Only one persona is ever live.

That's True Isolation. The others stay sealed, with no path between them.

Temporal and cryptographic isolation

A Redwall Mobile device with its active persona shown in full color and focus, with two other sealed personas visible behind it
Temporal isolation

Only one persona runs at a time. Switching personas wipes the previous keys and memory before the next one opens.

Cryptographic isolation

Each persona's data is sealed with its own keys. Only the active persona is ever decrypted. The rest stay sealed, even on the same device.

Only one persona is ever live. It is decrypted and active in memory. The others remain sealed.

How the platform enforces it

Redwall's security monitor enforces True Isolation from a level above root. It uses behavioral analysis — watching for what the system should be doing, not matching a list of known attacks — so it catches new attacks without waiting for a patch. The same monitor runs real-time integrity checks on the kernel, critical memory, and key files, catching tampering as it happens.

What this means in practice

A compromised persona has no path to the others. That's different from a hardened Android build or a container-based, dual-persona approach. Both keep multiple environments running side by side, leaving a path from one to the next. With True Isolation, there's no path at all. Each persona can also set its own rules for networks, sensors, cameras, and apps.

One device, every network

Each persona connects only to the network it's cleared for.

Diagram of one Redwall Mobile device branching into three isolated personas: Personal on an open network, Official on a managed network, and Classified on a locked-down network

More than attack protection

Controlled connections

Each persona controls its own Bluetooth, NFC, sensors, and network access. A sensitive persona will not allow an unapproved Bluetooth device to join a call or let data move to a device that is not cleared to receive it — even if a user tries.

Sensitivity stays separated

Redwall Mobile never lets classified and unclassified data, networks, or connections share a single profile — policy keeps them in separate personas.

A clear reset between personas

Switching personas is deliberate. Different wallpaper, layout, and environment give the user a clear cue so something meant for one persona is not accidentally sent from another.

Why isolation, not promises

Nothing is impenetrable. That's exactly why True Isolation exists. If one persona is ever compromised, it stays contained. The device, the other personas, and the data behind them stay protected.

See True Isolation in action

Request a briefing and see exactly how it holds up under real conditions.

Request a Briefing