Cicada.OS is an open-source laptop OS. The package engine is Arch Linux (official repos). Cicada is the product layer on top: greeter, dock, settings, launcher monopoly, per-app scopes, Helium browser policy, and a pinned update channel.
It is not GrapheneOS, not AOSP, and not a phone OS. Graphene’s permission model is an inspiration for the scopes sheet — not the codebase. Official releases: download. Install: install.
Status — read this before you trust it
PRE-ALPHA
Cicada boots to a Hyprland desktop on an Intel MacBook Air. Most of the hardening on this site is verified structurally — the configuration says the thing — and a growing part of it is now verified against a real Linux kernel. Little of it has been exercised on hardware end to end. Do not rely on this for anything that matters yet.
- On a real kernelFirewall + VPN kill switch, NTS time, Tor bootstrap, onion namespace, session duress wipe
- In simulationUSB gate and its restore path, watchdog arming, escape hatches, beacon signing and alarm
- Needs the hardwarehardened_malloc under Helium, chipset watchdog reset, kernel USB refusal, LoRa beacon
Full list: Status in the README.
Threats vs evidence
HONEST
| Threat | What we ship | What we do not claim |
|---|---|---|
| Trackers / school HTTPS filter / cold stolen disk | Helium managed policy + LUKS2 passphrase (installed systems) | “Unbreakable” crypto or Graphene-class attestation |
| Device seized while on or just locked (AFU) | Lock timer reboot, USB authorize gate, optional duress wipe | Cellebrite / GrayKey “no access” — that is userspace, not Titan |
| Evil maid / firmware on Apple EFI Air | Nothing that survives that class | Verified boot — needs Heads/PureBoot-class hardware |
| “Is this just Arch with a theme?” | Launcher monopoly + scopes + Work UID + channel path | Android UID isolation or Qubes VMs |