Ask Rubix Technology a question. Answers come from this site's docs only. I will cite a page. I will not invent a product claim.
Products
Four products, three self-hosted plus SaaS Assess
Built to HIPAA and PCI DSS standards, with security as the first requirement rather than a hardening pass at the end. Mail, network edge, and web VDI / isolated agent desktops run on the customer’s own infrastructure. Secure Assess is multi-tenant SaaS for defensive PCI 11.3 scans. Each one exists because supporting healthcare IT since 2012 showed us exactly where the available software gave up. They are built to satisfy a clinical environment, which is simply a strict version of what any organization wants.
Self-hosted secure email gateway
Next-generation firewall & UTM appliance
Web VDI and isolated AI-agent desktops on a relay you run
PCI 11.3 vulnerability assessment (SaaS)
Hosted or managed Secure Message, Secure Desk, or SecureGuard is available by request — not a catalog SKU. Secure Assess is already multi-tenant SaaS; its own site owns signup. Describe the environment.
Product 01
Secure Message
Self-hosted secure email gatewayOutbound message protection, a one-time-code recipient portal, and layered inbound filtering — running as an appliance on the customer’s own network.
Most secure-email services route your mail through their servers, decrypt it to scan and store it, then push your recipients into a portal with yet another password. Secure Message inverts that: the gateway runs on the customer’s own network, every stored message and attachment is encrypted under their keys, and nothing in the mail path depends on us being reachable.
What it does
- Messages and attachments encrypted at rest under keys the customer holds
- Inbound on-box BEC and phishing score — the only AI in the mail path
- Recipients read protected mail with a one-time code — no account, no app
The only AI is an inbound on-box BEC/phishing score.
Product 02
SecureGuard
Next-generation firewall & UTM applianceAn object-based, zone-aware firewall whose entire configuration is one document: validated, rendered into every daemon, and applied atomically instead of edited daemon by daemon.
Firewall outages are usually configuration accidents: a rule edited on a live box, NAT tangled through the filter policy, no way back except a restore. SecureGuard treats the whole configuration as one document — validated, rendered into every daemon, applied atomically — so a change is reviewable before it lands and reversible after it does.
What it does
- Policy reads LAN → WAN using named objects, so re-cabling a site isn’t a policy migration
- Preview the rendered diff before you commit — and a confirm window rolls back a change that locks you out
- Every state is an immutable revision, so rollback is an id rather than a restore
- The AI layer proposes changes and can throttle on a reputation score. A human commits. We do not advertise auto-block.
Rollback is an id, not a restore. Every config state is an immutable, content-addressed revision.
Product 03
Secure Desk
Web VDI and isolated AI-agent desktops on a relay you runPersistent Windows desktops in the browser, and isolated desktops for AI agents, on a customer-run relay. The relay pairs sessions and forwards ciphertext — it cannot watch. Remote support is one use case, not the product.
Secure Desk is web VDI and isolated AI-agent desktops on a relay you run. Persistent Windows desktops in the browser; many agents, each with its own enrolled desktop and session keys. The relay only pairs sessions and forwards ciphertext — it cannot watch. Remote support is one use case on the same pipe, not the category.
What it does
- End-to-end encrypted sessions — the relay forwards AES-256-GCM it holds no key for
- No inbound firewall rules: both ends dial out to the relay you run
- Per-session verification code, so both ends can confirm who they’re connected to
The relay forwards AES-256-GCM it holds no key for — and needs no inbound rule on the networks you reach. Desk does not run or orchestrate the agents.
Product 04
Secure Assess
PCI 11.3 vulnerability assessment (SaaS)Multi-tenant SaaS for defensive PCI 11.3 vulnerability assessment: we scan and advise, we never attack. Not a pentest and not an official ASV attestation.
Secure Assess is multi-tenant SaaS for PCI readiness and vulnerability assessment. Sign up in the app. We scan systems you authorize. We report and advise. We never attack. External and credentialed views of the same authorized scope. Findings are mapped to PCI DSS 11.3 vulnerability assessment — not 11.4 pentest, and not an official ASV attestation.
What it does
- Scan systems you authorize — external and credentialed views of the same authorized scope
- Findings mapped to PCI DSS 11.3 vulnerability assessment, not 11.4 penetration testing
- We report and advise; we do not patch, remediate, or change the host we scanned
We scan and advise. We never attack.
Workstation signer
Office PDF Sign
Workstation PDF signer — no extra tenantFill, sign and flatten PDFs on the workstation. No cloud account, no extra tenant, no telemetry. Pairs with the Secure Message gateway you run.
Office PDF Sign runs on the workstation and pairs with Secure Message. Sign and flatten the document locally, then send it through the gateway you already run. No extra cloud tenant for signing. 1.4.0 for Windows is a free download. Mac is not published — this page does not promise a Mac file.
- Type, date, checkmark and sign, then save a flattened copy
- Edit the document’s own text instead of covering it over
- Prepare fields for someone else to fill and sign
- No account, no telemetry; the only network it uses is the update feed
- No extra tenant; updates from hub.rubixtechnology.com
Free Windows installer
Rubix Certbot
Free Windows installer — no accountFree Windows installer. No account, no license. Authenticode-signed with the Rubix Technology public trust certificate.
Rubix Certbot is a free Windows installer. No account, no license. Authenticode-signed with the Rubix Technology public trust certificate. Check for Updates inside the app uses the same public feed.
- Free Windows installer — $0, public download
- No account, no license, no signup
- Authenticode-signed with the Rubix Technology public trust certificate
- Check for Updates inside the app uses the same public feed
Support & roadmap
Support is still the oldest thing we do
We were an IT support company for years before we sold software, and we still are one. A support agreement on a Rubix product is written by the same company that writes them for clinical environments — so a customer with a problem reaches engineers who can read the source, not a queue that only escalates.
- Support from the people who wrote the code, under an agreement rather than a best-effort inbox
- Nothing in the critical path of the self-hosted products depends on us being reachable — Message, Guard and Desk run on your own hardware, so your mail, your edge and your desktop sessions keep working regardless
- We can add a feature in weeks because we use our own AI toolchain to build
- Every release held to the standard our clinical customers set
Self-hosted means what you install is yours, on your hardware, under your keys.
Product engineering
We can build one for you
Shipping four products of our own means we have already solved the parts that usually derail a first release — and that experience transfers directly to yours.
- Software that installs and stays supportable on hardware you don’t own
- Tenant isolation strict enough to survive a security review
- Licensing and activation that works on a restricted or air-gapped network
- A build-and-deploy pipeline with logs an auditor can read
- On-premise AI, where the data never leaves the customer’s perimeter
The hard part of selling software is rarely the feature list. It is everything that has to be true before a customer will run it.
Get in touch
Want to see one of them running?
We will stand up an evaluation on your own hardware — a gateway, a firewall or a Desk relay — or talk through the product you are trying to ship. Either conversation starts the same way.
Prefer to talk? The number is in the header, on every page.
