Bor
Bor is a self-hosted, open-source platform for centrally managing browser and firewall policies across Linux fleets. It uses an agent-based architecture where enrolled Linux nodes connect to a policy server via mTLS and receive policy definitions for Firefox, Thunderbird, Chrome, Edge, firewalld zones, and polkit rules. The web UI provides a dashboard for defining policies, monitoring node compliance, viewing audit logs, and delegating admin duties through role-based access control. Managed configuration files are protected from tampering and automatically restored if altered. Bor is designed for IT teams and MSPs that operate internal Linux infrastructure and need consistent security baselines without commercial endpoint management licensing.
Bor is a self-hosted, integrating with Firefox, Thunderbird, Chrome, and Microsoft Edge. InnovaAI scores it 3.3/10 for agency adoption, best for Operations Manager, Systems Administrator, and Founder roles handling weekly client-facing work.
Agency Audit
Bor is an open-source fleet management platform that centralizes browser and firewall policy enforcement across Linux desktops and servers via a web dashboard and agent-based architecture. It is built for IT-focused agencies and MSPs that operate internal Linux infrastructure and need to enforce consistent security baselines without commercial endpoint management licensing. Adoption pays off if your agency runs 5+ Linux nodes and currently manages browser policies, firewall rules, or compliance audits manually across machines. The platform delegates admin duties through role-based access control, making it suitable for ops teams that need to distribute policy enforcement without granting full system access.
5recommended
40/mo
No paid plan published
Moderate
Illustrative scenario. Not a guarantee. Net capacity needs a verified paid base plan, and none is published for this service, so it is not modeled. Hours saved come from the service estimate; implementation, taxes, and unprovided usage charges are excluded.
- Operations Manager handling linux fleet policy deployment
- Systems Administrator handling firewall rule management across multiple servers
- Founder handling compliance auditing and log review
- Your agency infrastructure is primarily Windows or macOS, or you do not operate internal Linux desktops and servers, because Bor only manages Linux endpoints.
- Your team has no in-house Linux systems expertise and cannot commit to self-hosted deployment, patching, and mTLS certificate management without external contractor support.
- You manage fewer than 5 Linux nodes, because the overhead of agent deployment and policy server maintenance exceeds the time savings from centralized policy enforcement.
Internal Adoption Path
No paid plan published
40 hr/mo
5 seats × 8 hr each
$3,000/mo
modeled at $75/hr labor rate
No paid plan published
Illustrative scenario. Not a guarantee. No verified paid base plan is published for this service, so subscription cost and net capacity are not modeled. Implementation, taxes, and unprovided usage charges are excluded.
Platform Features
Core capabilities of Bor
Centralized policy definition and push
Define browser policies for Firefox, Thunderbird, Chrome, and Edge once in the web UI, then push them to all enrolled Linux nodes simultaneously. Eliminates per-machine configuration for your Operations team and ensures policy consistency across the fleet.
Firewall and polkit rule management
Manage firewalld zones and polkit authorization rules from a single dashboard instead of SSH-ing into individual servers. Compresses firewall policy rollout from hours to minutes for your Ops lead.
Compliance monitoring and audit logs
View node compliance status and audit trails from a centralized dashboard, eliminating manual log review across machines. Gives your Operations Manager or compliance-focused team member real-time visibility into policy drift and configuration changes.
Tamper protection and automatic restoration
Bor automatically restores managed configuration files if they are altered, preventing unauthorized or accidental policy bypass. Reduces the need for your Ops team to manually audit and repair compromised configurations.
Role-based access control for policy delegation
Assign per-action admin permissions so junior ops staff or team members can apply specific policies without full system access. Lets your Founder or Operations Manager distribute routine policy tasks without security risk.
Agent-based enrollment and mTLS communication
Enroll Linux nodes via agent installation, with encrypted mTLS communication between agents and the policy server. Ensures secure policy delivery and prevents man-in-the-middle policy tampering.
What Makes Bor Different
Unique advantages vs similar tools in this niche
Tamper protection automatically restores managed policy files
vs Manual configuration management tools that don't detect unauthorized changesThe agent's tamper watcher detects external edits and immediately restores the original file.
