# FireAI 1.0: a redesigned interface that shows the state of a Mac’s network at a glance > FireAI 1.0 from HisnLabs redesigns the World map, Activity, Home and alerts so network state is shown, not read, and acting takes fewer steps than 0.1.8. FireAI Security & Research Team (HisnLabs) · Published 2026-09-30 Canonical: https://hisnlabs.com/en/blog/fireai-1-0-see-your-mac-network-at-a-glance FireAI 1.0, released on 30 September 2026, is a redesign of how the firewall shows what a Mac is doing on the network. FireAI is a macOS network firewall developed by HisnLabs, with an on-device AI model that suggests decisions. This note lists what changed since 0.1.8, and each change follows one of four design decisions described below. The four decisions are: show state instead of asking the user to read numbers; act where you look; let nothing move unless something happens, which also lowers CPU use; and let every alert say in plain words what happened and what can be done about it. ## What changed since 0.1.8 | Area | Before (0.1.8) | Now (1.0) | | --- | --- | --- | | World map | Arcs showed all-time totals; dots kept moving on idle connections | Data rivers: width and moving dots follow live throughput, and only while data flows; day and night shading; a live traffic ring | | Countries | Not shown as a list | “Requests by country” under the globe, with Filter and Block on each row | | Upload alerts | No upload-specific alert | An unusual upload to a country is flagged in the list, on the globe, on Home and in the menu bar | | Activity | Connection lists | A 60-second heartbeat strip per connection; Replay for blocked connections | | Home | Figures | A privacy weather pill and a mascot that reacts to events | | Suggestions | A list of suggestions | Quick Review card stack with drag and keyboard answers | | Threats | Details of a threat | A “Why?” timeline of what was observed | | Menu bar | Status icon | A red flash on a block; a red arrow and country code during an upload spike | | FireAI Pilot | One profile for the whole Mac in 0.1.8; per network from 0.1.8 build 3 | Learns per Wi-Fi network and per security mode | | CPU use | Lowered from 0.1.8 build 3 | Redraws only what changed; the globe pauses in the background | *Release notes for every build are on the [release page](https://hisnlabs.com/en/whats-new).* ## The World map: throughput as a shape In 0.1.8 the map’s arcs represented all-time totals, and their dots kept moving even on connections that had gone quiet. A total says little about the present, and a moving dot on an idle line suggests activity that is not there. The World map now draws “data rivers”. The width of a line follows live throughput on a logarithmic scale from about 1 KB/s to about 1 MB/s. White dots run out from the Mac while an app uploads and coloured dots run back while it downloads, and only while data flows. Idle lines stay thin and still, so motion on the map always means traffic. The [World map documentation](https://hisnlabs.com/en/docs/world-map) lists the details. Context is added where it changes the reading of a connection. The real night side of the Earth is shaded, a small moon marks destinations that are busy while it is night there, and the connection card gives an approximate local time at the destination, for example “About 1 AM there”. A ring around the globe shows each country’s share of current traffic, captioned “LIVE · 1.2 MB/s”. Pointing at a slice shows the country, its share and its speed, and fades the lines of the other countries so that one country can be read on its own. ## Requests by country: acting where you look Under the globe, a new list shows each country with its flag, a bar and a request count, which is the sum of connections and blocked attempts. Selecting a row turns the globe to that country by the shortest way, with easing, and labels it. Selecting the row again lets the globe spin on without a jump. Labels of neighbouring countries stack instead of overlapping. The design reason is proximity between observation and action. Pointing at a row reveals two buttons. Filter limits both the globe and the list to that country. Block creates block rules for the destinations already seen there, after a confirmation. New destinations in that country still ask, or follow the current mode, so the action covers what was observed and does not silently extend to what was not. See [Requests by country and upload spikes](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes). > The World map and the country list are part of FireAI 1.0. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Upload spikes: an alert that names the country A country is flagged when it receives at least 5 MB in the last 10 seconds and at least 10 times its usual rate. The country moves to the top of the list in red with its speed, for example “↑ 4.2 MB/s”, and a red line reads “Unusual upload to France · since 14:02”. The globe shows red lines and a pulsing marker, the Home weather changes to “Storm”, and the menu bar shows a red ↑ with the country code. The same fact is therefore shown in four places, each at the level of attention the user is likely to be at: the menu bar for a glance, Home for a session, the map for investigation, and the list for the decision. The flag stays for one minute after the spike ends. A steady upload such as a backup becomes normal after about two minutes, which limits repeated alerts for expected behaviour. FireAI does not block the traffic by itself; the alert states what happened and leaves the decision with the user. ## Activity: a minute of behaviour in one strip Each connection now carries a 60-second heartbeat strip, on its card and as a “Last minute” column in the table. A spike is a burst, a wave is a steady stream, a red tick is a blocked attempt, and a flat line is a quiet connection. The strip updates once a second and only while it is visible on screen. It replaces a row of rate