r-fx networks · ecosystem overview · march 2026

Building infrastructure security
since 2002.

16 projects · 2,302 commits · 4,597 tests · AI-native governance

proj@rfxn.com · rfxn.com · github.com/rfxn

by the numbers

Two decades. One mission.

2,302
total commits
16
active projects
4,597
test cases
68K+
lines of code
6
shared libraries
8
OS targets
27
AI agent roles
15
audit domains
market position

The default security stack just became the only one.

ConfigServer shut down. Permanently.

Aug 31, 2025 — CSF, LFD, and CXS went dark. Licenses cannot be reinstalled. Every cPanel server that shipped with ConfigServer is now unprotected or paying for a commercial replacement.

500K–1M+
servers ran ConfigServer
$72.2B
shared hosting market (2026)
Imunify360 $5–25/mo · BitNinja $4–40/mo · cPGuard $4–10/mo · Monarx $15+/mo

The rfxn stack. Since 1999.

LMD since 2002 · 909 commits
Only maintained GPL malware scanner for shared hosting. 12+ panel integrations.
APF since 2002 · 435 commits
Drop-in CSF replacement. Zero Perl. Trust system, GeoIP, structured telemetry.
BFD since 1999 · 172 commits
Pressure-based adaptive blocking. Multi-service. LFD replacement with audit trail.
100 servers × 1 year
$6K–30K commercial
$0 rfxn
GPL · pure Bash · no vendor lock-in · the moat is adoption at zero friction
the ecosystem
SECURITY PRODUCTS INTELLIGENCE SHARED INFRASTRUCTURE GOVERNANCE APF 2.0.2 Advanced Policy Firewall 435 commits · 950 tests LMD 2.0.1 Linux Malware Detect 909 commits · 867 tests BFD 2.0.2 Brute Force Detection 172 commits · 1,773 tests Sigforge 1.4 Malware Signature Forge 179 commits · 806 tests geoscope 1.1 IP Geolocation Pipeline 62 commits · 201 tests geoip_lib 1.0.4 GeoIP Resolution Library 18 commits GPUBench GPU Performance Testing 74 commits tlog_lib Structured logging v2.0.4 · 60 commits alert_lib Alert dispatch v1.0.5 · 21 commits elog_lib Event logging v1.0.4 · 25 commits pkg_lib Package manager v1.0.5 · 27 commits batsman BATS test harness v1.2.2 · 60 commits RDF v3.0.4 rfxn Development Framework — 6 profiles, 4 adapters 247 commits · spec/plan/build/ship pipeline RulePlane Governance-as-Code for AI agents stealth · ruleplane.com
the renaissance · february–march 2026

What happens when legacy meets AI-native development?

1,244
commits in 25 days
8
new projects shipped
4,597
tests written
6
shared libraries
COMMIT VELOCITY — 2026 FEB 469 commits APF 175 · LMD 150 · BFD 44 · batsman · tlog_lib MAR 1,093 commits LMD 327 · RDF 247 · APF 181 · Sigforge 176 · BFD 118 · geoscope 45
governance · rdf v3.0

The Development Framework that governs everything.

01

Canonical Source

All agent commands, scripts, and governance live in rdf/canonical/. One source of truth, generated into every adapter.

02

4-Command Pipeline

/r:spec → /r:plan → /r:build → /r:ship — every change follows the same arc from design to release.

03

6 Profiles

core, shell, python, frontend, database, go — domain-specific conventions auto-detected and enforced.

04

4 Adapters

Claude Code, Gemini CLI, Codex, agents-md — one definition, every AI tool gets native-format instructions.

247 commits · 30+ commands · 10 scripts · 6 agents

the workforce
27 AI Agent Roles 9 workflow roles + 18 audit domain agents PIPELINE USER request PO scope & tier EM orchestrate SE implement SENTINEL adversarial QA verify UAT acceptance ADVERSARIAL CHALLENGER pre-impl review UX REVIEWER CLI/output quality AUDIT PIPELINE — 15 DOMAIN AGENTS regression latent security standards cli docs config test-coverage test-exec install build-ci upgrade version interfaces MODEL TIERING: opus(4) semantic depth · sonnet(11) pattern matching · haiku(2) checklist 3-ROUND PIPELINE: agents (parallel) → condense-dedup (parallel) → compile (sequential)
quality · test infrastructure

Every commit is tested across 8 operating systems.

