# FireAI 1.0 shows where a Mac’s data goes in real time

> HisnLabs has released FireAI 1.0 for macOS: a live World map with data rivers, upload-spike warnings, a heartbeat strip per connection, a reacting mascot and per-network learning.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-30
Canonical: https://hisnlabs.com/en/news/fireai-1-0-released

HisnLabs has released FireAI 1.0 for macOS. The version centres on making a Mac's outbound traffic visible as it happens: a World map that draws the volume of each connection, a per-country list, a warning for sudden uploads, a one-minute activity strip for each connection and a Home screen that summarises the last hour as weather. The changes are listed in the [release notes](https://hisnlabs.com/en/whats-new) [[1]](https://hisnlabs.com/en/whats-new) and in the product documentation. The statements below come from the vendor's own pages, which are its own account and not independent testing.

## Background

FireAI is a network firewall with on-device AI. It sits on the Mac as a content filter, judges each app's outbound connection against the user's rules and the current security mode, and shows the result. Earlier versions listed connections and asked the user to decide. Version 1.0 adds ways to see the pattern across many connections, for example that one country is receiving a large share of the Mac's traffic, and to notice a change.

## What the release contains

The World map now draws data rivers: a line's width follows the live throughput of the connection, and dots run outward for uploads and back for downloads, only while data is actually flowing. The globe shades day and night, shows a moon on destinations that are busy at night, and gives the approximate local time on the connection card. A live ring displays each country's share of the current traffic [[3]](https://hisnlabs.com/en/docs/world-map).

Beneath the globe, the Requests by country list ranks the countries that the Mac connects to. Clicking a country turns the globe to it. A Filter button restricts the view to that country, and a Block button adds block rules for the destinations already seen there, after asking the user [[2]](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes). A destination that is new in that country still asks, or follows the security mode.

Upload spikes are flagged by fixed thresholds. A country counts as a spike when it receives at least 5 MB in 10 seconds and at least ten times its usual rate. It then turns red in the list and on the globe, the Home weather changes to Storm and the menu bar shows a red upward arrow with the country code. The flag remains for a minute after the spike ends, and a steady upload such as a backup becomes normal after about two minutes. FireAI does not block a spike on its own; the user decides [[2]](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes).

In Activity, each connection has a 60-second heartbeat strip, shown on its card and in a "Last minute" column of the table, and blocked connections can be replayed as an animation. On Home, the privacy weather reads Clear, A few clouds, Showers, Storm, Sheltered when the kill switch is on, or Calm and Calm night. A 3D mascot reacts: it shakes its head at a burst of blocks, jumps at an upload spike and dozes late at night when nothing moves [[1]](https://hisnlabs.com/en/whats-new).

> FireAI, the on-device firewall for macOS developed by HisnLabs, now draws the traffic of a Mac on a live map and flags a sudden upload to a country. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

Suggestions gain a Quick Review card stack. The user swipes left to block, right to allow or down to skip, each answer creates the rule, and each answer also teaches FireAI Pilot [[4]](https://hisnlabs.com/en/docs/quick-review-suggestions). The Threats page gains a "Why?" timeline [[1]](https://hisnlabs.com/en/whats-new).

FireAI Pilot now learns for each Wi-Fi network and each security mode. The network is stored as a short fingerprint, never as the Wi-Fi name, and only on the Mac. Reading the Wi-Fi name requires the macOS Location permission. Lessons from other networks weigh about a third as much as those from the current one, and per-network learning never overrides the user's rules, security-mode blocks or the kill switch [[5]](https://hisnlabs.com/en/docs/fireai-pilot-learns-per-network). The release also lowers CPU use [[1]](https://hisnlabs.com/en/whats-new).

## Implications for Mac users

The additions target one problem: outbound traffic is usually invisible until something has gone wrong. A user who keeps the World map open can see which app is talking to which country, and the spike rule is designed to bring a sudden large upload to the user's attention on Home and in the menu bar [[2]](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes). Users who prefer not to be asked can let Quick Review and FireAI Pilot build rules from a few answers.

## Recommendations

1. Open the World map and click the busiest countries to see which apps are behind them.
2. When a country turns red, click it, find the app and destination, and block them if the upload was unexpected.
3. Answer a few cards in Quick Review to let FireAI Pilot learn your usual apps.
4. Grant Location permission only if you want per-network learning, and note that FireAI stores a fingerprint of the network, not its name.

## What FireAI does and does not do

FireAI is a network firewall. It does not scan files, remove software from a Mac or decide that a spike is malicious. A spike is a signal for the user, and the block decision stays with the user. FireAI Pilot's per-network learning works alongside the user's rules and does not replace them [[2]](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes)[[5]](https://hisnlabs.com/en/docs/fireai-pilot-learns-per-network).

> The globe, the country list and the spike warning are aimed at one question: where does this Mac send its data. FireAI 1.0 is available with a 17-day trial. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

Locations on the map are approximate: large networks are shown at the edge nearest to the user, not at their real building, and without the location database no places are shown [[3]](https://hisnlabs.com/en/docs/world-map). The spike thresholds are fixed and cannot be changed by the user [[2]](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes). Per-network learning needs the Location permission, and without it, or on a wired connection, FireAI Pilot falls back to one profile for the whole Mac [[5]](https://hisnlabs.com/en/docs/fireai-pilot-learns-per-network).

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [HisnLabs, What’s new in FireAI](https://hisnlabs.com/en/whats-new)
- [HisnLabs documentation: Requests by country and upload spikes](https://hisnlabs.com/en/docs/requests-by-country-and-upload-spikes)
- [HisnLabs documentation: World map](https://hisnlabs.com/en/docs/world-map)
- [HisnLabs documentation: Quick Review suggestions](https://hisnlabs.com/en/docs/quick-review-suggestions)
- [HisnLabs documentation: FireAI Pilot learns per network](https://hisnlabs.com/en/docs/fireai-pilot-learns-per-network)