figures with a shape that can be compared across connections at a glance. Details are in [Activity and connection history](https://hisnlabs.com/en/docs/activity-and-connection-history). A blocked connection has a Replay button. It plays a 2-second animation: a packet leaves the app, the FireAI mascot of the part that blocked it catches the packet, and a ✕ appears at the destination. The animation is followed by what blocked the connection and how many times it tried. The purpose is to answer the question “what stopped this?” in the order in which the events happened, without a separate log view. ## Home, the menu bar and the mascot: nothing moves without a reason Home now leads with a privacy weather pill. “Clear” means nothing was blocked this hour, “A few clouds” and “Showers” mean some and many blocked connections, “Storm” means an upload spike, and “Sheltered” means the kill switch is on. “Calm” and “Calm night” mean almost nothing is going out. Selecting the pill opens Activity, or the World map during a storm. The [Home dashboard documentation](https://hisnlabs.com/en/docs/home-dashboard) describes each state. The 3D mascot reacts to the same events. It shakes its head at a burst of blocks, defined as five or more in 10 seconds, jumps at an upload spike, and dozes late at night when almost nothing flows. When nothing happens it draws nothing. The menu bar icon follows the rule: it flashes red for about a second on a block, at most once every 3 seconds, and shows a red ↑ with the country code during an upload spike (see [Menu bar widget](https://hisnlabs.com/en/docs/menu-bar-widget)). Animation is used as a signal here, so its absence is also information. ## Quick Review, the Threats timeline and FireAI Pilot [Quick Review](https://hisnlabs.com/en/docs/quick-review-suggestions) turns the list of suggestions into a stack of cards. Dragging a card or pressing ← blocks, → allows, ↓ skips and Esc stops. BLOCK and ALLOW stamps appear while dragging so that the result is visible before the card is released, and a summary is shown at the end. Each answer creates the rule and teaches FireAI Pilot, so a decision is made once and used twice. On [the Threats page](https://hisnlabs.com/en/docs/the-threats-page), a “Why?” timeline lists when the app first went online and whether it was signed, its first contact with the server and the server’s country, the warning signs, and what FireAI did. The verdict is thus accompanied by the evidence in order. [FireAI Pilot learns per Wi-Fi network and per security mode](https://hisnlabs.com/en/docs/fireai-pilot-learns-per-network), a change that started in 0.1.8 build 3 and is part of 1.0. The network is stored as a short fingerprint of its name or of its saved place, never the name itself, and only on the Mac. Reading the Wi-Fi name requires Location permission. A decision taken on another network counts for about a third of one taken on the current network. ## Lower CPU use The rule that nothing moves unless something happens has a side effect on resource use. Home redraws only what changed, the globe draws at 24 frames per second and pauses while FireAI is in the background, and the 3D mascot stops drawing after its entrance. The heartbeat strips update only while visible. FireAI is a program that runs continuously beside other work, so the interface is designed to cost little when the network is quiet. ## Design principles we kept - Show state, not numbers: width, colour, shape and a weather word carry the meaning before any figure is read. - Act where you look: Filter and Block sit on the country row, Replay on the blocked connection, answers on the card. - Nothing moves unless something happens: motion signals traffic, and stillness signals quiet. - Every alert says what happened in plain words and what can be done, and FireAI does not act on an upload spike without the user. - Actions cover what was observed: a country block applies to the destinations already seen and leaves new ones to the current mode. ## Limitations - The upload threshold (at least 5 MB in 10 seconds and 10 times the usual rate) is a heuristic. A short legitimate upload below it is not flagged, and a large one to a country that regularly receives large uploads may not be. - The country of a destination is derived from its address, and the local time and night marker are approximations for that country. - Blocking by country covers destinations already seen. It is not a rule against a country as a whole. - A steady upload becomes normal after about two minutes by design, so a slow, continuous transfer of data is not flagged after that period. - Without Location permission FireAI cannot read the Wi-Fi name, and FireAI Pilot then cannot tell networks apart. ## How to update FireAI updates itself from Settings. Users without automatic updates can [download FireAI 1.0](https://hisnlabs.com/en/download) and try it free for 17 days. The [release page](https://hisnlabs.com/en/whats-new) lists the changes of every build. ## How FireAI and HisnLabs fit in See where your Mac talks, and act on it from the same screen. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [FireAI release notes](https://hisnlabs.com/en/whats-new) - [FireAI docs: World map](https://hisnlabs.com/en/docs/world-map) - [FireAI docs: Requests by country and upload spikes](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes) - [FireAI docs: Activity and connection history](https://hisnlabs.com/en/docs/activity-and-connection-history) - [FireAI docs: Home dashboard](https://hisnlabs.com/en/docs/home-dashboard) - [FireAI docs: Quick Review for suggestions](https://hisnlabs.com/en/docs/quick-review-suggestions) - [FireAI docs: The Threats page](https://hisnlabs.com/en/docs/the-threats-page) - [FireAI docs: Menu bar widget](https://hisnlabs.com/en/docs/menu-bar-widget) - [FireAI docs: FireAI Pilot learns per network](https://hisnlabs.com/en/docs/fireai-pilot-learns-per-network)