Cicada.OS — private laptop OS
● LIVE<br>· —
MAGI-01 // SENTRY<br>CHANNEL · cicada-stable
SRC · GITHUB<br>TRACKED · LAPTOP OS
Pre-alpha · live USB = test · install = product
CICADA.OS
The private laptop OS you can actually use.
GrapheneOS intent. Hyprland daily driver. Flash the ISO to try; run cicada-install when you want files and wallpaper to stick.
Download ISO<br>Install (keep your files)<br>Features
About
BALTHASAR-2
Cicada.OS is a privacy and security focused laptop operating system,<br>developed as an open source project. It hardens defaults, owns the launcher,<br>and ships Graphene-shaped permissions — without making you fight the machine for Wi‑Fi, files, or a browser.
Official releases land on the download page.<br>Installation instructions are on the install page.<br>Claims stay honest about silicon — see the table below.
Status — read this before you trust it<br>PRE-ALPHA
Cicada boots to a Hyprland desktop on an Intel MacBook Air. Most of the hardening<br>on this site is verified structurally — the configuration says the thing —<br>and a growing part of it is now verified against a real Linux kernel .<br>Little of it has been exercised on hardware end to end.<br>Do not rely on this for anything that matters yet.
On a real kernelFirewall + VPN kill switch, NTS time, Tor bootstrap, onion namespace, session duress wipe
In simulationUSB gate and its restore path, watchdog arming, escape hatches, beacon signing and alarm
Needs the hardwarehardened_malloc under Helium, chipset watchdog reset, kernel USB refusal, LoRa beacon
Splitting “unverified” into those three lists is not bookkeeping — it is what exposed<br>the last five defects, including a session duress credential that had never fired.<br>Full list: Status in the README.
Product layers<br>POLICY OS
LauncherDock / Wofi / MIME only start Cicada wrappers
ScopesDefault-deny network, files, cam, mic
Work UIDSecond Unix user — not a folder named Burner
BrowserHelium with Vanadium-class managed policy
ChannelPinned cicada-stable — not floating Arch extra
Not Google · Not AOSP theater<br>ENGINE
Cicada will never ship a fake Titan story on Apple EFI.<br>Arch remains the package engine; the product layer is what you touch.<br>Kitty is Owner adb — power user escape, not the UI.
Claims — do not collapse them<br>THREAT MODEL
ClaimWhen true
Trackers / school filter / cold disk thief<br>Strong passphrase + Helium policy + LUKS — mostly now
LEO with AFU (on or just locked)<br>Never “can’t.” Shorten the window. Still userspace.
Firmware / evil maid on Apple EFI Air<br>Never. Heads/PureBoot is a different laptop.
Cicada is its own OS<br>No unsandboxed dock path; scopes; Work UID; signed channel. Identity, not uncrackability.
Device support<br>HARDWARE TIERS
PrototypeIntel MacBook Air 2015–2017 — software privacy only
DailyFramework / modern ThinkPad — TPM2 + Secure Boot enroll
Boot storyLibrem / NitroPad + Heads — evil maid answer