💡 Official FAQ

Frequently Asked Questions (FAQ)

Answers to common questions regarding RoamSwitch for Mac and Linux: zero-telemetry architecture, autonomous defense, compatibility, and AI/MCP integration.

🔍

🍎 Overview & Core Concepts

Q1. What is RoamSwitch for Mac?
RoamSwitch for Mac is a zero-trust autonomous network defense and security diagnostic suite for macOS designed with strict Zero-Telemetry (zero external data transmission). It features sub-second macOS kernel packet filter (pf) switching based on network changes, canary-driven ransomware detection with Air-Gap isolation, dev server LAN exposure protection, unknown port auto-blocking, unauthorized USB storage & BadUSB keyboard defense, an 18-item comprehensive security audit, and read-only AI integration via MCP.
Q2. What is the difference between the Free and Pro Lifetime editions?
The Free edition includes automatic Wi-Fi detection, 3-tier pf profile switching, automatic sharing service stop/restore, 18-item manual security audit, Wi-Fi encryption strength warning, and port/USB device monitoring (view-only) with no expiration. The Pro Lifetime edition ($19.99 / ¥2,980 one-time purchase, lifetime free updates) adds ransomware encryption detection & Air-Gap isolation, dev server LAN exposure isolation, anomalous port auto-blocking, ARP spoofing auto-containment, gateway ARP/NDP pinning (prevention), VPN auto-tunnel + kill switch (WireGuard / Tailscale), unauthorized USB storage & BadUSB defense, web/mail download protection with automatic ClamAV scanning, hazardous AI model (.pkl) download detection, DNS threat protection, link protection (/etc/hosts sinkholing), link safety auditing, clipboard API key protection, Bluetooth auto-off on untrusted Wi-Fi, autonomous patrols, CSV/JSON export, and dual-Mac licensing per user.
Q3. How is RoamSwitch different from traditional antivirus or tools like Little Snitch?
While traditional antivirus software relies on passive scans for known malware signatures, RoamSwitch detects network environment changes in sub-seconds and autonomously enforces kernel-level (pf) packet filtering and service shutdown. Unlike dialog-heavy interactive firewalls like Little Snitch, RoamSwitch provides zero-click autonomous defense once your trusted networks are configured, never interrupting your workflow with constant approval popups.
Q4. How is Zero-Telemetry verified and guaranteed?
RoamSwitch contains zero analytics, tracking, or telemetry code. The developer Lafine publishes a comprehensive security architecture whitepaper detailing exact verification methods, allowing users to independently verify zero outbound transmission using standard tools such as Wireshark or tcpdump.

⚙️ Features & Specifications

Q5. What is automatic network security profile switching (pf control)?
RoamSwitch identifies connected Wi-Fi networks by gateway BSSID/MAC address and SSID in milliseconds, automatically applying one of three macOS packet filter (pf) profiles: Trusted (Home/Office), Balanced (Standard Protection), or Lockdown (Public/Untrusted Wi-Fi). Unnecessary listening ports and sharing services are instantly blocked the moment you open your Mac in a cafe or hotel.
Q6. How does ransomware detection and Air-Gap isolation work?
RoamSwitch places canary honeypot files in key directories (Desktop, Documents, Downloads) and monitors FSEvents for mass modifications and encryption entropy spikes. Upon detection, it instantly freezes the offending process using SIGSTOP, severs all network interfaces via pf (Air-Gap), and stops file sharing services to prevent lateral infection across your LAN and Time Machine backups.
Q7. What is local dev server LAN exposure isolation?
When starting local frontend dev servers (Vite, Next.js, Webpack) or local AI backends (Ollama, LM Studio), they often bind to 0.0.0.0, exposing internal endpoints to everyone on the same Wi-Fi network. RoamSwitch detects these listening ports and blocks incoming connections from the local subnet while maintaining full access from localhost.
Q8. How does automatic sharing service control work?
Even if services like Remote Login (SSH), File Sharing (SMB), Screen Sharing (VNC), and AirDrop are enabled at home, RoamSwitch automatically pauses them the instant you connect to an untrusted Wi-Fi network, and automatically restores them when you return to a trusted network.
Q9. What are the unauthorized USB storage guard and BadUSB keyboard guard?
When an unregistered USB mass storage device is attached, RoamSwitch automatically unmounts/ejects it (or retains it read-only for ClamAV inspection). When a malicious BadUSB device (e.g. Rubber Ducky, disguised USB cable) that injects keystrokes at superhuman speed is inserted, RoamSwitch temporarily intercepts keystrokes and presents an authorization dialog to stop automated payload injection.
Q10. What are ARP spoofing detection and preventive gateway pinning?
RoamSwitch continuously inspects ARP tables for Man-in-the-Middle (MitM) attacks where rogue machines impersonate the gateway. Upon detection, it triggers emergency Air-Gap isolation. Furthermore, upon connecting to untrusted Wi-Fi, it pins gateway and DNS MAC addresses in the neighbor cache to prevent ARP/NDP poisoning before it starts.
Q11. What are DNS threat protection and web/mail download protection?
RoamSwitch prevents local DNS resolution of known malicious C2 and phishing domains (via Quad9, Cloudflare, or AdGuard integration). It also detects newly downloaded files and hazardous AI models (.pkl / .pt) in real time via FSEvents and scans/quarantines them using ClamAV.
Q12. What are Link Audit and passive Link Protection?
Before clicking a link received via email or chat, Link Audit expands shortened URLs, traces redirect chains, checks Unicode homoglyphs, and inspects domain reputation locally with Zero-Telemetry. Additionally, Link Protection automatically sinkholes confirmed malicious phishing domains locally via /etc/hosts to prevent accidental connections.

