The smallest attack surface in edge.
Admiral is immutable, outbound-only, and built on hybrid post-quantum cryptography from the first commit. The most up-to-date edge platform on the planet.
Most edge platforms bolt on security. They ship mutable operating systems, open inbound ports for management, and leave you responsible for patching a sprawling userspace across every device in your fleet.
Admiral takes the opposite approach. We control the entire infrastructure end-to-end: the cloud control plane, the transport fabric, and every byte executing on the physical machine. Every system component—upstream mainline Linux kernel, bootloader, init supervisor, and networking engine—is open-source compilable from source. There are zero opaque vendor blobs, zero third-party wrapper daemons, and zero unvetted package mirrors.
The entire rootfs is immutable and cryptographically signed with dm-verity Merkle trees. No inbound ports. No shell. No SSH. Every device holds a hardware-rooted cryptographic identity and authenticates with post-quantum, non-replayable proof-of-possession.
And because Admiral ships a tightly coupled kernel and supervisor, we track CVEs upstream and roll patched images continuously. No other platform can give you this level of deterministic provenance, supply-chain sovereignty, and zero-trust verification.
How Admiral defends your fleet.
Supply-Chain Sovereignty
Every binary on the machine—mainline kernel, bootloader, init supervisor, container boundary—is compiled from source. Zero proprietary vendor blobs or unvetted third-party distro packages.
Immutable by default
Fully immutable Linux distribution. No shell, no package manager, no mutable filesystem. Your attack surface is a rounding error.
No inbound ports
Devices never expose listening ports. All communication is outbound. No SSH, no agent ports, nothing to scan.
Post-quantum cryptography
Hybrid TLS 1.3 with ML-KEM key exchange everywhere. Vaccinated against harvest-now, decrypt-later from day one.
Hardware-rooted identity
Every device gets a sovereign cryptographic identity at boot. Late-binding tenancy means devices stage under human control.
Proof-of-possession auth
Every credential rotation requires a fresh, non-replayable challenge signed by the device's hardware key.
Short-lived credentials
30-minute, micro-segmented session tokens. Retire a device and its access evaporates on the next rotation.
Zanzibar-style RBAC
Fine-grained, relationship-based access control modelled on Google's Zanzibar. Every action authorised against a tamper-evident graph.
Always-on CVE tracking
We track upstream kernel and userspace CVEs continuously, shipping patched images the moment they land.
Offline survivability
Devices cache last-known-good credentials locally. If backhaul drops, your fleet keeps running and buffers telemetry.
24/7 monitoring
Control plane monitored around the clock, backed by global peering networks including Megaport.
Encryption everywhere
AES-256 at rest, hybrid post-quantum TLS 1.3 in transit. Customer-managed keys available on request.
SOC 2 Type II
Controls already implemented and enforced. The audit is the formal signoff on work done from day one.
Talk to our security team.
Responsible disclosure, architecture deep-dives, and DPA requests all welcome.
Dig into the architecture with our team.
Our security lead is happy to walk you through our cryptography, threat model, and CVE response process.