// hardened · zero-telemetry · auditable
The Linux OS for
people who defend infrastructure.
Hardened Debian base. Pre-configured security stack — SIEM agent, network IDS, compliance scanning. Zero telemetry. Your systems are defense-ready from first boot.
Our flagship Arcline OS variants
for different use cases.
Pick the edition that matches your role. All share the same hardened Debian base and zero-telemetry guarantee.
Arcline Server
A hardened, production-ready host for SOC and production use — built-in SIEM agent and network IDS on top of the hardened base, with zero telemetry.
Arcline Workstation
A security analyst / blue-team workstation — KDE Plasma, pre-configured dev toolchains, privacy-hardened browser, forensics-friendly tooling, and secrets scanning.
Arcline Cloud
Minimal cloud images with a small attack surface — Falco runtime security and CIS benchmark scanning built in. Ready for AWS, GCP, Azure, or private cloud.
A Debian-derived OS that doesn't
make you start from scratch.
Debian gives you a rock-solid base. Arcline OS hardens it, layers on a full security and observability stack, and ships with pre-configured container infrastructure. No telemetry. No snap store. No cloud integration. Just a secure, auditable OS that respects your hardware.
Secure by default
Hardened kernel with lockdown, seccomp, and AppArmor profiles. Default-deny nftables firewall. You opt in to exposure — never out.
Privacy-first
Zero telemetry. Zero analytics. Zero cloud integration. No network calls you didn't initiate.
btrfs-native
btrfs root with subvolume snapshots, transparent compression, and boot-to-snapshot rollback — not bolted on, built in.
Developer-ready
Go, Rust, Python, Node.js toolchains pre-configured. Git, Make, LLVM/Clang included. Start building immediately.
Infrastructure-aware
Observability that feeds your security stack — node_exporter, Grafana, Loki, and a pre-configured host security agent, out of the box.
Fully documented
Every feature and tool includes offline man pages and a hardening guide. You own the system — and you understand it.
Production-ready from first boot.
Arcline OS layers pre-configured infrastructure and security tooling on top of a hardened Debian base. Everything is documented, auditable, and yours.
- Debian stable (Bookworm)
- Hardened Linux kernel (lockdown, seccomp)
- btrfs root + snapshot rollback
- nftables firewall (default-deny)
- Docker + Podman containers
- Go, Rust, Python, Node.js
- Git, Make, CMake, LLVM/Clang
- Docker / Podman pre-configured
- VS Code / Helix / Vim configs
- Prometheus node_exporter
- Grafana dashboards
- Loki log aggregation
- Pre-built alerting rules
Defense-in-depth, pre-configured
from first boot.
Beyond the hardened base, Arcline OS ships a named security tooling layer — host and network detection, malware and secrets scanning, compliance and runtime checks. Pre-configured, documented, and yours.
- Wazuh agent, pre-configured
- Host + integrity telemetry to your SIEM
- Suricata (or Zeek)
- Detects malicious traffic, not just uptime
- ClamAV baseline scanning
- Scheduled and on-demand
- OpenSCAP + CIS Benchmark profiles
- Mapped toward HIPAA, PCI-DSS, SOC 2
- Falco — container / syscall anomalies
- Cloud edition
- gitleaks + trufflehog
- Workstation / dev edition
- syft + grype
- Know what's installed, catch known CVEs
- Lynis hardening score
- Continuous, post-install
Arcline OS ships CIS Benchmark-aligned by default, with compliance scanning mapped toward HIPAA, PCI-DSS, and SOC 2 control families. The OS itself isn't certified — only audited deployments can be — but the defaults give you a running start.
The Wazuh agent pairs naturally with Arcline IT's Wazuh-based managed monitoring. Want the whole stack run and watched for you? Arcline IT's managed security services cover hardening, monitoring, and response.
No major Linux distro ships
pre-hardened for production.
Debian gives you the packages. Arcline OS assembles them into a finished system. A privacy-first, zero-telemetry operating system with built-in monitoring, auditing, and security — configured the way you'd do it yourself, if you had the weekend.
Built in the open. Shaped by the
people who use it.
Arcline OS is open-source under the GPL. The code lives on git.arcline.it. Every config, every build script — auditable and forkable.
Arcline OS is in active development.
Be there at the start.
We're building the ISO pipeline and hardening the defaults. Sign up to receive early access and help shape the first release.
No spam. No tracking. We'll only email you when there's something to try.
The Arcline Project is funded and operated by Arcline IT LLC — the same model as Red Hat and Fedora. The commercial services business at arcline.it keeps the lights on so the OS stays independent and sustainable.
Arcline IT also offers managed security services — hardening, Wazuh-based monitoring, and response — for teams that want Arcline OS run and watched for them.