💻 System Requirements, Installation & Setup

Q13. Which macOS versions and CPU architectures are supported?
macOS 13 Ventura or later. Exclusively built for Apple Silicon Macs (M1, M2, M3, M4 and newer). Intel-based Macs are not supported.
Q14. Why is RoamSwitch distributed via direct .dmg download instead of the Mac App Store?
RoamSwitch requires privileged daemon execution (SMAppService.daemon) and sub-second kernel packet filter (pf) management, which are strictly prohibited by Mac App Store sandbox policies. The .dmg package is officially code-signed with Apple Developer certificates and notarized by Apple for full security and integrity.
Q15. What should I do if I see 'Helper connection failed' or 'Operation not permitted'?
Open System Settings -> General -> Login Items & Extensions, and ensure RoamSwitch helper is toggled ON under 'Allow in Background'. Ensure the app is located in /Applications, then restart the application.
Q16. When I enable the antivirus feature, RoamSwitch asks for access to my Desktop and Downloads folders. Is this a sign of malicious behavior?
No, this is not malicious behavior. The Web & Mail Protection feature scans files downloaded via your browser or email the moment they arrive, so it requests access to your Desktop, Downloads, and Documents folders through macOS's standard permission system. RoamSwitch explains this in-app before the prompt appears, and it is a legitimate system permission (TCC), not unauthorized access. Scanning happens entirely on your Mac; file contents are never sent to any external server (Zero Telemetry). If you'd rather not grant this permission, you can leave this feature off -- other protections (such as DNS Threat Protection) will keep working normally.
Q17. Can I transfer my license to a new Mac or use it on multiple Macs?
A single Pro Lifetime license permits installation on up to 2 Macs owned by the same user (e.g. MacBook and desktop Mac). To transfer to a new machine, deactivate the license on your old Mac or contact official support.

🤖 Diagnostics, AI Integration (MCP) & Developer Tools

Q18. What does the 15-item Mac Security Health Audit check?
It checks 18 critical macOS security parameters: FileVault full disk encryption, System Integrity Protection (SIP), Gatekeeper, automatic security updates, XProtect update status, macOS Application Firewall, Stealth Mode, Wi-Fi encryption strength, ARP spoofing state, external listening port exposure, and more, providing an overall security posture score (0-100).
Q19. What is the bundled MCP server and which AI tools can connect to it?
It is an implementation of the Model Context Protocol (MCP) enabling AI assistants such as Claude Desktop, Claude Code, Cursor, OpenCode, and Google Antigravity to directly inspect your Mac's security posture score and audit findings.
Q20. Is there any risk of AI altering Mac system settings through MCP?
None. The bundled MCP server (RoamSwitchMCPServer) is designed as strictly read-only over local stdio. Even in the event of prompt injection, the AI has no capability to modify firewall rules, change system settings, or execute administrative commands.
Q21. Can I query RoamSwitch diagnostic data from custom Swift apps or scripts?
Yes. We provide the official open-source Swift client SDK RoamSwitchKit (Swift Package Manager supported). With a few lines of Swift async code, you can fetch security reports, exposed ports, guard statuses, and link safety scores.
Q22. My USB keyboard suddenly stopped working. Is it broken?
A. It's probably not broken — RoamSwitch's Rogue USB / BadUSB Keyboard Guard may have detected an unregistered keyboard and is temporarily blocking its input. Select “Allow” in the approval dialog that appears when you connect it, and the keyboard will work normally from then on (if you missed the dialog, unplug and replug it to bring it back). Input is also released automatically after 3 minutes of no response. If the issue persists, check the allowlist from “USB / BadUSB Guard Settings…” in the menu.
Q23. What exactly is the difference between the protection levels (Trusted, Standard Protection, Maximum Lockdown)? Can I still use the internet during Lockdown?
A. Yes — ordinary outbound traffic like web browsing, email, and chat is never restricted at any protection level. The three levels differ in how much unsolicited inbound traffic they allow. 🟢 Trusted disables the firewall and also allows shared services (SSH/SMB/Screen Sharing) and AirDrop. 🟡 Standard Protection uses the firewall and stealth mode to block external probing while keeping shared services available. 🔴 Maximum Lockdown fully blocks the firewall and enables stealth mode, and also disables shared services and AirDrop. None of the levels ever block traffic you initiate yourself, like browsing.