Proto-driven policy catalogues ensure consistency across components
vs Tools with hardcoded policy definitions that can drift between server and agentPolicy catalogues are generated from protobuf annotations, providing one source of truth.
Per-action RBAC allows fine-grained delegation of admin duties
vs Tools with blanket admin permissions that limit delegationUser and role administration is guarded by per-action permissions instead of a single blanket permission.
Latest Updates
Recent releases and improvements for Bor
Bor v0.8.0 released
New2026-08-02Release adds three new policy types, Thunderbird, Microsoft Edge for Business, and Firewalld zones, alongside a full web UI overhaul, finer-grained RBAC, and a dedicated security hardening pass.
Thunderbird policy type
New2026-08-02Mozilla Thunderbird can now be managed on enrolled desktops; agent writes managed policies.json, supports Flatpak and RPM/DEB installations, with tamper watcher protection and a full policy editor in the web UI.
Microsoft Edge for Business policy type
New2026-08-02Agent writes bor_managed.json into Edge managed-policy directories on Linux; web UI provides a tree-based editor with Edge policy catalogue, JSON validation, and setting preview.
Firewalld zone policy type
New2026-08-02New Firewalld policy type manages firewalld zones on enrolled nodes; agent writes zone XML, validates with firewall-cmd --check-config, reloads firewalld, and tamper-protects zone files.
Web UI overhaul
Improvement2026-08-02Full modernization pass over PatternFly 6 interface including URL routing, full-page policy editor, scalable server-side paginated lists, destructive-action protection, and WCAG 2.2 AA accessibility improvements.
Value Equation
Outcome-likelihood-time-effort assessment for Bor
Value math requires real pricing
The Value Equation (dream outcome × likelihood ÷ time × effort) feeds directly into ROI math. Bor has no published pricing, so we hold this section until real numbers are available.
Contact BorPricing
Pricing data not yet available for Bor.
Reality Check
Bor requires Linux-only infrastructure; it does not manage Windows or macOS endpoints. Adoption complexity rises if your team lacks familiarity with mTLS agent deployment or firewall policy syntax. Self-hosted open-source platforms demand internal maintenance and security patching, which adds operational overhead compared to SaaS alternatives.
High effort: requires technical configuration and team training
How This Accelerates White-Label Services
Who It's For
- ✓it-services-agencies
- ✓managed-security-service-providers
- ✓linux-focused-msps
Acceleration Steps
- 1Schedule onboarding with the vendor
- 2Configure enroll linux desktops and servers into a centralized fleet management platform
- 3Connect Firefox
- 4Launch your first client project
Academy for Bor
Work through it in order: the course for this service first, then the modules behind it.
No Academy modules are published for this service yet. Browse the full Academy
Why this category matters
The commercial case before the tooling.
Core concepts
The mental model you need to price and scope the work.
- Liability CeilingConcept
Liability Ceiling is the maximum exposure an agency accepts when it sells security as an outcome rather than as a process. Every retainer that promises "we will keep you secure" converts an evolving attack surface into a contractual obligation the agency cannot fully control. The framework asks one question before signing: what is the worst-case dollar figure if this control fails, and who pays it? Agencies that sell detection, monitoring, and documented response steps cap their exposure at labor and tooling cost. Agencies that sell guarantees inherit the breach. A documented case from September 2026 shows a vibe-coded client app with exposed API keys generating a $4,000+ unauthorized usage bill, small enough to absorb but proof that the failure mode is financial, not theoretical. Set the ceiling in the statement of work: name the controls in scope, the review cadence, and the response time, then price the retainer against that scope instead of against an outcome you cannot underwrite.
- Blast Radius BudgetConcept
Blast Radius Budget treats every automated workflow as a spend of trust: the more autonomy an agent gets, the smaller the radius of damage it must be able to cause before a human checkpoint fires. Agencies scope security not by counting tools but by mapping what each automation can touch (client CRM records, ad accounts, production repos, payment keys) and capping the worst-case outcome. A workflow that drafts copy can run unattended; one that sends client-facing email or rotates credentials cannot. The budget is set per client, per retainer tier, and reviewed when scope expands. The failure mode is real: exposed API keys in AI-built client apps have produced bills above $4,000 from unauthorized calls, a cost that lands on the agency's invoice and reputation, not the model vendor's. Pair the budget with runtime controls such as Vaultak's action interception or Cogent's attack-path mapping so the cap is enforced, not just documented.
