Pillar 03 · Secure · Helix

DNA firewall — if it isn’t certified, it doesn’t pass.

Helix asks one question: is this still the certified app? Learn, promote, shadow, then enforce from live traffic DNA. Allow while securing.

  1. 01 Learn record DNA
  2. 02 Promote sign identity
  3. 03 Shadow alert only
  4. 04 Enforce block holes
Helix DNA firewall: live traffic feeds certified app DNA (route, schema, status). Learn records, shadow alerts, enforce blocks DNA holes with 403. Allow while securing; augment NGFW; optional CWL bridge.

How Helix runs

Allow traffic while you secure it.

Modes separate pass from trust. You never flip from “open internet” to “locked” in one scary click.

  1. 01 · Learn Pass + record

    Watch production

    Observe real requests and responses. Build app-dna from what the app actually does.

    • Traffic still flows
    • Baseline forms
  2. 02 · Promote Review + sign

    Certify the DNA

    Diff the certificate. Promote only what you intend. Reload without downtime.

    • Human-reviewed diff
    • Hot reload
  3. 03 · Shadow Pass + alert

    Score without blocking

    Live traffic vs certified DNA. Holes alert only — users keep working.

    • Drift visible
    • Zero user impact
  4. 04 · Enforce Block · 403

    Fail closed

    Unauthorized surface stops. We don’t allow app shape we didn’t certify.

    • Unknown routes die
    • Certified shape holds

What DNA fingerprints

Identity, not payload theater.

Routes

Which URLs and methods the app is allowed to expose — new paths are holes until promoted.

Schema · query

Shape of bodies and query strings that belong to certified routes — drift shows up as identity failure.

Status · behavior

Expected response patterns for the certified surface — what “normal” looks like for that route.

A DNA hole means Helix saw app shape it never certified (unknown route, schema drift, and so on). It is about identity, not scanning every payload for classic web attacks.

Where Helix sits

In front of your app. No firewall redesign.

Internet clients hit Helix on the public port. Helix talks to your app on localhost. Your existing NGFW / NAT stays put — Helix is the identity layer in front of the process.

Operators call this Mode A: same box, public listener moves to Helix, app binds loopback. You keep allowing traffic while Helix learns, shadows, then enforces.

What Helix does

Only certified app behavior gets through.

Helix watches real traffic, learns what your app normally does, then blocks new routes and shapes that were never part of that picture. You turn it on without CWL or Convert.

Chrysalis Web Language is a separate pillar for describing and translating apps. Helix does not need it to protect. If you later want a migration’s claimed surface checked against live traffic, that is when CWL can connect — not before.