AI ToolSecurity Tools

Bor

Bor is a self-hosted, open-source platform for centrally managing browser and firewall policies across Linux fleets.

Bor is a self-hosted, integrating with Firefox, Thunderbird, Chrome, and Microsoft Edge. InnovaAI scores it 3.3/10 for agency adoption, best for Operations Manager, Systems Administrator, and Founder roles handling weekly client-facing work.

Situational Fit3.3/10

Agency Audit

Bor is an open-source fleet management platform that centralizes browser and firewall policy enforcement across Linux desktops and servers via a web dashboard and agent-based architecture. It is built for IT-focused agencies and MSPs that operate internal Linux infrastructure and need to enforce consistent security baselines without commercial endpoint management licensing. Adoption pays off if your agency runs 5+ Linux nodes and currently manages browser policies, firewall rules, or compliance audits manually across machines. The platform delegates admin duties through role-based access control, making it suitable for ops teams that need to distribute policy enforcement without granting full system access.

Situational FitNo WLOpen Source
Seats

5recommended

Est. Hours Saved

40/mo

Net Capacity

No paid plan published

Friction

Moderate

Illustrative scenario. Not a guarantee. Net capacity needs a verified paid base plan, and none is published for this service, so it is not modeled. Hours saved come from the service estimate; implementation, taxes, and unprovided usage charges are excluded.

Situational Fit
Fit33
Visit Bor
Best For Your Team
  • Operations Manager handling linux fleet policy deployment
  • Systems Administrator handling firewall rule management across multiple servers
  • Founder handling compliance auditing and log review
Not Ideal If
  • Your agency infrastructure is primarily Windows or macOS, or you do not operate internal Linux desktops and servers, because Bor only manages Linux endpoints.
  • Your team has no in-house Linux systems expertise and cannot commit to self-hosted deployment, patching, and mTLS certificate management without external contractor support.
  • You manage fewer than 5 Linux nodes, because the overhead of agent deployment and policy server maintenance exceeds the time savings from centralized policy enforcement.

Internal Adoption Path

Team Subscription

No paid plan published

Time Saved Monthly

40 hr/mo

5 seats × 8 hr each

Value of Reclaimed Time

$3,000/mo

modeled at $75/hr labor rate

Net Capacity

No paid plan published

Illustrative scenario. Not a guarantee. No verified paid base plan is published for this service, so subscription cost and net capacity are not modeled. Implementation, taxes, and unprovided usage charges are excluded.

Platform Features

Core capabilities of Bor

Centralized policy definition and push

Define browser policies for Firefox, Thunderbird, Chrome, and Edge once in the web UI, then push them to all enrolled Linux nodes simultaneously. Eliminates per-machine configuration for your Operations team and ensures policy consistency across the fleet.

Firewall and polkit rule management

Manage firewalld zones and polkit authorization rules from a single dashboard instead of SSH-ing into individual servers. Compresses firewall policy rollout from hours to minutes for your Ops lead.

Compliance monitoring and audit logs

View node compliance status and audit trails from a centralized dashboard, eliminating manual log review across machines. Gives your Operations Manager or compliance-focused team member real-time visibility into policy drift and configuration changes.

Tamper protection and automatic restoration

Bor automatically restores managed configuration files if they are altered, preventing unauthorized or accidental policy bypass. Reduces the need for your Ops team to manually audit and repair compromised configurations.

Role-based access control for policy delegation

Assign per-action admin permissions so junior ops staff or team members can apply specific policies without full system access. Lets your Founder or Operations Manager distribute routine policy tasks without security risk.

Agent-based enrollment and mTLS communication

Enroll Linux nodes via agent installation, with encrypted mTLS communication between agents and the policy server. Ensures secure policy delivery and prevents man-in-the-middle policy tampering.

What Makes Bor Different

Unique advantages vs similar tools in this niche

Tamper protection automatically restores managed policy files

vs Manual configuration management tools that don't detect unauthorized changes

The agent's tamper watcher detects external edits and immediately restores the original file.

Proto-driven policy catalogues ensure consistency across components

vs Tools with hardcoded policy definitions that can drift between server and agent

Policy catalogues are generated from protobuf annotations, providing one source of truth.

Per-action RBAC allows fine-grained delegation of admin duties

vs Tools with blanket admin permissions that limit delegation

User and role administration is guarded by per-action permissions instead of a single blanket permission.

Latest Updates

Recent releases and improvements for Bor

Bor v0.8.0 released

New2026-08-02

Release adds three new policy types, Thunderbird, Microsoft Edge for Business, and Firewalld zones, alongside a full web UI overhaul, finer-grained RBAC, and a dedicated security hardening pass.

Thunderbird policy type

New2026-08-02

Mozilla Thunderbird can now be managed on enrolled desktops; agent writes managed policies.json, supports Flatpak and RPM/DEB installations, with tamper watcher protection and a full policy editor in the web UI.

Microsoft Edge for Business policy type

New2026-08-02

Agent writes bor_managed.json into Edge managed-policy directories on Linux; web UI provides a tree-based editor with Edge policy catalogue, JSON validation, and setting preview.

Firewalld zone policy type

New2026-08-02

New Firewalld policy type manages firewalld zones on enrolled nodes; agent writes zone XML, validates with firewall-cmd --check-config, reloads firewalld, and tamper-protects zone files.