🐧 Overview & Core Concepts

Q1. What is RoamSwitch for Linux?
RoamSwitch for Linux is a free, zero-trust autonomous network defense and security diagnostic suite for Linux built on strict Zero-Telemetry (no external telemetry transmission). It provides sub-second nftables firewall profile switching, canary-based ransomware isolation, a 24-item comprehensive security audit, and read-only AI integration via MCP in a single lightweight binary.
Q2. How does it differ from traditional Linux tools like ClamAV or Lynis?
While existing tools focus on passive file scanning or periodic manual audits, RoamSwitch specializes in active real-time automation: sub-second nftables rule switching based on Wi-Fi changes, automated network isolation upon threat detection, and seamless zero-click background protection.
Q3. Is RoamSwitch for Linux open source (OSS)?
The core binary is distributed as proprietary freeware (Community Edition, closed source). However, peripheral developer tools, client SDKs (Rust/Python), and MCP server definitions are released as open source on GitHub.
Q4. Since the core binary is closed source, how can users verify its safety?
To ensure absolute transparency, Lafine publishes a comprehensive security whitepaper outlining step-by-step packet capture and system call verification methods. Users can independently confirm using tcpdump or eBPF tools that zero outbound telemetry is ever transmitted.

⚙️ Features & Specifications

Q5. What does 'Zero-Telemetry' mean in practice?
It guarantees that zero security logs, system information, traffic history, or audit scores are ever sent to any remote server or cloud, including Lafine's own infrastructure. All analysis and policy enforcement execute 100% locally on your Linux machine.
Q6. What is autonomous nftables profile switching?
RoamSwitch inspects the gateway MAC/BSSID of connected networks in milliseconds and automatically applies tailored nftables rulesets for Home (Trusted), Office (Balanced), or Public Wi-Fi (Lockdown) environments without requiring manual iptables/nftables configuration.
Q7. How does the autonomous ransomware isolation feature operate?
Using canary honeypot files and fanotify/inotify with Shannon entropy analysis, RoamSwitch detects rapid encryption bursts. It immediately freezes the malicious PID via SIGSTOP and triggers emergency nftables Air-Gap isolation to halt lateral infection across your LAN.
Q8. How do the unauthorized USB and BadUSB guards work?
When an unapproved USB mass storage device is connected, udev integration holds mounting and presents a confirmation dialog (with optional ClamAV scanning). For BadUSB keystroke-injection devices, evdev (EVIOCGRAB) temporarily grabs keystrokes in software and displays an approval dialog to suppress unauthorized commands without physical port disconnection.
Q9. How do the VPN auto-tunnel and kill switch features operate?
Upon connecting to an untrusted network, RoamSwitch automatically brings up your configured WireGuard (.conf) or Tailscale (Exit Node) tunnel. An nftables kill switch immediately blocks non-tunnel plaintext leaks, ensuring a strict fail-closed state even if the tunnel drops (opt-in).
Q10. What is passive Link Guard (phishing connection blocking)?
RoamSwitch extracts outbound destination hostnames from local DNS queries, TLS SNI, and HTTP Host headers, comparing them against locally stored signed threat feeds and brand homograph heuristics to warn or block phishing connections (effective even with DoH browsers) without sending URLs to any cloud.