- Trust Premium DecayConcept
Trust Premium Decay treats every security promise an agency makes as a depreciating asset rather than a fixed credential. A SOC 2 badge, an encrypted client portal, or a clean scan earns trust at signature, then loses value as attack surfaces change and the evidence behind the claim ages. Agencies that re-verify on a cadence keep the premium; those that coast on a one-time audit watch it erode quietly until an incident reprices the whole retainer. The framework forces a simple question at renewal: what did we prove this quarter, and when? A concrete example sits in the $4,000+ API bills traced to exposed keys in AI-built client apps, where a single leaked credential converts a trust asset into a liability line item overnight. Pairing periodic re-verification with incident response keeps the premium compounding instead of decaying.
Decision and risk
How to judge the fit, and the ways it goes wrong.
- Security Tools Rule: Price the Liability Before You Price the RetainerEvaluation Rule
Split every security engagement into a fixed-fee detection and hardening deliverable plus a separately contracted advisory layer, and never let a retainer contract contain the words guaranteed, secure, or protected without a written scope boundary.
- When Client Workflows Run Autonomous Agents, Gate the Actions Before You Sell the RetainerEvaluation Rule
Buy the enforcement layer first and the detection layer second, because a tool that can block or reverse an agent action is worth more to a retainer than one that only files a finding.
- Security Tools Decision: Proactive Threat Modeling Retainer vs Reactive Incident ResponseDecision Framework
IF your agency already holds recurring access to client infrastructure, repositories, or marketing data pipelines, THEN sell a proactive threat-modeling retainer that bundles vulnerability scanning, secret hygiene, and access review into the existing monthly scope. IF clients only call after a breach, a leaked key, or a compliance questionnaire lands, THEN keep security as a reactive, project-priced incident response engagement and avoid promising continuous coverage you cannot staff.
- The Absolute-Security Trap: Why Security Tools Stall in Agency RetainersFailure Pattern
- The Scan-Once Trap: Why Security Tools Stall in Agency Delivery After the First ReportFailure Pattern
Delivery system
Blueprints and procedures for running it as a service.
- Proactive Threat Modeling and Incident Response Retainer (10-14 days)Implementation Blueprint
A productized security engagement that maps client attack paths, closes the highest-severity gaps, and leaves a documented incident response runbook the agency can operate on retainer.
- Pre-Engagement Security Scoping (Onboarding)Operating Procedure
- Agent Action Rollback Drill (QA)Operating Procedure
- Client Security Posture Handoff (Handoff)Operating Procedure
13 modules selected for Bor
Frequently Asked Questions
Answers about pricing, setup, implementation
Bor is an open-source platform that enrolls Linux desktops and servers into a centralized fleet and enforces browser policies (Firefox, Thunderbird, Chrome, Edge), firewall rules (firewalld zones), and authorization policies (polkit) across all enrolled nodes. It provides a web dashboard for policy definition, compliance monitoring, audit logging, and role-based access control, with agents on each node enforcing policies and protecting managed files from tampering.
Bor is open-source and free to deploy. There is no per-seat licensing cost. Your agency covers only the infrastructure cost of running the policy server and the time investment in deployment and maintenance.
Operations Managers and Systems Administrators benefit most, as Bor eliminates manual per-machine policy configuration and centralizes compliance auditing. Founders and Operations leads gain value from role-based access control, which lets them delegate policy enforcement to junior staff without granting full system access. IT service agencies and MSPs that manage client or internal Linux fleets see the largest time savings.
For an Operations team managing 10+ Linux nodes with monthly policy updates, Bor typically saves 4-6 hours per month by eliminating per-machine SSH configuration and manual audit log review. Savings scale with fleet size and policy change frequency. Agencies with fewer than 5 nodes or infrequent policy changes see minimal time recovery.
No. Bor only manages Linux desktops and servers. If your agency infrastructure includes Windows or macOS machines, you will need a separate endpoint management tool for those platforms.
Initial deployment of the policy server and agent installation on 5-10 Linux nodes typically takes 2-4 hours for a team with Linux systems experience. Ongoing policy updates and node enrollment take 15-30 minutes per node after the initial setup.