Root of Trust
Measured firmware, verified boot, and attestation.
A minimal, hardened, AI-ready secure Linux distribution for servers and workstations. Two desktop environments on a verifiable foundation.
Explore Kawésqar Linux ↓Kawésqar Linux is a secure server and workstation distribution built for development, infrastructure, cybersecurity, and AI-enhanced operations. Nébula is its workstation experience and offers two desktop environments: COSMIC and BlackBox. The foundation integrates CIS Level 1 hardening and a verifiable control roadmap spanning firmware, kernel, applications, packages, network, identity, audit, and hardware.
A modern, complete, comfortable environment for development, IT, and cybersecurity. Daily productivity with AI-enhanced tools and a defensive posture from first boot.
A contained, minimal environment for operators who favor focus, speed, and a reduced visual surface — ready for technical and AI workflows. Revived and refined: a redesigned root menu, a compositor with restraint, and the tools that matter.
The first public Kawésqar Linux alpha is targeted for mid-October 2026. It will include initial server and workstation profiles, Nébula with COSMIC and BlackBox, and the first hardening baseline; the remaining controls will advance through verifiable roadmap deliveries.
The October alpha establishes a CIS Level 1 baseline. Everything beyond it ships as verifiable engineering: implementation, tests, and evidence before claims.
Measured firmware, verified boot, and attestation.
Hardened kernel and per-application confinement.
Reproducible packages, SBOM, and binary transparency.
Atomic updates, auditability, and hardware control.
4 controls
5 controls
4 controls
5 controls
5 controls
6 controls
3 controls
6 controls
39 controls in the roadmap · organized by domain
Models, data, prompts, agents, runtimes, and accelerators expose distinct risks. Kawésqar extends operating-system security to every AI artifact, identity, and action.
Models, adapters, tokenizers, and runtimes carry verifiable hashes, signatures, SBOMs, and provenance through fs-verity, IMA, and Sigstore/Cosign.
The TPM + IMA/EVM chain extends from firmware and kernel to the runtime and model actually loaded.
Inference, plugins, MCP servers, and generated code are isolated with namespaces, seccomp, Landlock, AppArmor, and cgroups; WASM or microVMs contain untrusted workloads.
Attestation, memory isolation, and confidential computing for GPUs/NPUs where hardware permits.
External data never gains instruction authority. Documents, web pages, and email cannot automatically invoke shell, Git, SSH, secrets, or privileged tools.
API keys, tokens, certificates, and SSH keys remain outside model context. The broker performs authorized operations without revealing secret values.
Per-model or per-agent network policy: offline, local-only, LAN-only, allowlist, proxy-only, or internet. Local models start without network access.
Explicit limits for CPU, RAM, VRAM, accelerators, context, processes, runtime, tool calls, bandwidth, and temporary storage.
Trusted, verified, experimental, unsigned, and untrusted levels drive isolation and capabilities without preventing legitimate experimentation.
private, restricted-ai, local-model-only, no-ai, and no-network-ai labels enforced by the OS or runtime.
GGUF, safetensors, LoRAs, plugins, and MCP servers enter as non-executable until signature, hash, metadata, dependencies, and policy pass verification.
Every model, runtime, and agent is an independent principal. Actions, resources, and state changes are traced with hashes and transactions while sensitive prompts stay out of logs.
The agent requests a specific access. The broker verifies identity, model, version, hash, workload, session, policy, and time; then issues a minimal capability that expires.
A minimal, hardened, no-GUI Linux server designed for secure infrastructure, virtualization, and production workloads. The base installation deploys no AI services — each workload enables only the profile it requires.
AI as a first-class security principal: its own identity, least privilege, isolation, provenance, and explicit access to every capability.
Kawésqar proposes treating the Job — rather than a process or permanent kernel — as the fundamental unit of computation. A temporary federation is formed from a closed set of sovereign providers for each requested outcome. When the Job ends, the visible machine disappears and its operational authority tends to zero.
ingress / egress
execution
persistent state
human interface
notary / archive
observation
Zero Core is in early research and development. The immediate goal is not to proclaim a finished architecture, but to turn its invariants into measurable experiments on a closed physical substrate. Master paper v1.3 defines the contributions, boundaries, and questions the PoC must answer.
Reject undeclared participants.
Keep an active Job alive without a governor.
Cancel among peers without the notary.
Measure compatibility, latency, and real cost.
Master draft 1.3 · proposed architecture · active research