The firewall knows nothing about your users
It opens ports to IP addresses. When someone leaves, somebody has to remember to go back over it — and nobody does.
Zero Trust edge appliance
What protects your sites fits in a file you can read. korridor brings firewall, multi-WAN, high availability, reverse proxy, WAF, per-user access control and remote access together in a single product. No database, no third-party software: to reach an internal site, korridor is what you put at the other end too. And it does not configure itself — it verifies a signature, then it applies.
Six products that never talk to each other, and no one able to say what is actually running.
It opens ports to IP addresses. When someone leaves, somebody has to remember to go back over it — and nobody does.
The fibre goes down, 5G takes over, and tunnels and certificates only find out afterwards.
The value is real. So is a cost that tracks headcount, a black box you cannot audit, and traffic routed through a third party. And it stops at the network: not your firewall, not your links.
Who changed what, when, and is that really what is running? A per-site admin interface answers none of those three questions.
An artefact signed in a safe zone, applied at the edge by a process that is not root. The chain is short and every link can be checked.
The bundle is YAML, reviewed like code and versioned in git — or composed in the control plane. To the edge it is the same thing: a file.
A detached signature, with the private key kept off the host. The host holds public keys only: it can sign nothing.
The binary is signed too. The switchover is blue-green under a watchdog: if the new generation does not become ready, the old one takes back over on its own.
Invalid signature, version going backwards, unknown field: rejected, and the last valid configuration stays in force. From the firewall up to L7.
A stack to operate and version, turned into a line of configuration. The left-hand column is what you already maintain.
| What you operate today | In korridor |
|---|---|
| pfSense / OPNsense / network appliance + plugins | An nftables firewall generated from the bundle, applied before routing comes up |
| `ip rule` scripts or a multi-WAN router | Uplinks probed through their own link, with automatic failover and failback |
| keepalived + HAProxy + a session store | Two machines are enough: virtual address, replicated state, upgrades without downtime |
| Nginx + ModSecurity | HTTP/1.1, HTTP/2 and HTTP/3 reverse proxy + Coraza WAF and OWASP CRS |
| oauth2-proxy, Authelia, home-grown forward-auth | An access policy evaluated on every request, and an OIDC portal that works with your identity provider |
| No equivalent: a full identity provider to host | A standalone enrolment portal: email code, authenticator app, passkeys — with no identity provider at all |
| cloudflared, ngrok, frp | Inbound tunnel: two korridor instances chain together, the remote site dials the edge and opens no port |
| OpenVPN / WireGuard + scripts, or a mesh subscription | Split-tunnel roaming client: the internal network goes through the edge, the internet stays direct |
| certbot / cert-manager | Automatic ACME per host, without ever opening port 80 |
| Ansible + apt, and a maintenance window | A signed upgrade, watchdog-gated, without downtime |
This is the only interface korridor serves itself, and it needs nothing installed: no identity provider to host, no agent on the machine. A visitor proves they control an authorised mailbox, picks a second factor, and their source address is approved for as long as you decided. The screenshots come from a demonstration instance: the account, the gateway and the services shown are fictional.
No password to create, so no password to steal or reset. The portal caps sends per source, and the browser solves a proof of work before a single message leaves: rotating IP addresses is not enough to flood your mailboxes. The authorised-access warning is served by the portal; it is not something you configure.
Authenticator app or passkey: the user picks at enrolment, and a user enrolled on several methods picks at sign-in. A passkey is phishing-resistant and device-bound; an authenticator app needs no hardware. The strength required is set per resource — a monotone ladder, from a plain email code to a mandatory hardware factor.
Backup codes are issued once, at enrolment, and never shown again. They are the only way out that needs nobody else — everything else goes through a reset from the host, which is traced.
Once the proof is made, the source address is approved and the firewall rule follows within milliseconds — then disappears on its own when it expires. That is what opens SSH, RDP or a database to the person who has just authenticated, with no integration to write between firewall and directory, and without leaving a port open to the whole internet the rest of the time.
Adding a passkey, removing one, switching device, regenerating backup codes: users do it themselves, and every change demands a fresh proof on the spot. One admin queue fewer.
The layout recomposes on a narrow screen: the form takes the full width, choices stack, nothing is hidden behind a menu. Nothing to install either, no app to publish in a store — it is a web page, and that is what makes it available on a borrowed machine as well as on a phone.
The threat model is the argument, not the datasheet. "Zero Trust" means nothing on its own: here it comes down to four properties, and each one is readable in the configuration rather than in a brochure.
The process that faces the internet never runs as root. What touches the kernel — firewall, virtual address, routing — lives in a supervisor with no public network surface. A compromised web component has no right to reconfigure the network.
The exposed machine can sign nothing. It holds public keys only: it can neither forge a configuration, nor manufacture an upgrade, nor issue a federated identity.
The safe posture is the absence of configuration. A route without a policy is not published. An unknown tunnel is refused. A machine with no declared network reaches nothing. People forget to close; they do not forget to open.
An enrolment opens a port, its expiry closes it again. When someone proves their identity at the portal, the firewall rule follows within milliseconds — with no integration to write between two products.
No module to buy, no option to switch on. There is no "enterprise" edition: the plan changes the service commitment, never the product.
Serving your applications and sites, under TLS, with no stack to assemble.
Filtering before the request ever reaches your application.
Who reaches what, re-evaluated on every request — Zero Trust taken literally, with no trust granted to the originating network.
The entry point holds the machine at L3 and L4 as well.
Reaching a site or an internal network without opening an inbound port.
What it takes to hold the machine over time.
All of these capabilities are shipped and in service. korridor holds the entry point of the Koraisoft infrastructure itself — it is the product we operate the longest every day.
Four situations where the current stack costs more than it protects.
NIS2, DORA, HDS regulation; traffic and logs leaving your premises; a cost that tracks headcount; a black box impossible to audit. korridor delivers the same application-level value on your machines, with a configuration your auditor can read line by line.
Branches, workshops, laboratories. One appliance per site: firewall, two internet links, VPN, application publishing, identity portal — configured by a signed file pushed remotely, not by a web interface clicked through site by site.
Hosting and managed-service providers: every customer dials out to your points of presence without opening a single inbound port. Routes and policies are per customer, in a versioned artefact. A point of presence can be replaced without anyone reconnecting.
Nginx, ModSecurity, oauth2-proxy, cloudflared, cert-manager, keepalived: six lifecycles, six configurations, none of them signed. korridor consolidates the lot behind a single artefact, with no database and no third-party component at runtime.
The scope is deliberately kept narrow. Here is where it stops — and saying so up front beats finding out later.
korridor holds your sites and your machines. Load distribution between distant points of presence is built with you; it is not delivered as an anycast service.
No IPsec, no BGP, no OSPF, no captive portal, no QoS. The firewall and multi-WAN exist because the entry point needs them — not to compete with a carrier router.
If your tender requires it today, korridor does not answer that line. It is an identified piece of work, not a ticked box.
This is the structural choice of the product: everything goes through a signed, reviewed file. If your operations rely on an interface to click through, korridor will ask for a change of habit.
Against a community package catalogue, korridor offers a small, audited surface instead. That is a deliberate trade-off, not a gap to fill.
Allow half a day: we write the bundle for your first site, sign it, deploy it on a machine of yours, and you leave with the file — readable, versioned, reversible. Pricing is counted in nodes and sites, never per seat or per request; we send you the rate card on request.
Request a demonstration