Test Matrix

BFD1,773 tests · brute force detection APF950 tests · policy firewall LMD867 tests · malware detection Sigforge806 tests · signature forge geoscope201 tests · geolocation pipeline

batsman v1.2.2 — Docker-based BATS harness, per-OS containers

OS Targets

CentOS 6 (bash 4.1 floor) CentOS 7 Rocky 8 Rocky 9 Ubuntu 20.04 Ubuntu 24.04 Debian 12 Gentoo / Slackware

Pre-usr-merge compat · no systemd dependency · bash 4.1+ floor

shipped · 2026 q1

What we shipped in 25 days.

APF 2.0.2 — full modernization + trust system BFD 2.0.2 — tlog integration + event system LMD 2.0.1 — hookscan API + signature engine Sigforge 1.4.0 — batch processing + ClamAV RDF 3.0.4 — spec/plan/build/ship pipeline geoscope 1.1.0 — Python IP geolocation batsman 1.2.2 — Docker BATS harness 6 shared libraries shipped 27 agent persona system 15-domain audit pipeline FP prevention protocol Documentation convention (all projects) GitHub Issue Model v2 Red team engagement (enterprise, authorized) RulePlane stealth presence Profile expansion (6 profiles)
in flight · active plans

What's in progress right now.

APF — Trust Event Logging

10 phases: instrument cli_trust() and cli_trust_temp() with tlog events across all code paths

BFD — Alert Event System

8 phases: add block_escalated, block_added, block_removed, and alert_sent events

LMD — Hookscan Enforcement

3 phases: rate limit enforcement + signature name masking in hookscan API

SIGFORGELevel-2 doc convention complete, sentinel fixes shipped GEOSCOPEFloor-level doc convention complete RDFDoc convention plan complete, all 5 phases shipped
forward work

What's coming. Not indexed by calendar — AI blurs velocity.

in flight spec ready aspirational
CSF Migration 8 phases — config translation, trust lists, RPM packaging
csm_lib 8 phases — detect, parse, translate CSF/LFD/CXS
APF 10 phases — trust event logging port flood · UDP · NAT · GeoIP v2
BFD 5 phases — audit log expansion CDN proxy · pressure.conf
LMD 3 phases — hookscan scan engine auto-detect
Sigforge 5 phases — FP gate, taxonomy LLM classification · fuzzy hash · 112K drain
RulePlane product build — rule schema · sync engine · harness · CI gate · observability
APF/BFD 3.x MESSENGER · cluster · web UI · auto-updates
37 specs designed · 43+ phases queued · velocity is the constraint, not ambition
claude code · usage telemetry

891 sessions. 37.5 days. One workspace.

399,863
total messages
87,087
lines added
285
git commits
1,623
files modified

Quality Outcomes

75.6% fully achieved · 53.2% rated essential
37 specs designed · 26 plans executed
24 sessions/day average intensity

Infrastructure

17 commands · 6 agents · 10 scripts
6 governance profiles auto-detected
148 permission rules configured

model: claude-opus-4-6 · 4.8M output tokens · 3.8B cache reads

ai-native development
The Human + AI Partnership How rfxn builds with Claude Code HUMAN Ryan MacDonald · R-fx Networks → Architecture decisions → Security threat modeling → Product vision & roadmap → Spec review & approval → Quality standards definition → Release decisions 20+ years Linux security Domain expertise drives governance Every commit reviewed Phase-based work, one unit per commit CLAUDE.md as enforceable contract governed feedback AI WORKFORCE 27 roles · Claude Opus/Sonnet/Haiku → Implementation (SE agent) → Adversarial review (Sentinel) → Quality verification (QA) → User acceptance (UAT) → 15-domain audits (parallel) → Test execution (8 OS matrix) Multi-model tiering (opus/sonnet/haiku) Parallel agent dispatch Counter-hypothesis protocol Persistent memory across sessions Self-healing governance loop
the insight
2,302

commits. Zero ungoverned.

Every commit passes through the same pipeline.
Spec. Plan. Build. Ship.
Governance doesn't slow you down.
It's what lets you go full throttle.

R-fx Networks

infrastructure security · since 2002

16 projects. 4,597 tests. 27 AI agent roles.
One governance framework. Ship clean on the first pass.

proj@rfxn.com · rfxn.com · github.com/rfxn

1 / 15