COMPLETE FEATURE CATALOG

More than protection. Control.

IRONWALL protects the files you keep, the passwords you use, the messages you receive, and the devices connected to your home - all from one local-first Windows Control Center.

AES-256Authenticated file encryption performed locally.
5 GBMaximum size for each file you encrypt.
OfflinePassword, bank, card, and secure-note vault.
6 waysFlexible security-alert delivery channels.
NEW IN IRONWALL

Protect sensitive files and private records without sending them to the cloud.

The newest IRONWALL tools add strong local file encryption and a Windows-protected offline vault. They work alongside the existing malware, phishing, identity, network, health, and notification features.

FILE ENCRYPTION

AES-256 protection for files up to 5 GB.

IRONWALL uses AES-256-GCM authenticated encryption to help prevent unauthorized viewing or modification. Processing stays local and uses smaller chunks for large files.

AES-256-GCMEncryption and integrity
5 GBMaximum file size
LocalNo cloud upload
  • Browse for a file instead of typing its path.
  • See processing progress for large documents, photos, videos, archives, and backups.
  • Keep the original file until you verify the encrypted copy.
  • Detect an incorrect key or altered encrypted data during decryption.
  • Use one unique decryption key that is displayed only once.
Important: Save the decryption key securely. IRONWALL does not display it again, and CYBALITY cannot recover encrypted files if the key is lost.
PASSWORD MANAGER

Your private vault, offline by default.

The IRONWALL vault stores sensitive records locally on the Windows computer and protects the vault with Windows Data Protection API encryption.

DPAPIWindows-based protection
4 record typesPasswords, bank, cards, notes
EncryptedBackup and migration
  • Create, view, and edit website, application, and service logins.
  • Store usernames, passwords, website addresses, and private notes.
  • Organize bank-account and credit-card information separately.
  • Protect recovery codes, software keys, instructions, and identification details in Secure Notes.
  • Export an encrypted backup protected by a separate export password.
  • Import the encrypted backup to restore or migrate the vault.
EVERY FEATURE, ORGANIZED

One suite. Ten protection areas.

01 / CONTROL CENTER

Clear security management

Understand your current protection, find what needs attention, and review important activity without digging through multiple tools.

Overview dashboard

See protection status, recent activity, schedules, findings, and device information in one place.

IRONWALL Security Score

Turns technical signals into an easy score with plain-language recommendations.

Security Center

Review unresolved findings and prioritize the items that need action.

Unresolved-alert badges

Dashboard badges make pending security work visible at a glance.

Security event timeline

Combines important findings and activity in chronological order.

Searchable histories

Search and filter scan, phishing, device, alert, and notification history.

Dark and light appearance

Choose the dashboard theme that is most comfortable to use.

Weekly security reports

Summarizes protection health, scans, findings, devices, and recent activity.

02 / ANTIVIRUS

File and malware protection

Scan the places where threats commonly arrive, isolate confirmed detections, and keep malware definitions current automatically.

Confirmed-threat scanning

Checks files against malware, virus, and adware signatures instead of judging a filename alone.

One-click Quick Scan

Checks Downloads, Desktop, and common temporary folders.

Custom file and folder scans

Browse to a specific file or folder and scan it on demand.

Automatic download monitoring

Watches local Downloads folders and scans new files after writes stabilize.

Scheduled scans

Run security scans automatically using independent schedules.

External-drive scanning

Check mounted USB and external storage for suspicious files.

Quarantine and restore

Isolate confirmed critical threats, inspect details, restore approved files, or remove them.

Trusted-file allowlist

Exclude files you have reviewed and approved.

Automatic definition updates

Refreshes malware definitions daily and reports current or update-error status.

Scan history

Records scan type, target, result, detection details, timing, and status.

03 / ENCRYPTION

Local file encryption

Protect confidential documents, financial records, identification files, photos, videos, archives, and backups.

AES-256-GCM encryption

Provides strong authenticated encryption and detects incorrect keys or altered encrypted data.

Files up to 5 GB

Chunked processing reduces memory use while progress keeps the user informed.

Easy file selection

Uses browser-based file selection with an optional Windows path picker as a secondary method.

One-time decryption key

Generates a unique key, displays it once, and requires it whenever a file is decrypted.

Original-file protection

Preserves the unencrypted original so the encrypted copy can be verified before deletion.

Local processing

Encrypts and decrypts on the computer without uploading the selected file to the cloud.

04 / PASSWORD VAULT

Offline password manager

Replace unsecured notes and scattered documents with an organized local vault tied to the Windows environment.

Secure offline vault

Stores sensitive records locally and protects vault data with Windows Data Protection API encryption.

Password records

Save account names, usernames, passwords, websites, and additional notes.

Bank-account records

Organize important account information separately from ordinary files.

Credit-card records

Keep personal card information offline instead of in unprotected notes.

Secure Notes

Protect recovery codes, software keys, instructions, identification details, and other sensitive text.

