IN THE NETWORK
● NOV 2025 / LATIN AMERICA PARTNER UPDATE● SEP 2025 / BRIAN SLOAT NAMED PRESIDENT● AUG 2025 / HPE + AMD DNS CACHE TESTS

Company / Network security / No. 064

Secure64 Wants to Stop the Trouble Before You Click

The Colorado software company puts security inside DNS, the internet’s address book. Its wager: the best place to interrupt a bad connection is before it begins.

Before a browser can fetch a page, it usually asks a small question: where is this name? The answer arrives so quietly that the user scarcely notices. Yet that exchange can send someone towards a bank, a fraudulent imitation of a bank, or a machine waiting for instructions from its attacker. Secure64 Software Corporation has spent two decades attending to this unglamorous moment. The address book, it turns out, deserves a bouncer.

The story in three lines
  • Secure64 sells DNS infrastructure and DNS-layer security to network operators.
  • Its tools combine availability, automated signing and threat filtering.
  • Its customers’ users are the scale: the homepage reports more than 1.5 billion.

DNS translates domain names into the addresses computers use. For an internet provider, trouble here spreads quickly: perfectly healthy websites can become unreachable to subscribers. Secure64 serves carriers, enterprises and government agencies that need those lookups to keep working. The company’s reported user count describes people downstream of its infrastructure, rather than a billion individual subscriptions to Secure64. Most of those people have little reason to learn the vendor’s name.

A chip architect’s problem

One of its founders, Bill Worley, had already spent a career looking beneath the software. He helped create Hewlett-Packard’s PA-RISC and PA-WideWord processor architectures; the latter became the Intel Itanium family. Together with Steve Goodbarn, whose background included serving as Janus Capital’s CFO, he helped establish Secure64. The pairing brought computer architecture and financial management to a problem that could look deceptively small from outside a network operations room.

Worley’s original technical answer was SourceT, a purpose-built micro operating system. Secure64 used the security features of Itanium rather than simply adding another defensive layer to a conventional server. In March 2007, it released commercial DNS software for HP Integrity hardware. The stated software price was $9,995; the server was a separate purchase. Security and throughput were sold together, because a protected system that could not answer enough questions would still disappoint its owner.

“DNS is one of the weakest links in IT infrastructures.”

Steve Goodbarn · 2007 product launch

The hardware story has since moved on. In August 2025, Secure64 described testing DNS Cache with HPE and AMD on a ProLiant server using an EPYC processor. The collaboration reported more than six times BIND’s performance at a 95% cache-hit ratio. That condition matters: answering a remembered question differs from chasing a fresh answer. A buyer should read the workload assumptions before admiring the multiplier.

The work hiding inside the address book

The product names are refreshingly literal. DNS Authority publishes authoritative records. DNS Cache resolves and remembers answers. DNS Signer automates DNSSEC key management and zone signing. DNS Manager centralizes configuration and monitoring, while Vizion helps operators inspect security events. DNS Proxy puts DNS-over-HTTPS processing in front of existing resolvers, allowing the proxy capacity to grow separately. These are tools for operating infrastructure, with security threaded through the work.

A simplified LineGuard lookup
01AskA device requests a domain.
02CheckDNS policy examines the destination.
03DecideReturn an answer or block the request.
The small question with a large guest list. Filtering happens at the DNS checkpoint.

DNSSEC illustrates the attraction of automation. It provides a way to authenticate DNS data, but someone must generate keys, rotate them and keep signatures current. Secure64’s Signer handles those recurring tasks and integrates with existing BIND, NSD and Microsoft DNS infrastructure. The operational appeal is plain: a security requirement becomes a manageable routine. Errors in that routine can make online services unreachable, an unusually persuasive argument for removing repetitive manual steps.

DNS Cache also has a specific architectural distinction: it shares no code with BIND. That removes exposure to BIND-specific code vulnerabilities. It does not establish immunity to every possible attack. LineGuard extends the portfolio into malicious-domain blocking and content policies, with cloud, hybrid and in-network options. LineGuard Edge adds enterprise policies through Active Directory and clients for users away from the office. Support and professional services cover planning, deployment and training.

Six weeks to change the gatekeeper

A useful test of this proposition appears in an anonymous carrier case study. The LineGuard site describes a major US operator replacing Cisco Umbrella for more than six million users. The pressures were rising costs and performance limitations. Secure64 reports a six-week rollout and 50% cost savings. Those are the vendor’s account of one deployment, not a promise that every network can obtain the same result.

Reported carrier cost comparison
Previous platform
100
LineGuard
50
Previous cost indexed to 100. Secure64 reports 50% savings; these bars show relative cost, not dollar prices.

Its October 2024 announcement supplies the revealing detail: the carrier deployed in the cloud to speed testing and rollout, with an eventual move into its own network planned. The existing platform was already operating. The trigger was the strain of cost and performance; the response was a migration path that allowed policies to change without waiting for the final infrastructure destination. The case offers a practical answer to what changed the purchase decision.

Official LineGuard shield artwork
A shield gets the publicity. Policy rules do the shift work. Official LineGuard product artwork.

Another company case study, called MobileCo, describes a different squeeze: rising DNS load, IPv6 plans and BIND patching costs. After evaluation, the operator conducted two field trials, then rolled Secure64 out across 19 sites over three months. The reported result was twice the scalability. The first thing under pressure was infrastructure headroom. Testing, rather than an attractive slogan, helped turn that pressure into a deployment decision.

The part worth copying

Secure64 earns money through commercial software, security subscriptions, support and services, with direct sales and partner distribution. It also announced a carrier revenue-sharing model for subscriber security services in 2018. Current LineGuard pricing uses customized proposals. The old $9,995 launch price belongs to a different product and year. Buyers comparing alternatives need a complete operating-cost calculation: infrastructure, support, migration and the staff hours consumed by recurring maintenance.

The transferable lesson is to inspect the repetitive work beneath a security requirement. Automate signing. Test capacity against actual traffic. Pilot before a broad rollout. Secure64’s differentiation rests on those operating details, its independent DNS implementation and deployment choice. HPE and AMD supply a hardware collaboration; 6connect supplied an IP-address-management integration; a November 2025 update names Biwares in Latin America. Distribution follows the networks that already have the users.

DNS filtering has boundaries. A device must use the protected DNS path for its lookups to receive that protection; direct-address connections and bypass routes need separate attention. Authenticating a DNS answer also cannot make the destination’s content trustworthy. Operators still need other security controls, sensible exceptions and workable policies for legitimate activity. Secure64’s proposition is compelling where DNS scale and operational complexity are real problems. Its quiet achievement is making an ordinary lookup worth a purchasing conversation.