Web UI overhaul

Improvement2026-08-02

Full modernization pass over PatternFly 6 interface including URL routing, full-page policy editor, scalable server-side paginated lists, destructive-action protection, and WCAG 2.2 AA accessibility improvements.

Value Equation

Outcome-likelihood-time-effort assessment for Bor

Value math requires real pricing

The Value Equation (dream outcome × likelihood ÷ time × effort) feeds directly into ROI math. Bor has no published pricing, so we hold this section until real numbers are available.

Contact Bor

Pricing

Pricing data not yet available for Bor.

Reality Check

Trade-offs & Gotchas

Bor requires Linux-only infrastructure; it does not manage Windows or macOS endpoints. Adoption complexity rises if your team lacks familiarity with mTLS agent deployment or firewall policy syntax. Self-hosted open-source platforms demand internal maintenance and security patching, which adds operational overhead compared to SaaS alternatives.

Implementation Reality

High effort: requires technical configuration and team training

Effort: 4/10Time: 4/10

How This Accelerates White-Label Services

Who It's For

  • it-services-agencies
  • managed-security-service-providers
  • linux-focused-msps

Acceleration Steps

  1. 1Schedule onboarding with the vendor
  2. 2Configure enroll linux desktops and servers into a centralized fleet management platform
  3. 3Connect Firefox
  4. 4Launch your first client project

Academy for Bor

Work through it in order: the course for this service first, then the modules behind it.

Core concepts

The mental model you need to price and scope the work.

  1. Defense-in-Depth StackingConcept

    Defense-in-Depth Stacking is the practice of layering independent security controls so that a failure in any single layer does not expose the whole system. For agencies, this framework is essential because client deliverables and internal operations are prime targets for breaches, and no single tool can promise absolute security. Instead, agencies should combine complementary controls: endpoint protection, access management, threat detection, and data encryption. For example, an agency might pair Cogent's VR-1 for attack path mapping with Tresorit's end-to-end encrypted storage to protect client files, while using hCaptcha to block automated attacks on client websites. Each layer addresses a different risk vector, and together they create a resilient posture that agencies can market as a trust factor and recurring revenue stream.

  2. Trust Surface MappingConcept

    Trust Surface Mapping is a framework for agencies to visualize every point where client data, deliverables, or internal operations touch third-party systems, AI models, or automated agents. Each touchpoint is a trust surface: a place where a breach, data leak, or unauthorized modification can occur, directly impacting client confidence and agency liability. Agencies that map these surfaces can prioritize security investments where exposure is highest, rather than applying blanket protections. For example, when an AI agent modifies approved creative post-launch, as seen in a recent campaign incident, the trust surface includes the ad platform, the AI tool, and the approval workflow. By mapping these, agencies can implement verification checkpoints and contractual safeguards. This framework turns security from a cost center into a strategic trust differentiator, enabling agencies to confidently offer managed security services as a recurring revenue stream.

  3. Liability Boundary PricingConcept

    Liability Boundary Pricing frames security offerings not as feature bundles but as contractual risk transfers. Agencies that promise 'absolute security' inherit unlimited downside when a breach occurs; those that scope guarantees to specific controls (e.g., encryption at rest, MFA enforcement) convert security into a recurring revenue stream with a defined ceiling on liability. The framework maps each security service to a liability boundary: where does the agency's responsibility end and the client's begin? For example, an agency offering deepfake detection with Resemble AI can guarantee detection accuracy against known generative models, but not against future unknown ones, so the contract must cap liability at the cost of the detection service. Similarly, using hCaptcha for bot protection limits liability to blocking automated traffic, not human fraud. By pricing each boundary separately, agencies protect margins while still selling trust.

8 modules selected for Bor

Frequently Asked Questions

Answers about pricing, setup, implementation

Bor is an open-source platform that enrolls Linux desktops and servers into a centralized fleet and enforces browser policies (Firefox, Thunderbird, Chrome, Edge), firewall rules (firewalld zones), and authorization policies (polkit) across all enrolled nodes. It provides a web dashboard for policy definition, compliance monitoring, audit logging, and role-based access control, with agents on each node enforcing policies and protecting managed files from tampering.

Bor is open-source and free to deploy. There is no per-seat licensing cost. Your agency covers only the infrastructure cost of running the policy server and the time investment in deployment and maintenance.

Operations Managers and Systems Administrators benefit most, as Bor eliminates manual per-machine policy configuration and centralizes compliance auditing. Founders and Operations leads gain value from role-based access control, which lets them delegate policy enforcement to junior staff without granting full system access. IT service agencies and MSPs that manage client or internal Linux fleets see the largest time savings.

For an Operations team managing 10+ Linux nodes with monthly policy updates, Bor typically saves 4-6 hours per month by eliminating per-machine SSH configuration and manual audit log review. Savings scale with fleet size and policy change frequency. Agencies with fewer than 5 nodes or infrequent policy changes see minimal time recovery.

No. Bor only manages Linux desktops and servers. If your agency infrastructure includes Windows or macOS machines, you will need a separate endpoint management tool for those platforms.

Initial deployment of the policy server and agent installation on 5-10 Linux nodes typically takes 2-4 hours for a team with Linux systems experience. Ongoing policy updates and node enrollment take 15-30 minutes per node after the initial setup.