One alliance. Every layer protected.
Twelve products, one intelligence graph. From collective threat data to automated enforcement and independent assurance — every layer of the OneFirewall platform draws on the same alliance-wide telemetry, in real time.
Collective Intelligence
The foundation of the platform — crowd-sourced, enriched, and enforcement-ready.
Cyber Threat Intelligence
Alliance-sourced threat intelligence covering IP addresses, domains, URLs, and malware. Real-time feeds for comprehensive threat coverage.
Explore →
Scanner
Vulnix0
Automated vulnerability discovery and exposure management. Continuously scans your attack surface and cross-references findings against the OFA threat feed to flag actively exploited CVEs first.
Explore →Free Security Tools
A growing library of free community tools — IP reputation lookup, Crime Score checker, IOC search, STIX feed sampler, and more. No sign-up required for basic access.
Explore →Threat visibility across every region you operate in
Alliance intelligence isn't concentrated in one region or one vendor's customer base — coverage spans North America, Europe, the Middle East, Asia-Pacific and Latin America, so the feed reaching your firewall reflects a genuinely global attack surface, not just your own neighbourhood of the internet.
Network & Enforcement
Turning validated intelligence into automated blocking — across your existing stack, or on purpose-built hardware.
Core
WCF Agent
The World Crime Feeds agent pushes validated IOC block-rules to your firewall or IPS automatically — no manual playbook, no ticket queue. Detection to enforcement in <30s.
Documentation →
Hardware
OneDevice Firewall
A purpose-built hardware firewall pre-loaded with OFA intelligence. Plug in, connect to the Alliance, and start blocking — zero configuration required on day one.
Explore →
Core
Web Application Firewall
Alliance-powered WAF that extends perimeter protection to your web applications. OWASP Top 10 coverage enriched with live IOC reputation scoring from the OFA feed.
Documentation →
Core
OFA Secure DNS
DNS-layer protection that blocks malicious domains before they resolve. Resolvers updated in real time from the Alliance threat feed — no agent required for basic coverage.
Documentation →
New
ClosedVPN
A zero-trust encrypted VPN that routes traffic through OFA-verified tunnels. Available on iOS and Android — blocks malicious exit destinations before connection.
Documentation →
Core
Secure Channel
End-to-end encrypted communication channel for security teams and alliance members — no metadata leakage, no third-party servers. Built for sensitive incident coordination.
Explore →Drop it in front of any firewall you already run
OneDevice runs in Parallel mode alongside pfSense — or any other firewall — as a passive, out-of-band enforcement point, blocking on the rules feed while your existing stack keeps doing what it already does. No inline failure risk, no re-architecture.
Every rule the WCF Agent pushes, counted
An illustrative view from a live deployment: attacks prevented, distinct threat actors blocked, and the automated firewall rules the WCF Agent pushed on your behalf — with zero manual rule-writing.
AI, Cloud & Mobile
Extending alliance intelligence into AI workloads, cloud estates, and the pockets of your response team.
New
AI Gateway
A security-first AI inference gateway that inspects and filters LLM traffic for prompt injection, data exfiltration attempts, and malicious model abuse — before it reaches your AI stack.
Documentation →
AI
AquilaX Security
AI-powered security scanning platform that analyses code, containers, APIs, and cloud configurations for vulnerabilities — enriched with OFA threat context to prioritise what actually matters.
Explore →
Mobile
OFA Mobile
The Alliance in your pocket. Monitor live threat feeds, check Crime Scores, receive push alerts on critical IOC events, and manage your security posture from iOS or Android.
Explore →Every prompt and response inspected before it leaves
AI Gateway sits between your team and the LLMs they use — OpenAI, Gemini, Claude, Grok, and more — stripping PII before it's sent, scoring every session for policy violations, and giving security teams a safety score instead of a blind spot.
Query the alliance's intelligence in plain English
The MCP Server exposes OneFirewall's CTI database directly to AI assistants — ask about an IP in a chat window and get the Crime Score, MITRE ATT&CK mapping, sightings across the alliance, and a block recommendation back in seconds.
Explore MCP Server →