Hashim Ruan

Helius Network HeliusOS v0.1 · Helius Network Ltd · measured 1 Oct 2026

The machine that checks your systems checks itself first.

HeliusOS is a hardened, image-based Linux operating system I built to run every security assessment from. It boots only from a verified image, encrypts its disk to the hardware it was enrolled on, refuses any target outside your signed scope, and produces evidence your own team can rerun. Every number on this page was measured, and every gap is named.

heliusos · boot booting
    CIS RHEL 10 Level 2
    0%

    374 of 386 scored rules, OpenSCAP

    Lynis hardening index
    0

    target was 80

    Automated tests
    0

    on every build, with SBOM and CVE scan

    Inbound by default
    Deny

    SELinux enforcing, kernel lockdown

    Why an assessor needs its own operating system

    You are about to hand someone the keys. What are they holding them on?

    The usual answer
    • A personal laptop with a few hundred packages nobody has audited
    • Your credentials in a notes app, next to the last client’s
    • Scanner output copied into a template, no way to reproduce a finding
    • Nothing stops the tooling reaching systems you never authorised
    • A score, and a request to trust it
    HeliusOS
    • One image, built from a single definition, hardened to a published benchmark at build time
    • Disk encrypted and sealed to the hardware; nothing readable if the machine walks
    • Every request and response hashed into an evidence pack you can rerun
    • Targets outside the signed scope refused at the network layer
    • Measured numbers, named gaps, and the reports behind them

    The flow · one engagement, start to finish

    From a signed scope to a retest letter, with the machine proving itself at every step.

    Scroll. The panel on the right shows what HeliusOS is doing at each stage. Nothing here is a simulation of your systems; it is a drawing of the method.

    01 · Verified start

    01

    Verified start

    Before anything touches your systems, the machine proves it is what it claims to be. The image signature is checked, the root filesystem is immutable, SELinux is enforcing, the kernel is locked down, and a boot health check passes or the system rolls back to the previous image on its own. The disk unlocks only because the TPM recognises the hardware it was enrolled on.

    LUKS2 sealed to TPM2 · bootc image · automatic rollback

    02

    Scope locked at the network layer

    Your signed scope and authorisation are loaded as a file, and the firewall is built from it: the three targets you authorised are reachable, and everything else is refused before a packet leaves the machine. Scope creep becomes a technical impossibility rather than a promise, which is also what makes the resulting report usable with insurers and customers.

    Default-deny firewall · per-engagement allow-list · audited

    03

    Twelve surfaces, one pass

    Transport, headers, authentication, sessions, access control, cryptography, the mobile binary, dependencies, secrets, storage, any AI feature, and infrastructure. Each gets manual review plus the right tooling, run from an environment where I know exactly what is installed and nothing else. Anything you host also gets the same OpenSCAP and Lynis treatment HeliusOS applies to itself.

    OWASP ASVS and MASVS · manual code review · OpenSCAP and Lynis on servers

    04

    Everything becomes evidence

    Every request, response, screenshot and extracted string is hashed the moment it is captured and stored encrypted on the machine. A finding in the report is a link to the exact artefact that produced it. Your engineers can reproduce it, an auditor can trust it, and I cannot quietly edit it afterwards.

    Hashed at capture · encrypted at rest · deleted after retest unless you keep it

    05

    A report written for two readers

    Page one is for whoever signs: overall risk, the three things to fix this week, and what it means commercially. The rest is for engineers: a grade per surface, a risk matrix, every finding with where, evidence, impact, the fix with code, and the standard it maps to, then a now, thirty and ninety day roadmap. See the sample pages.

    Typically 40 to 80 pages · ISO 27001, PCI DSS, Cyber Essentials, NIST CSF mapping

    06

    Fixed, retested, signed

    After your fixes, the same scope is run again from HeliusOS. Closed findings are verified, accepted risks are documented with your rationale, and a check confirms the fixes introduced nothing new. The retest letter is the page you attach to a sales deal, an insurance renewal or an App Store review note.

    Same scope, same method · retest letter you can share

    Inside the image

    Six layers, each with a real implementation and an honest status.

    Pick a layer. The status is what heliusos-status reports on the machine, not what a brochure would like it to say.

    Baseline hardening

    CentOS Stream 10, built as a bootc image from one definition. The CIS RHEL 10 Level 2 Server benchmark is applied while the image is built, so a machine cannot drift away from it: every HeliusOS device is the same image.

    In the image
    SELinux enforcing, kernel lockdown, auditd with custom rules, AIDE file integrity monitoring, USBGuard allow-listing, hardened SSH limited to the admin group, 30 second login window
    Measured
    CIS 96.9% (374 of 386 scored rules). Of the 12 that fail, 7 are documented deviations and 5 were fixed in the next image
    Why you care
    The baseline is a published benchmark your auditor already recognises, not a private checklist

    Evidence a sceptic can rerun

    Do not take my word for it. That is the point.

