. Zero External Telemetry.

RoamSwitch never transmits your Mac's connection details, port numbers, diagnostic results, or logs. Every check and every block happens entirely on your device.

Read Privacy & Security Policy → The technical basis: Security Whitepaper →