Bor
Bor is a self-hosted, open-source platform for centrally managing browser and firewall policies across Linux fleets. It uses an agent-based architecture where enrolled Linux nodes connect to a policy server via mTLS and receive policy definitions for Firefox, Thunderbird, Chrome, Edge, firewalld zones, and polkit rules. The web UI provides a dashboard for defining policies, monitoring node compliance, viewing audit logs, and delegating admin duties through role-based access control. Managed configuration files are protected from tampering and automatically restored if altered. Bor is designed for IT teams and MSPs that operate internal Linux infrastructure and need consistent security baselines without commercial endpoint management licensing.
Bor is a self-hosted, integrating with Firefox, Thunderbird, Chrome, and Microsoft Edge. InnovaAI scores it 3.3/10 for agency adoption, best for Operations Manager, Systems Administrator, and Founder roles handling weekly client-facing work.
Agency Audit
Bor is an open-source fleet management platform that centralizes browser and firewall policy enforcement across Linux desktops and servers via a web dashboard and agent-based architecture. It is built for IT-focused agencies and MSPs that operate internal Linux infrastructure and need to enforce consistent security baselines without commercial endpoint management licensing. Adoption pays off if your agency runs 5+ Linux nodes and currently manages browser policies, firewall rules, or compliance audits manually across machines. The platform delegates admin duties through role-based access control, making it suitable for ops teams that need to distribute policy enforcement without granting full system access.
5recommended
40/mo
No paid plan published
Moderate
Illustrative scenario. Not a guarantee. Net capacity needs a verified paid base plan, and none is published for this service, so it is not modeled. Hours saved come from the service estimate; implementation, taxes, and unprovided usage charges are excluded.
- Operations Manager handling linux fleet policy deployment
- Systems Administrator handling firewall rule management across multiple servers
- Founder handling compliance auditing and log review
- Your agency infrastructure is primarily Windows or macOS, or you do not operate internal Linux desktops and servers, because Bor only manages Linux endpoints.
- Your team has no in-house Linux systems expertise and cannot commit to self-hosted deployment, patching, and mTLS certificate management without external contractor support.
- You manage fewer than 5 Linux nodes, because the overhead of agent deployment and policy server maintenance exceeds the time savings from centralized policy enforcement.
Internal Adoption Path
No paid plan published
40 hr/mo
5 seats × 8 hr each
$3,000/mo
modeled at $75/hr labor rate
No paid plan published
Illustrative scenario. Not a guarantee. No verified paid base plan is published for this service, so subscription cost and net capacity are not modeled. Implementation, taxes, and unprovided usage charges are excluded.
Platform Features
Core capabilities of Bor
Centralized policy definition and push
Define browser policies for Firefox, Thunderbird, Chrome, and Edge once in the web UI, then push them to all enrolled Linux nodes simultaneously. Eliminates per-machine configuration for your Operations team and ensures policy consistency across the fleet.
Firewall and polkit rule management
Manage firewalld zones and polkit authorization rules from a single dashboard instead of SSH-ing into individual servers. Compresses firewall policy rollout from hours to minutes for your Ops lead.
Compliance monitoring and audit logs
View node compliance status and audit trails from a centralized dashboard, eliminating manual log review across machines. Gives your Operations Manager or compliance-focused team member real-time visibility into policy drift and configuration changes.
Tamper protection and automatic restoration
Bor automatically restores managed configuration files if they are altered, preventing unauthorized or accidental policy bypass. Reduces the need for your Ops team to manually audit and repair compromised configurations.
Role-based access control for policy delegation
Assign per-action admin permissions so junior ops staff or team members can apply specific policies without full system access. Lets your Founder or Operations Manager distribute routine policy tasks without security risk.
Agent-based enrollment and mTLS communication
Enroll Linux nodes via agent installation, with encrypted mTLS communication between agents and the policy server. Ensures secure policy delivery and prevents man-in-the-middle policy tampering.
What Makes Bor Different
Unique advantages vs similar tools in this niche
Tamper protection automatically restores managed policy files
vs Manual configuration management tools that don't detect unauthorized changesThe agent's tamper watcher detects external edits and immediately restores the original file.
Proto-driven policy catalogues ensure consistency across components
vs Tools with hardcoded policy definitions that can drift between server and agentPolicy catalogues are generated from protobuf annotations, providing one source of truth.
Per-action RBAC allows fine-grained delegation of admin duties
vs Tools with blanket admin permissions that limit delegationUser and role administration is guarded by per-action permissions instead of a single blanket permission.
Latest Updates
Recent releases and improvements for Bor
Bor v0.8.0 released
New2026-08-02Release adds three new policy types, Thunderbird, Microsoft Edge for Business, and Firewalld zones, alongside a full web UI overhaul, finer-grained RBAC, and a dedicated security hardening pass.
Thunderbird policy type
New2026-08-02Mozilla Thunderbird can now be managed on enrolled desktops; agent writes managed policies.json, supports Flatpak and RPM/DEB installations, with tamper watcher protection and a full policy editor in the web UI.
Microsoft Edge for Business policy type
New2026-08-02Agent writes bor_managed.json into Edge managed-policy directories on Linux; web UI provides a tree-based editor with Edge policy catalogue, JSON validation, and setting preview.
Firewalld zone policy type
New2026-08-02New Firewalld policy type manages firewalld zones on enrolled nodes; agent writes zone XML, validates with firewall-cmd --check-config, reloads firewalld, and tamper-protects zone files.
Web UI overhaul
Improvement2026-08-02Full modernization pass over PatternFly 6 interface including URL routing, full-page policy editor, scalable server-side paginated lists, destructive-action protection, and WCAG 2.2 AA accessibility improvements.
