BSD-3-CLAUSE · PRE-LAUNCH

Immutable Linux you can prove.

SealProof builds a Linux OS from clean Gentoo source, seals it into an immutable, cryptographically verifiable image, and proves it, from source to a running fleet.

Request access Read the docs →
verify-trust-chain
$ sealproof verify-trust-chain --image sealproof-prod-3841.img
  loading attestation bundle …
  dm-verity root      OK   merkle root matches kernel cmdline
  sha512              OK   7c1f9a2e…b0d4 (image digest)
  gpg signature       OK   signed by release key 0xE4D2…
  slsa provenance     OK   all inputs pinned by digest
  sbom (cyclonedx)    OK   licenses resolved · 0 denied
  tpm quote          OK   PCR 0-7 as expected
✓ trust chain verified — reproducible from source
01
Black-box images
Prebuilt distro images are opaque binaries. You cannot reconstruct what went in, so you cannot prove what is running.
02
Poisoned pipelines
One compromised build step, SolarWinds-class, silently taints the whole fleet, with no boundary and no rollback story.
03
Compliance gap
Regulated operators are required to attest to integrity they have no mechanism to demonstrate.
NOW MANDATED
US Executive Order 14028 and the EU Cyber Resilience Act now require verifiable provenance and SBOMs.
HOW IT WORKS

Five stages, one artifact.

01
Source
Gentoo / Portage, every input pinned by digest.
02
Build
Reproducible emerge inside a sandboxed SDK container.
03
Immutable
GPT + dm-verity + sysext. Immutable by construction.
04
Attest
SBOM, SLSA provenance, GPG signatures, TPM quotes.
05
Fleet
A/B atomic OTA updates, zero-touch Ignition.
Every artifact traceable to a single root of trust, no hidden binaries, no silent drift.
SealProof console: build pipeline stages and the nine-partition GPT layout
Build pipeline and 9-partition GPT layout
SealProof image builder: build steps, output artifact and the live build log
Image assembly, digests and the live build log
SECURITY

Scanners find problems after the fact. SealProof makes whole classes of them impossible to introduce.

SIX AXES OF SUPPLY-CHAIN TRUST
Pinning — every input by digest
Licenses — allow / deny / clarify
Provenance — SHA-512 + GPG
CVE advisories — checked at build time
Freshness — staleness detection
SBOM — CycloneDX, generated
DEFENSE IN DEPTH, BUILT INTO THE IMAGE
dm-verity integrity — Merkle root pinned in the kernel cmdline
Tetragon eBPF runtime enforcement
ZFS with encryption
TPM attestation
A/B atomic updates with rollback
Tooling written in Rust — memory-safe, with a small trusted computing base.
WHO IT IS FOR

Fleets that have to answer for what they run.

Critical infrastructure & defense
Long-lived systems that must stay verifiable for a decade, rebuildable from pinned source.
Finance & regulated cloud
Auditors who want evidence, not questionnaires, produced by the build itself.
Edge & fleet operators
Thousands of unattended machines, atomic updates, rollback on failure, no hands on site.
COMPLIANCE
Evidence mapped to CIS, NIST, SOC 2 and ISO 27001.
ENGINEERING TODAY
54,214
lines of Rust
1,122
automated tests
96
architecture fitness gates
E2E
working build pipeline
Pre-revenue, pre-launch. Built on Flatcar Linux, Gentoo (Portage) and Tetragon.

Prove what you run.

We are onboarding a small number of design partners running regulated, edge or critical-infrastructure fleets.

Request access
Seal Proof
SealProof by Nuculo Incorporated · sealproof.dev · Brooklyn, NY
GitHubDocs