A door policy is the oldest security control there is, and it works on software for the same reason it works on people. Everything your estate has been approved to run is allowed. Everything else is refused, including the thing nobody has a name for yet.
Most protection works by recognising bad things. This one works by refusing everything that has not been approved, which is a much shorter list and a far more stable one. Malware built new for one particular target has no reputation to overcome, and also no place on the list, and the list is where it fails.
Alongside that sits containment. An approved application can be held to what it reasonably needs: which files it may open, which other programs it may start, and where on the network it may reach. A document reader that suddenly wants to run a script and call out to an unfamiliar address is stopped by the boundary, not by an opinion.
Everybody wants to know what happens the first time something legitimate is blocked at an inconvenient moment. The answer is that the request lands with our desk and a person reviews it, at whatever hour it happens. Approvals are not a ticket queue you wait behind until Monday.
There is also a learning period at the start, where we watch what your estate genuinely uses before anything is enforced. It is a real cost in time and we would rather you planned for it than discovered it.
The machines worth protecting hardest are the ones where money and identity meet: the business manager's workstation, the laptop that signs contracts, the machine that holds unreleased work. Those are the devices where the list should be short and firmly held.
| Model | Default deny. What has been approved executes, and nothing else does |
|---|---|
| Baseline | Built by watching what your estate genuinely uses, before anything is enforced |
| Boundaries | Per application limits on files, child processes and network destinations |
| Approvals | Reviewed and released by the Fortify 24x7 desk, day or night |
| Updates | Application updates are tracked so routine upgrades do not become tickets |
| Best fit | Machines that touch money, contracts, or unreleased work |
| Priced by | Device, monthly |
Whatever you add here joins anything already chosen. Nothing is charged before you finish checkout, and your selections are kept as you move through the other briefs.
Default deny on a machine: what is on the list runs, and the rest is turned away.
Heads up: card statements show FORTIFY 24X7 - Red Carpet Computing is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.
Execution control governs software. It does not govern people, and the distinction is where most of its limits sit.
Every line on this page is a subscription within the digital protection stack. Physical security, and taking private information off surface web and dark web sources, are handled by the concierge as engagements in their own right. Each is scoped and quoted for the situation in front of it, none of them is a product on this domain, and no version of either will ever reach this checkout. Write to concierge@redcarpetcomputing.com if that is the help you want.