{{define "content"}}

// hardened · zero-telemetry · auditable

The Linux OS for
people who defend infrastructure.

Hardened Debian base. Pre-configured security stack — SIEM agent, network IDS, compliance scanning. Zero telemetry. Your systems are defense-ready from first boot.

Our flagship Arcline OS variants
for different use cases.

Pick the edition that matches your role. All share the same hardened Debian base and zero-telemetry guarantee.

Arcline Server

A hardened, production-ready host for SOC and production use — built-in SIEM agent and network IDS on top of the hardened base, with zero telemetry.

Arcline Workstation

A security analyst / blue-team workstation — KDE Plasma, pre-configured dev toolchains, privacy-hardened browser, forensics-friendly tooling, and secrets scanning.

Arcline Cloud

Minimal cloud images with a small attack surface — Falco runtime security and CIS benchmark scanning built in. Ready for AWS, GCP, Azure, or private cloud.

A Debian-derived OS that doesn't
make you start from scratch.

Debian gives you a rock-solid base. Arcline OS hardens it, layers on a full security and observability stack, and ships with pre-configured container infrastructure. No telemetry. No snap store. No cloud integration. Just a secure, auditable OS that respects your hardware.

Secure by default

Hardened kernel with lockdown, seccomp, and AppArmor profiles. Default-deny nftables firewall. You opt in to exposure — never out.

Privacy-first

Zero telemetry. Zero analytics. Zero cloud integration. No network calls you didn't initiate.

btrfs-native

btrfs root with subvolume snapshots, transparent compression, and boot-to-snapshot rollback — not bolted on, built in.

Developer-ready

Go, Rust, Python, Node.js toolchains pre-configured. Git, Make, LLVM/Clang included. Start building immediately.

Infrastructure-aware

Observability that feeds your security stack — node_exporter, Grafana, Loki, and a pre-configured host security agent, out of the box.

Fully documented

Every feature and tool includes offline man pages and a hardening guide. You own the system — and you understand it.

Production-ready from first boot.

Arcline OS layers pre-configured infrastructure and security tooling on top of a hardened Debian base. Everything is documented, auditable, and yours.

Base System
  • Debian stable (Bookworm)
  • Hardened Linux kernel (lockdown, seccomp)
  • btrfs root + snapshot rollback
  • nftables firewall (default-deny)
  • Docker + Podman containers
Developer Environment
  • Go, Rust, Python, Node.js
  • Git, Make, CMake, LLVM/Clang
  • Docker / Podman pre-configured
  • VS Code / Helix / Vim configs
Observability
  • Prometheus node_exporter
  • Grafana dashboards
  • Loki log aggregation
  • Pre-built alerting rules

Defense-in-depth, pre-configured
from first boot.

Beyond the hardened base, Arcline OS ships a named security tooling layer — host and network detection, malware and secrets scanning, compliance and runtime checks. Pre-configured, documented, and yours.

Host IDS / SIEM
  • Wazuh agent, pre-configured
  • Host + integrity telemetry to your SIEM
Network IDS
  • Suricata (or Zeek)
  • Detects malicious traffic, not just uptime
Malware Scanning
  • ClamAV baseline scanning
  • Scheduled and on-demand
Compliance Scanning
  • OpenSCAP + CIS Benchmark profiles
  • Mapped toward HIPAA, PCI-DSS, SOC 2
Runtime Security
  • Falco — container / syscall anomalies
  • Cloud edition
Secrets Scanning
  • gitleaks + trufflehog
  • Workstation / dev edition
Supply Chain / SBOM
  • syft + grype
  • Know what's installed, catch known CVEs
System Auditing
  • Lynis hardening score
  • Continuous, post-install
Compliance-ready by default

Arcline OS ships CIS Benchmark-aligned by default, with compliance scanning mapped toward HIPAA, PCI-DSS, and SOC 2 control families. The OS itself isn't certified — only audited deployments can be — but the defaults give you a running start.

The Wazuh agent pairs naturally with Arcline IT's Wazuh-based managed monitoring. Want the whole stack run and watched for you? Arcline IT's managed security services cover hardening, monitoring, and response.

No major Linux distro ships
pre-hardened for production.

Debian gives you the packages. Arcline OS assembles them into a finished system. A privacy-first, zero-telemetry operating system with built-in monitoring, auditing, and security — configured the way you'd do it yourself, if you had the weekend.

Ubuntu Server
Great ecosystem and hardware support — but Snap packages and cloud integration are baked in by default.
Fedora Server
Cutting-edge kernel and tooling — but rapid release cycles mean more churn on production machines.
Alpine Linux
Minimal and musl-based — ideal for containers, but limited as a full-featured server workstation.
Kali Linux
A great offensive-security and pentesting toolkit — but built to break in, not to serve as a hardened daily-driver production OS.
Security Onion
An excellent network security monitoring platform — but not a general-purpose or developer-ready OS for your day-to-day hosts.
Arcline OS
Hardened Debian base. Pre-configured security stack. Built-in observability. Zero telemetry. Ready to deploy.

Built in the open. Shaped by the
people who use it.

Arcline OS is open-source under the GPL. The code lives on git.arcline.it. Every config, every build script — auditable and forkable.

Arcline OS is in active development.
Be there at the start.

We're building the ISO pipeline and hardening the defaults. Sign up to receive early access and help shape the first release.

I'm interested in:

No spam. No tracking. We'll only email you when there's something to try.

{{end}}