Products

Four products, three self-hosted plus SaaS Assess

Built to HIPAA and PCI DSS standards, with security as the first requirement rather than a hardening pass at the end. Mail, network edge, and web VDI / isolated agent desktops run on the customer’s own infrastructure. Secure Assess is multi-tenant SaaS for defensive PCI 11.3 scans. Each one exists because supporting healthcare IT since 2012 showed us exactly where the available software gave up. They are built to satisfy a clinical environment, which is simply a strict version of what any organization wants.

Hosted or managed Secure Message, Secure Desk, or SecureGuard is available by request — not a catalog SKU. Secure Assess is already multi-tenant SaaS; its own site owns signup. Describe the environment.

Product 01

Secure Message

Self-hosted secure email gateway

Outbound message protection, a one-time-code recipient portal, and layered inbound filtering — running as an appliance on the customer’s own network.

Most secure-email services route your mail through their servers, decrypt it to scan and store it, then push your recipients into a portal with yet another password. Secure Message inverts that: the gateway runs on the customer’s own network, every stored message and attachment is encrypted under their keys, and nothing in the mail path depends on us being reachable.

What it does

  • Messages and attachments encrypted at rest under keys the customer holds
  • Inbound on-box BEC and phishing score — the only AI in the mail path
  • Recipients read protected mail with a one-time code — no account, no app

The only AI is an inbound on-box BEC/phishing score.

Deployment
Appliance on your own network
Encryption
At rest, under your keys
Recipients
One-time code, no account
AI scoring
Inbound, on-box

Product 02

SecureGuard

Next-generation firewall & UTM appliance

An object-based, zone-aware firewall whose entire configuration is one document: validated, rendered into every daemon, and applied atomically instead of edited daemon by daemon.

Firewall outages are usually configuration accidents: a rule edited on a live box, NAT tangled through the filter policy, no way back except a restore. SecureGuard treats the whole configuration as one document — validated, rendered into every daemon, applied atomically — so a change is reviewable before it lands and reversible after it does.

What it does

  • Policy reads LAN → WAN using named objects, so re-cabling a site isn’t a policy migration
  • Preview the rendered diff before you commit — and a confirm window rolls back a change that locks you out
  • Every state is an immutable revision, so rollback is an id rather than a restore
  • The AI layer proposes changes and can throttle on a reputation score. A human commits. We do not advertise auto-block.

Rollback is an id, not a restore. Every config state is an immutable, content-addressed revision.

Model
Objects and zones, not IPs
Changes
Preview diff, then commit
History
Immutable revisions
AI layer
Propose / reputation; human commits

Product 03

Secure Desk

Web VDI and isolated AI-agent desktops on a relay you run

Persistent Windows desktops in the browser, and isolated desktops for AI agents, on a customer-run relay. The relay pairs sessions and forwards ciphertext — it cannot watch. Remote support is one use case, not the product.

Secure Desk is web VDI and isolated AI-agent desktops on a relay you run. Persistent Windows desktops in the browser; many agents, each with its own enrolled desktop and session keys. The relay only pairs sessions and forwards ciphertext — it cannot watch. Remote support is one use case on the same pipe, not the category.

What it does

  • End-to-end encrypted sessions — the relay forwards AES-256-GCM it holds no key for
  • No inbound firewall rules: both ends dial out to the relay you run
  • Per-session verification code, so both ends can confirm who they’re connected to

The relay forwards AES-256-GCM it holds no key for — and needs no inbound rule on the networks you reach. Desk does not run or orchestrate the agents.

Hosting
Your relay, your network
Session
End-to-end encrypted
Firewall
No inbound rules
Use cases
Web VDI, agent desktops, support

Product 04

Secure Assess

PCI 11.3 vulnerability assessment (SaaS)

Multi-tenant SaaS for defensive PCI 11.3 vulnerability assessment: we scan and advise, we never attack. Not a pentest and not an official ASV attestation.

Secure Assess is multi-tenant SaaS for PCI readiness and vulnerability assessment. Sign up in the app. We scan systems you authorize. We report and advise. We never attack. External and credentialed views of the same authorized scope. Findings are mapped to PCI DSS 11.3 vulnerability assessment — not 11.4 pentest, and not an official ASV attestation.

What it does

  • Scan systems you authorize — external and credentialed views of the same authorized scope
  • Findings mapped to PCI DSS 11.3 vulnerability assessment, not 11.4 penetration testing
  • We report and advise; we do not patch, remediate, or change the host we scanned

We scan and advise. We never attack.

Hosting
Multi-tenant SaaS
Scope
Authorized only — external + credentialed
Requirement
PCI DSS 11.3, not 11.4
Output
Report and advise — we never attack

Workstation signer

Office PDF Sign

Workstation PDF signer — no extra tenant

Fill, sign and flatten PDFs on the workstation. No cloud account, no extra tenant, no telemetry. Pairs with the Secure Message gateway you run.

Office PDF Sign runs on the workstation and pairs with Secure Message. Sign and flatten the document locally, then send it through the gateway you already run. No extra cloud tenant for signing. 1.4.0 for Windows is a free download. Mac is not published — this page does not promise a Mac file.

  • Type, date, checkmark and sign, then save a flattened copy
  • Edit the document’s own text instead of covering it over
  • Prepare fields for someone else to fill and sign
  • No account, no telemetry; the only network it uses is the update feed
  • No extra tenant; updates from hub.rubixtechnology.com

Free Windows installer

Rubix Certbot

Free Windows installer — no account

Free Windows installer. No account, no license. Authenticode-signed with the Rubix Technology public trust certificate.

Rubix Certbot is a free Windows installer. No account, no license. Authenticode-signed with the Rubix Technology public trust certificate. Check for Updates inside the app uses the same public feed.

  • Free Windows installer — $0, public download
  • No account, no license, no signup
  • Authenticode-signed with the Rubix Technology public trust certificate
  • Check for Updates inside the app uses the same public feed

Support & roadmap

Support is still the oldest thing we do

We were an IT support company for years before we sold software, and we still are one. A support agreement on a Rubix product is written by the same company that writes them for clinical environments — so a customer with a problem reaches engineers who can read the source, not a queue that only escalates.

  • Support from the people who wrote the code, under an agreement rather than a best-effort inbox
  • Nothing in the critical path of the self-hosted products depends on us being reachable — Message, Guard and Desk run on your own hardware, so your mail, your edge and your desktop sessions keep working regardless
  • We can add a feature in weeks because we use our own AI toolchain to build
  • Every release held to the standard our clinical customers set

Self-hosted means what you install is yours, on your hardware, under your keys.

Product engineering

We can build one for you

Shipping four products of our own means we have already solved the parts that usually derail a first release — and that experience transfers directly to yours.

  • Software that installs and stays supportable on hardware you don’t own
  • Tenant isolation strict enough to survive a security review
  • Licensing and activation that works on a restricted or air-gapped network
  • A build-and-deploy pipeline with logs an auditor can read
  • On-premise AI, where the data never leaves the customer’s perimeter

The hard part of selling software is rarely the feature list. It is everything that has to be true before a customer will run it.

Get in touch

Want to see one of them running?

We will stand up an evaluation on your own hardware — a gateway, a firewall or a Desk relay — or talk through the product you are trying to ship. Either conversation starts the same way.

Or email ussales@rubixtechnology.com

Prefer to talk? The number is in the header, on every page.