💻 Operating Environment & Supported OS

Q11. Which Linux distributions are supported?
Ubuntu 22.04 / 24.04, Debian 12+, Linux Mint, Pop!_OS, Fedora, RHEL, CentOS Stream, openSUSE, Arch Linux, and Raspberry Pi OS (64-bit), covering all major distributions utilizing systemd and nftables.
Q12. How is RoamSwitch installed on Linux?
You can install it via official package repositories: APT for Ubuntu/Debian (lafine.net/apt), DNF for Fedora/RHEL (lafine.net/rpm), zypper for openSUSE (lafine.net/rpm), and PKGBUILD / signed tarball for Arch Linux (lafine.net/linux/dl/).
Q13. Does RoamSwitch work on headless environments (CLI/CUI)?
Yes. While a native GTK GUI and tray icon are provided for desktop users, headless systems can operate fully via the background daemon, the 'roamswitch' CLI command suite, and the MCP server interface.
Q14. Can RoamSwitch be deployed on Linux servers (VPS / data centers)?
The Client Edition (this tab) is optimized for roaming devices — workstations and laptops that move between networks. For a cloud VPS or data-center server, use the dedicated headless roamswitch-server package instead (also free, distributed separately). It includes server-specific features such as inbound Default Drop, SSH lockout prevention, and eBPF intrusion detection. See the "🖧 Linux Server Edition" tab for details.
Q15. When was the Server Edition released? Is it free?
Yes — it has already shipped, and like the Client Edition it's free (Community Edition, every feature included, no activation required). Install it as the separate roamswitch-server package via APT / DNF / zypper / AUR.

🤖 Diagnostics & AI Integration (MCP)

Q16. What is verified in the 24-item Security Health Check (MCP Audit)?
It evaluates 24 critical parameters: Secure Boot, LUKS full disk encryption, LSM status (AppArmor/SELinux), automated security updates, SSH/Sudo hardening, sysctl kernel hardening, external listening ports, browser Safe Browsing, ARP pinning, and DNS threat protection, producing a standardized security score (0-100).
Q17. How can I inspect diagnostic results?
You can inspect live results via the GTK GUI dashboard or by executing 'roamswitch status' in any terminal for a comprehensive CLI report.
Q18. What is the bundled Model Context Protocol (MCP) server?
roamswitch-mcp is a standardized interface that allows AI agents such as ChatGPT, Claude, Cursor, and Antigravity to securely inspect your local Linux security posture without needing custom integration code.
Q19. What workflows are possible by integrating AI with RoamSwitch via MCP?
You can ask your AI assistant questions like 'What is my current security posture score?' or 'Are there any dangerous exposed ports on this machine?' The AI reads local diagnostic data and generates clear remediation steps and audit summaries.
Q20. Is there any risk of AI tampering with Linux system configurations through MCP?
None. The bundled MCP server is architected as strictly read-only communicating exclusively over local stdio. Even under adversarial prompt injection, AI agents cannot alter firewall rules, modify system configuration files, or execute privileged commands.
Q21. My USB keyboard suddenly stopped working. Is it broken?
A. It's probably not broken — RoamSwitch's BadUSB Keyboard Guard may be temporarily blocking keystrokes from a keyboard that isn't on the allowlist, and showing an approval dialog. Select “Allow” in that dialog to register the keyboard and restore input. If there's no response within 3 minutes, input is released automatically (so a headless machine never gets locked out). If you don't see the dialog, unplug and replug the keyboard to bring it back.
Q22. What exactly is the difference between the protection levels (open, balanced, lockdown)? Can I still use the internet in lockdown mode?
A. Yes — outbound traffic like web browsing and package updates is never restricted at any protection level. The three levels differ in how much unsolicited inbound traffic nftables allows. open is meant for a home LAN and allows local traffic. balanced is for work networks or tethering — it watches for suspicious ports without getting in the way of normal use. lockdown is for public Wi-Fi and drops all inbound traffic in stealth mode. None of the levels ever block traffic you initiate yourself (browsing, outbound SSH client connections, etc.).

