A next-generation firewall / UTM you run on hardware you own. Not a managed detection subscription. The AI layer proposes; a human commits.
If you are coming off Astaro or Sophos UTM, the work is the same: objects and zones as one document, a preview of the rendered diff, an atomic commit, and rollback by id. SecureGuard is that appliance OS — FreeBSD, pf, one canonical document. HA clustering is tested and shipping on Business+. It is not a cloud NGFW and it is not MDR.
Object and zone config as one document, not a pile of per-daemon files.
Validate, preview the rendered diff, commit atomically, roll back by id.
AI proposes and can throttle on a score. A human commits.
What does a Sophos UTM replacement mean here?
A self-hosted FreeBSD NGFW/UTM: named objects, zones, one canonical config document. Validate, preview the rendered daemon diff, commit atomically, roll back by id. Built for teams leaving Astaro or Sophos UTM who want an appliance they own, not a cloud NGFW.
Does the AI change the firewall on its own?
No. The AI layer proposes changes and can throttle on a reputation score. A human commits. We do not advertise auto-block.
Is this MDR or endpoint detection?
No. It is a next-generation firewall / UTM: pf, objects, zones, preview, commit and rollback. HA clustering is tested and shipping on Business+. Endpoint agents and SOC-as-a-service are a different product.
Sophos publishes named application control and endpoint sync; SecureGuard does not ship those — application control, anti-spam, identity in policy, and off-box analysis are coming soon. Endpoint-alert ingestion is coming soon on Orchestrator.