    Every HeliusOS release ships an evidence pack, and every client assessment ships the same shape. The two commands below are what produced the numbers at the top of this page.

    helius@heliusos
    $ sudo heliusos-status --pretty
    baseline     ACTIVE    selinux=enforcing lockdown=integrity
    vault        ACTIVE    luks2 tpm2-sealed
    firewall     ACTIVE    inbound=DROP zone=heliusos
    integrity    PARTIAL   signature-policy=unset (dev build)
    shield       PREVIEW   tetragon=not-started auditd=active
    binding      PARTIAL   tpm=absent (vm)
    
    $ sudo heliusos-evidence
    openscap   cis_server_l2   96.9%  374 pass  12 fail  53 n/a
    lynis      hardening-index 84     1 warning  21 suggestions
    sbom       spdx            written
    cve        grype           0 critical reachable
    pack       /var/lib/heliusos/evidence/20261001T085921Z
    • OpenSCAP reportHTML and ARF against the CIS benchmark, rule by rule, with every failure explained
    • Lynis reportHardening index with each warning and suggestion
    • Software bill of materialsEvery package in the image, so you know exactly what touched your systems
    • CVE scanKnown vulnerabilities in the image at release, and whether any is reachable
    • Signature verificationThe one-line command that proves the image is the one I say it is
    • Your assessment, same shapeHashed captures, policy test results, dependency inventory, fix code, and a control mapping for questionnaires

    After the assessment

    The same image can run your own machines.

    Everything HeliusOS does for the assessment it can do for the laptops and servers that hold your secrets: one hardened image, encrypted disks sealed to hardware, signed updates that roll back on failure, and an evidence pack per release that answers the security questionnaire for you. The dashboard shows what is actually on, and the AI layer, Olo, explains an alert in plain language and proposes a step. A person presses the button. It never enforces on its own.

    • Admin and developer workstations that hold production credentials
    • Servers where a published benchmark score is easier than a paragraph of assurances
    • Teams who want "what is actually on" as a screen, not a slide

    Early access. HeliusOS is at v0.1 and runs my own engagements. If you want it on your fleet, that is a conversation and a pilot, not a download button, and the roadmap above is what you would be buying into.

    Helius NetworkSecurity Centerv0.1
    97%
    ProtectedCIS Level 2 · last evidence run today
    • Disk encryptionSealed to TPM
    • App containmentEnforcing
    • FirewallInbound deny
    • System integritySigned updates
    • Activity monitoringPreview

    Get HeliusOS

    Five steps from a request to a report in your inbox every morning.

    HeliusOS is sold as a pilot licence per device: the signed image, updates, the evidence pack for every release, and me on Helius Connect when something needs a human. There is no anonymous download, because the image is signed to you and the first boot is where most installs go wrong.

    1. 01

      Request the image

      Tell me how many machines and what they do. You get a licence, a download link for the installer, and the one-line command that verifies the image signature before you trust it.

      $ cosign verify --key heliusos-cosign.pub ghcr.io/heliusnetwork/heliusos:stable
    2. 02

      Install

      Boot the installer. It erases the target disk, creates an encrypted root (LUKS2), and asks you for the passphrase and an admin user. No secret is baked into the image, so nothing I hold can unlock your machine.

      clearpart --all --initlabel  part / --encrypted --luks-version=luks2
    3. 03

      First boot, two commands

      Set the per-device root and bootloader passwords, then seal the disk to this machine’s TPM so it unlocks itself only on this hardware and only when the boot chain matches.

      $ sudo heliusos-setup
      $ sudo heliusos-vault-enroll
    4. 04

      One line for the daily report

      From then on, at six every morning, the machine runs its own evidence pass and writes a report: the CIS pass rate and Lynis index with the change since yesterday, failing rules, any staged update, file integrity, failed logins and denied connections in the last 24 hours, and every layer’s real status. It lands in ~/HeliusOS Reports and, if the machine can send mail, in your inbox. The verdict is deterministic, so a quiet day reads Steady and a bad one reads Regressed before you have had coffee.

      $ sudo heliusos-report --enable you@company.com
      Daily report enabled: 06:00 local time, /var/lib/heliusos/reports/<date>.html
      HeliusOS daily report 2026-10-02: Steadyheliusos@your-machine
      CIS Level 296.9% (no change) · failing rules 12
      Lynis84 (no change) · warnings 1
      Staged updatenone
      File integrityno changes reported in 24h
      Failed logins, 24h0
      Denied connections, 24h37
      Layersbaseline active · vault active · firewall active · integrity active · shield preview
    5. 05

      Updates that cannot brick you

      New images are signed, downloaded in the background, and applied on a reboot you plan. The boot health check runs on the way up; if it fails, the machine is back on the previous image before you notice. Every release ships its evidence pack, so the report you forward to a customer is always about the version you are running.

      $ sudo bootc status
      booted  heliusos:0.1   staged  heliusos:0.2 (applies on next reboot)

    Request the image

    Tell me about the machines.

    I reply within one business day with a licence proposal, the link and the verification command. Pilot pricing is per device per month and includes updates, evidence packs and support on Helius Connect.

    HeliusOS is at v0.1. If your environment needs something it does not do yet, I will say so rather than sell it to you.

    Signed image, licence and verification command within one business day.

    Start

    Give me a signed scope and I will give you a report you can rerun.

    Fixed prices on the main page. NDA before the first substantive conversation. All communication on Helius Connect, end-to-end encrypted.