🖧 Overview & Pricing

Q1. What is RoamSwitch Server Edition?
A fully headless (zero GUI dependencies) autonomous defense suite for cloud VPS, on-premise data centers and container hosts. It ships as a separate package and binary, roamswitch-server, distinct from the Client Edition (roamswitch). It provides inbound Default Drop, SSH lockout prevention, eBPF intrusion detection, critical-path FIM (tamper monitoring), egress/C2 blocking and emergency alerts, all in one lightweight systemd daemon.
Q2. What's the difference between the Client Edition (desktop) and the Server Edition?
The Client Edition focuses on roaming: it detects changes in the Wi-Fi you're on (by gateway MAC) and autonomously switches between three firewall profiles. The Server Edition assumes no network roaming and instead defaults to an always-on inbound Default Drop, with SSH management-path protection, container port-exposure prevention, and kernel-level eBPF intrusion detection (Falco or Tetragon) — threats specific to an always-on server. There's no GUI or tray icon; you operate it via the CLI (the roamswitch command), config files, and MCP.
Q3. How much does the Server Edition cost?
Like the Client Edition, the Community Edition is free with every feature included and no activation required. Organizations that want to centrally manage a fleet of servers can add the paid RoamSwitch Business tier (fleet management, signed policy distribution, SLA support), but the endpoint defense itself is identical to the free edition.
Q4. Is Zero-Telemetry (no external communication) maintained on the Server Edition too?
Yes. Traffic content, connection history, and diagnostic results are never sent anywhere. The one exception is the update check through your OS package manager (apt/dnf/zypper). This is verified at build time by an audit script (audit_no_network.sh), and full details are published in the Server Edition Security Whitepaper.

⚙️ Installation & Initial Setup

Q5. Which Linux distributions are supported?
Ubuntu 22.04/24.04, Debian 12+, Fedora, RHEL, Rocky Linux, AlmaLinux, openSUSE, and Arch Linux (all require systemd + nftables). Both x86_64 and aarch64 (including AWS Graviton) are supported.
Q6. How do I install it?
From the same official repositories as the Client Edition, just installing a different package name: sudo apt install roamswitch-server (Ubuntu/Debian), sudo dnf install roamswitch-server (Fedora/RHEL family), sudo zypper install roamswitch-server (openSUSE). It mutually Conflicts with the Client Edition package (roamswitch), so the two cannot be installed on the same host at the same time.
Q7. What should I do first after installing it?
Run the interactive setup wizard with sudo roamswitch server setup. It walks you through the SSH management port, maintenance source IPs, emergency notification channels (Telegram/LINE/Webhook), and the action to take on a critical eBPF event (isolate/freeze/alert_only), then sends a test notification and restarts the service.
Q8. What do I need to do after editing the config file directly for it to take effect?
After editing /etc/roamswitch/server.conf, run sudo roamswitch server restart. The roamswitch-server.service unit does not support reloading its config via systemctl reload — only a full restart.
Q9. What is guard.yaml? Is it required?
It's optional. Creating /etc/roamswitch/guard.yaml lets you specify a distinct containment action (notify-only / isolate the process / isolate the whole host) and a safety timer for each Falco/Tetragon severity level (warning/error/critical/emergency). If the file doesn't exist, an equivalent policy is automatically synthesized from server.conf's action_on_critical, so existing deployments are unaffected. A template ships at /etc/roamswitch/guard.yaml.example.

🔥 Firewall & SSH Lockout Prevention

Q10. What does "inbound Default Drop" mean?
From the moment it's installed, every inbound connection is denied except the ports explicitly allowed in allowed_ports (default 80, 443). This prevents an unintentional management or debug port from being accidentally exposed to the internet.
Q11. Could a misconfiguration lock me out over SSH?
There are several layers of protection: (1) existing ESTABLISHED/RELATED connection sessions are always preserved; (2) ssh_ports (default 22) is always allowed unconditionally; (3) even during an emergency host isolation (Air-Gap), preserve_ssh_on_isolation=true (default) keeps the administrator's SSH session alive; (4) an invalid config syntax or an nftables load failure automatically rolls back to the last-known-good rule set.
Q12. Are Docker/Podman container ports protected too?
Yes. Docker's -p flag creates its own iptables rules by default, which can bypass the host's standard firewall and expose a container port directly to the internet. With protect_docker_ports=true (default), RoamSwitch inserts an inspection rule at the head of the DOCKER-USER chain so that traffic destined for containers is also subject to the allowed_ports / whitelist_ips policy.
Q13. What if I accidentally lock myself out?
Log in via your cloud provider's web console (VNC/serial console) and run sudo roamswitch emergency-restore to restore the firewall to its last-known-good baseline and clear any emergency isolation, or run sudo systemctl stop roamswitch-server to stop the service entirely.