Value Equation
Outcome-likelihood-time-effort assessment for Bor
Value math requires real pricing
The Value Equation (dream outcome × likelihood ÷ time × effort) feeds directly into ROI math. Bor has no published pricing, so we hold this section until real numbers are available.
Contact BorPricing
Pricing data not yet available for Bor.
Reality Check
Bor requires Linux-only infrastructure; it does not manage Windows or macOS endpoints. Adoption complexity rises if your team lacks familiarity with mTLS agent deployment or firewall policy syntax. Self-hosted open-source platforms demand internal maintenance and security patching, which adds operational overhead compared to SaaS alternatives.
High effort: requires technical configuration and team training
How This Accelerates White-Label Services
Who It's For
- ✓it-services-agencies
- ✓managed-security-service-providers
- ✓linux-focused-msps
Acceleration Steps
- 1Schedule onboarding with the vendor
- 2Configure enroll linux desktops and servers into a centralized fleet management platform
- 3Connect Firefox
- 4Launch your first client project
Academy for Bor
Work through it in order: the course for this service first, then the modules behind it.
No Academy modules are published for this service yet. Browse the full Academy
Why this category matters
The commercial case before the tooling.
Core concepts
The mental model you need to price and scope the work.
- Defense-in-Depth StackingConcept
Defense-in-Depth Stacking is the practice of layering independent security controls so that a failure in any single layer does not expose the whole system. For agencies, this framework is essential because client deliverables and internal operations are prime targets for breaches, and no single tool can promise absolute security. Instead, agencies should combine complementary controls: endpoint protection, access management, threat detection, and data encryption. For example, an agency might pair Cogent's VR-1 for attack path mapping with Tresorit's end-to-end encrypted storage to protect client files, while using hCaptcha to block automated attacks on client websites. Each layer addresses a different risk vector, and together they create a resilient posture that agencies can market as a trust factor and recurring revenue stream.
- Trust Surface MappingConcept
Trust Surface Mapping is a framework for agencies to visualize every point where client data, deliverables, or internal operations touch third-party systems, AI models, or automated agents. Each touchpoint is a trust surface: a place where a breach, data leak, or unauthorized modification can occur, directly impacting client confidence and agency liability. Agencies that map these surfaces can prioritize security investments where exposure is highest, rather than applying blanket protections. For example, when an AI agent modifies approved creative post-launch, as seen in a recent campaign incident, the trust surface includes the ad platform, the AI tool, and the approval workflow. By mapping these, agencies can implement verification checkpoints and contractual safeguards. This framework turns security from a cost center into a strategic trust differentiator, enabling agencies to confidently offer managed security services as a recurring revenue stream.
- Liability Boundary PricingConcept
Liability Boundary Pricing frames security offerings not as feature bundles but as contractual risk transfers. Agencies that promise 'absolute security' inherit unlimited downside when a breach occurs; those that scope guarantees to specific controls (e.g., encryption at rest, MFA enforcement) convert security into a recurring revenue stream with a defined ceiling on liability. The framework maps each security service to a liability boundary: where does the agency's responsibility end and the client's begin? For example, an agency offering deepfake detection with Resemble AI can guarantee detection accuracy against known generative models, but not against future unknown ones, so the contract must cap liability at the cost of the detection service. Similarly, using hCaptcha for bot protection limits liability to blocking automated traffic, not human fraud. By pricing each boundary separately, agencies protect margins while still selling trust.
Decision and risk
How to judge the fit, and the ways it goes wrong.
- Security Tools Rule: When Client Data Flows Through AI Agents, Govern Actions Before Promising ProtectionEvaluation Rule
Prioritize tools that provide runtime governance and action reversal over those that only detect or report threats.
- Security Tools Rule: When Promising Protection, Price for Incident Response, Not Just PreventionEvaluation Rule
Bundle proactive threat modeling with incident response and price for the reality of evolving attack surfaces, not for guaranteed prevention.
- The Absolute-Security Promise TrapFailure Pattern
- The Compliance Theater Trap: Why Security Tooling Fails AgenciesFailure Pattern
8 modules selected for Bor
Frequently Asked Questions
Answers about pricing, setup, implementation
Bor is an open-source platform that enrolls Linux desktops and servers into a centralized fleet and enforces browser policies (Firefox, Thunderbird, Chrome, Edge), firewall rules (firewalld zones), and authorization policies (polkit) across all enrolled nodes. It provides a web dashboard for policy definition, compliance monitoring, audit logging, and role-based access control, with agents on each node enforcing policies and protecting managed files from tampering.
Bor is open-source and free to deploy. There is no per-seat licensing cost. Your agency covers only the infrastructure cost of running the policy server and the time investment in deployment and maintenance.
Operations Managers and Systems Administrators benefit most, as Bor eliminates manual per-machine policy configuration and centralizes compliance auditing. Founders and Operations leads gain value from role-based access control, which lets them delegate policy enforcement to junior staff without granting full system access. IT service agencies and MSPs that manage client or internal Linux fleets see the largest time savings.
For an Operations team managing 10+ Linux nodes with monthly policy updates, Bor typically saves 4-6 hours per month by eliminating per-machine SSH configuration and manual audit log review. Savings scale with fleet size and policy change frequency. Agencies with fewer than 5 nodes or infrequent policy changes see minimal time recovery.
No. Bor only manages Linux desktops and servers. If your agency infrastructure includes Windows or macOS machines, you will need a separate endpoint management tool for those platforms.
Initial deployment of the policy server and agent installation on 5-10 Linux nodes typically takes 2-4 hours for a team with Linux systems experience. Ongoing policy updates and node enrollment take 15-30 minutes per node after the initial setup.