ForteStrike finds the lock; ForteLock throws it. The standing guard between assessments -- it reversibly contains new exposure as it appears, and it is a mode of ForteStrike, not a separate product. In active development: an overview of what it is for, not an API reference.
ForteLock is ForteStrike's active-protect mode. ForteStrike proves an exposure is real by attacking it; ForteLock is being built to hold that exposure shut afterward -- the standing guard on the systems you own, in the long stretch between assessments when drift creeps back in.
Its defining rule is that it only ever does reversible things. ForteLock is designed to contain -- to stop a newly-exposed service from being reachable -- and never to exploit, delete, or take an action it cannot cleanly undo. Containment with an undo, not an irreversible change.
An assessment is a moment in time; your fleet is not. New services appear, ports open, a change lands that nobody re-tested. ForteLock is aimed at that stretch -- keeping the line ForteStrike proved from quietly eroding before the next engagement.
The behavior it is being built around is deliberately narrow and always reversible:
| Behavior | Why it is bounded this way |
|---|---|
| Adopt an approved allowlist | ForteLock is intended to take the ports ForteStrike proved safe as its baseline -- what is expected is what is allowed. |
| Contain what is new | When something outside that baseline appears, the intent is to reversibly contain it -- a scoped, audited firewall or service action -- not to attack it. |
| Always reversible | Every action is designed to be undoable: pause, not kill; stop and disable, not destroy; firewall, not exploit. There is no irreversible step by design. |
| Audited, scoped, no surprises | Like ForteStrike, it acts only inside a loaded scope and appends every action to a signed audit trail. |
The most important thing to understand about ForteLock is what it will not do. Containment only, always reversible -- never exploitation, never an irreversible action. That is not a limitation to be lifted later; it is the design. A standing guard that could take an action you cannot undo is a guard you cannot leave running, and the whole point is that you can leave it running.
So ForteLock is being built to pause rather than kill, to stop-and-disable rather than delete, to firewall rather than fire a payload -- and to keep an audited record of every contain-and-release so nothing it did is ever a mystery.
ForteLock is a mode of ForteStrike, which is one member of the DenseDefense suite alongside the compliance engine, the data-discovery and AI-posture capabilities, and the evidence-and-custody layer. ForteStrike proves the exposure; ForteLock holds it shut. There is nothing extra to license -- it is the same engine in its active-protect mode.
In the suite's arc, ForteLock is the contain step: assess (the compliance engine) -> prove (ForteStrike) -> contain (ForteLock) -> attest (the custody layer).
ForteLock is an Early-Adopter capability, in active development, delivered as a mode of ForteStrike. There is no shipping public REST API today, which is why this is an overview and not an API reference.