Free Forever See pricing →

Security & trust

The smallest attack surface in edge.

Admiral is immutable, outbound-only, and built on hybrid post-quantum cryptography from the first commit. The most up-to-date edge platform on the planet.

Most edge platforms bolt on security. They ship mutable operating systems, open inbound ports for management, and leave you responsible for patching a sprawling userspace across every device in your fleet.

Admiral takes the opposite approach. We control the entire infrastructure end-to-end: the cloud control plane, the transport fabric, and every byte executing on the physical machine. Every system component—upstream mainline Linux kernel, bootloader, init supervisor, and networking engine—is open-source compilable from source. There are zero opaque vendor blobs, zero third-party wrapper daemons, and zero unvetted package mirrors.

The entire rootfs is immutable and cryptographically signed with dm-verity Merkle trees. No inbound ports. No shell. No SSH. Every device holds a hardware-rooted cryptographic identity and authenticates with post-quantum, non-replayable proof-of-possession.

And because Admiral ships a tightly coupled kernel and supervisor, we track CVEs upstream and roll patched images continuously. No other platform can give you this level of deterministic provenance, supply-chain sovereignty, and zero-trust verification.

Our posture

How Admiral defends your fleet.

Operational

Supply-Chain Sovereignty

Operational

Immutable by default

Operational

No inbound ports

Operational

Post-quantum cryptography

Operational

Hardware-rooted identity

Operational

Proof-of-possession auth

Operational

Short-lived credentials

Operational

Zanzibar-style RBAC

Operational

Always-on CVE tracking

Operational

Offline survivability

Operational

24/7 monitoring

Operational

Encryption everywhere

In progress

SOC 2 Type II

Transparency

Talk to our security team.

Responsible disclosure, architecture deep-dives, and DPA requests all welcome.

Dig into the architecture with our team.

Our security lead is happy to walk you through our cryptography, threat model, and CVE response process.

Explore the docs