Encrypted export and import

Back up or migrate the vault using an encrypted file protected by an export password.

05 / PHISHING & URLS

Plain-language risk analysis

Inspect suspicious messages, links, domains, certificates, and connection metadata without requiring users to interpret raw technical signals.

Email-file analysis

Browse to a saved .eml message and inspect its sender, headers, links, and attachments.

Header authentication checks

Reviews SPF, DKIM, DMARC, routing, and sender inconsistencies.

QR-code lure detection

Looks for QR codes that may conceal phishing destinations.

Link and redirect inspection

Examines redirect chains, risky terms, suspicious patterns, and final destinations.

Lookalike-domain detection

Flags domains designed to imitate a familiar brand or service.

Domain and IP reputation

Combines local analysis and configured reputation signals for clearer risk context.

TLS certificate checks

Reviews certificate validity and expiration information for a domain.

Verbal risk levels

Pairs the score with No Risk Detected, Low, Medium, or High and explains what the level means.

Monitor-only network protection

Observes hostnames, IPs, TLS SNI, certificates, and traffic volume without decrypting HTTPS.

Trusted sender, domain, and IP lists

Lets users approve reviewed sources and reduce repeat alerts.

06 / IDENTITY & EXPOSURE

Personal exposure awareness

Bring public-record, dark-web, and social-profile awareness into the same security workflow.

Authorized identity monitoring

Monitor identifiers the user is authorized to check for possible exposure.

Masked sensitive values

Reduces unnecessary exposure by concealing stored identifiers in results.

Public-record search

Organizes public-record findings and source links for review.

Social username search

Checks a username against a selected social platform.

Exposure history

Keeps prior results available for comparison and follow-up.

Scheduled monitoring

Runs configured exposure checks without requiring repeated manual searches.

07 / HOME NETWORK

Connected-device visibility

Know what is connected, establish what belongs, and receive notice when something unfamiliar appears.

Network device discovery

Scans the local network and organizes connected devices.

Trusted-device baseline

Creates a known-device inventory for future comparisons.

New-device alerts

Warns when a device appears that is not part of the trusted baseline.

Device details

Shows available IP, hostname, hardware address, vendor, first-seen, and last-seen context.

Trusted and blocked classifications

Organizes approved devices and devices that require attention.

Scheduled network scans

Checks the home network automatically on the user’s schedule.

Duplicate-event suppression

Combines repeat device alerts while preserving occurrence details.

Remote dashboard option

Allows controlled access to the IRONWALL interface from another computer when enabled.

08 / SECURITY HEALTH

System and application checks

Turn important Windows and software-security settings into clear status checks and recommended actions.

Windows security health

Reviews key protection settings and highlights conditions that may weaken the computer.

Firewall and update awareness

Shows whether important Windows protections and update status need attention.

App Signature Checker

Reviews an application’s signature and publisher information before trust decisions.

Installer Check

Inspects publisher, signature, certificate, cryptographic hash, and version details.

Certificate-expiration monitoring

Tracks configured certificates and warns before expiration.

Recommended actions

Explains findings in plain language and suggests a practical next step.

09 / ALERTS & AUTOMATION

Useful alerts, less noise

Choose how protection runs and where important notices arrive while reducing repetitive notifications.

Six notification channels

Send alerts through Windows, email, Home Assistant, Pushover, Telegram, or Slack.

Notification Test Center

Verifies configured channels before an actual security event occurs.

Independent schedules

Controls scans, monitoring, reports, and other recurring security work separately.

Temporary alert snooze

Pause noncritical notices for an hour or until tomorrow.

Duplicate-alert suppression

Reduces repeated noise while retaining first-seen, last-seen, and occurrence counts.

Notification history

Records delivery attempts, status, message type, channel, and errors.

10 / PRIVACY & ADMINISTRATION

Local-first control

Keep routine security data under the user’s control and make maintenance, backup, recovery, and troubleshooting easier.

Local-first storage

Stores routine findings, device history, scan results, schedules, settings, and vault records on the protected computer.

No HTTPS decryption

Does not install a trusted root certificate, capture passwords, or read webpage contents.

Windows-protected secrets

Uses Windows Data Protection API encryption for supported locally stored secrets.

Trusted-item allowlists

Manage approved files, devices, domains, IP addresses, senders, and applications.

Settings export and import

Move supported configuration between installations.

Database backup and restore

Protects local security history and configuration against accidental loss.

Log cleanup and retention

Controls how long operational records are kept and removes older logs automatically.

Troubleshooting logs

Provides clearer diagnostics when a scanner, update, picker, notification, or service encounters an error.

System tray and automatic start

Keeps protection services available when the main dashboard is closed.

Trial and product-key access

Supports time-limited trial access and licensed product-key activation.

READY TO PROTECT MORE?

Start your free IRONWALL trial.

Choose Windows to download the current installer. The macOS option is reserved and will become available separately.

Choose your platform