Deep Engineering

Custom OS Development

A rare capability: custom Linux distributions, hardened kernels, security modules, and embedded OS builds tailored to your hardware and threat model.

Custom Linux distributions, kernel modules, and security hardening.

  • An OS shaped to your hardware and threat model
  • Smaller attack surface, faster boot
  • Full control of the stack, top to bottom

The problem

Off-the-shelf operating systems fit neither your hardware nor your threat model.

Most products should run on an existing operating system. Some cannot: a device that must boot in seconds, a locked-down kiosk, a system that has to run for years without changes, or an environment where the attack surface must be as small as possible. For those, a purpose-built operating system fits better.

We build custom Linux images and distributions, configure and patch kernels, write kernel modules and drivers, and harden systems to a stated threat model. We also produce the build system that recreates the image from source, so you never depend on a system nobody can rebuild.

What you receive

What a project produces.

  • Requirements and threat model

    A written list of what the system must do and which attacks it must resist.

  • A reproducible OS image

    A build system that produces the same image from source every time, with pinned versions.

  • Kernel configuration and drivers

    A kernel with only what your hardware needs, plus modules or drivers where standard ones do not exist.

  • Hardening and access control

    Minimal packages, mandatory access control policies, secure boot where the hardware supports it, and locked-down services.

  • Update and recovery mechanism

    Signed updates with a fallback partition, so a failed update leaves the device bootable.

  • Documentation for maintainers

    How to rebuild, patch and audit the image, written for your own engineers.

How we approach it

The positions we take.

The smallest system that does the job

Every package and service is a possible vulnerability and a maintenance cost. We include what is needed and nothing else.

Reproducible builds

Anyone with the repository can rebuild the image. Nothing depends on a machine or a person who may not be around later.

Plan for security updates from day one

A custom OS still needs patches. We agree how upstream security fixes reach your image, and who applies them.

How it runs

Four steps, from the first call to hand-over.

  1. 1

    Requirements and threat model

    We write down the hardware, the behaviour required and the attackers you expect. You receive a fixed quote against that document.

  2. 2

    Base image and kernel

    We build a first bootable image on your hardware, with the kernel configured and any drivers in place.

  3. 3

    Hardening and update path

    Access controls, secure boot and the signed update mechanism are added and tested, including failed and interrupted updates.

  4. 4

    Validation and hand-over

    We test against the threat model, then hand over the build system, the documentation and a walkthrough for your maintainers.

Is it a fit

When we are the right people, and when we are not.

A good fit

  • Off-the-shelf distributions carry too much, boot too slowly, or do not support your hardware.
  • Your threat model requires a controlled and auditable software supply.
  • You have engineers who will maintain the image with our documentation.

Another route is better when

  • A standard Linux distribution with careful configuration would meet your needs. That is cheaper to maintain, and we will say so.
  • You want an operating system written from scratch. Almost no project needs one.
  • You cannot commit to applying security updates over the life of the product.

What we ask on the first call

  • Which hardware and processor architecture?
  • What must the system do, and what must it never do?
  • Who are the likely attackers?
  • How long must the product be supported?
  • Who will maintain the image afterwards?

Questions

About Custom Operating Systems.

Something missing? Write to [email protected] and an engineer will answer.

Do you write operating systems from scratch?

Rarely. Almost every project is better served by building on Linux, which has drivers and years of security review behind it. We build custom images and kernels on that base.

Can you harden an existing Linux system instead?

Yes. Hardening a system you already run is a smaller project, and often the right first step.

How do security patches reach a custom image?

We set up a build pipeline that pulls upstream fixes, rebuilds, tests and produces a signed update. Who runs it is agreed at the start.

Will we be able to maintain it without you?

That is the goal. The build is reproducible and documented, so your own engineers can rebuild and audit it.

Describe what you need.

Describe the problem in plain language. An engineer reads every inquiry and replies within one business day, with a written scope and fixed price before you commit to anything.

Talk to an Engineer
Reply
Within one business day
First call
Free, no commitment
Confidentiality
NDA on request, before you share anything