Threat Detection & Autonomous Response

Q14. What is the eBPF Runtime Guard? What's the difference between Falco and Tetragon?
It hooks into kernel-space eBPF sensors to detect reverse shells, privilege escalations, and container escapes in real time. The default sensor is Falco (JSONL over a UNIX domain socket), but setting sensor.type: tetragon in guard.yaml switches it to Cilium Tetragon (native gRPC, over the same UNIX socket). Neither adds a new listening port.
Q15. What actually happens when a critical threat is detected?
Depending on action_on_critical (or the policy in guard.yaml), one of isolate (network-isolate the offending process), freeze (SIGSTOP the process and network-isolate it), or alert_only (notify only) fires automatically. Setting kill_process: true also sends SIGKILL in addition to isolation. Foundational daemons — init, container runtimes, package managers, and more — are always excluded from freeze/kill via a protected-process list.
Q16. What is the safety timer?
It's the grace period after an emergency host isolation (Air-Gap) fires, during which the administrator must acknowledge it with sudo roamswitch server ack (guard.yaml's safety_timer_secs, default 300 seconds). If no acknowledgment arrives in time, RoamSwitch automatically restores network access so a false positive can't leave the server cut off indefinitely.
Q17. How does critical-path FIM (file tampering monitoring) actually work?
It monitors SHA-256 hashes of 150+ critical binaries, authentication configs, and systemd units. Files are individually watched via fanotify (FAN_CLASS_NOTIF) write-completion events, so tampering is detected the instant it happens rather than waiting for the next periodic scan (which remains as a backstop). On a legitimate OS package update, the baseline is re-synced automatically via Debian/Ubuntu's DPkg::Post-Invoke hook or Fedora/RHEL/openSUSE's systemd.path unit, preventing false-positive alerts.
Q18. What are the ransomware canaries?
Decoy files placed under web roots (/var/www, /srv, etc.) whose integrity is checked periodically. If a decoy is tampered with or encrypted, RoamSwitch identifies the accessing process, freezes and isolates it, and sends an emergency notification.
Q19. What are egress blocking and the DNS sinkhole?
Egress blocking (egress_ip_blocklist_enabled, default true, harmless until a feed is populated) blocks outbound connections to known-malicious IPs via nftables. The DNS sinkhole (dns_sinkhole_enabled, default false to avoid breaking internal DNS or split-horizon setups) forces resolution through a filtering DNS resolver (Quad9/Cloudflare/AdGuard/CleanBrowsing) to also block malicious domain resolution.

📢 Notifications, Operations & Diagnostics

Q20. Which channels are supported for emergency alerts?
Telegram Bot, the LINE Messaging API, and generic Webhooks (Slack / Discord / Microsoft Teams / your own monitoring stack). Alerts are dispatched instantly on major incidents — unauthorized port exposure, FIM tampering, eBPF threat detection, or an emergency isolation. Run roamswitch server test-notify to verify your configuration.
Q21. My Telegram test notification says "chat not found" — what's wrong?
In most cases, the supergroup's chat ID is missing its required -100 prefix (e.g. -1001234567890). Check the correct value in the "chat":{"id":...} field of the response from curl -s "https://api.telegram.org/bot<token>/getUpdates".
Q22. What does the "30-item security audit" check?
Run it with roamswitch status --server. It audits 30 items aligned with the CIS Benchmark — firewall state, Frag Gap mitigation (disabling unprivileged user namespaces), Yama LSM memory protection, critical file permissions, Docker exposure, and more — producing a 0–100 security score and a letter grade (S to C).
Q23. Could an AI change my firewall settings through the MCP server without my knowledge?
No. The bundled roamswitch-mcp is designed to be strictly read-only (state-retrieval and audit tools only). Even if a web app's logs contained a malicious prompt injection, an AI agent could not open up the firewall or lift an isolation through it. Changing policy or releasing a frozen process always requires an explicit command run from a local TTY (an SSH terminal).

🏢 Licensing & What's Next

Q24. What does the paid RoamSwitch Business tier add?
Fleet management — enrolling multiple servers with an Ed25519-signed organization token and aggregating protection level, health score, and policy status via periodic check-in; signed policy distribution — pushing trusted networks and each guard's enforced values as signed JSON; a private APT/RPM repository signed with an organization-specific GPG key; and contract-based SLA support. The endpoint defense itself is completely identical to the free edition.
Q25. Are there plans to support container orchestration platforms like Kubernetes?
Currently it targets standalone Docker/Podman hosts. Policy distribution and auditing across an entire Kubernetes cluster is being considered as a possible future extension of the Business fleet-management features. Send specific requests to our support contact.
No matching questions were found. Please try a different keyword.