esOS 1.0 · Encryption Studio OS

Encrypt files on a computer that cannot reach the network.

esOS is a live operating system for file encryption. It boots from a USB stick, runs entirely in memory and has no network stack. You work with your files, power off, and nothing is left on the computer.

  • No TCP/IP
  • RAM only
  • UEFI and BIOS
  • Linux 6.18 LTS
tty1esOS 1.0
esOS 1.0 starting - kernel 6.18.54-esOS (x86-64-v3)

  ==========================================================
   esOS 1.0  -  Encryption Studio OS
   kernel 6.18.54-esOS (x86-64-v3)
   Copyright (c) 2026 Koray USTUNDAG.
  ==========================================================

  Getting started:
    keyboard_setup     choose your keyboard layout (default: US)
    esx --help         encrypt / decrypt files
    hwreport           hardware and security summary
    poweroff           power off (USB sticks are unmounted safely)

esOS:~# mount /dev/sdb1 /mnt
esOS:~# esx encrypt -i /mnt/report.pdf -o /mnt/report.enc -k public.pem
esOS:~# 

Design

Isolation comes from what esOS leaves out.

Most hardening adds rules on top of a full system. esOS starts from an empty kernel configuration and adds only what file encryption needs.

CONFIG_INET=n

No network, by construction

The kernel has no IP stack and no network drivers. There is no firewall to misconfigure because there is nothing to filter.

initramfs → RAM

Runs in memory

The whole system unpacks into RAM. No swap, no hibernation, no core dumps. Memory is zeroed when it is allocated and when it is freed.

lockdown=confidentiality

A hardened kernel

Kernel lockdown, Yama ptrace limits and an IOMMU on by default. No loadable modules, kexec, BPF, io_uring or user namespaces.

SHA-256 + PGP

Built from verified source

Every upstream source archive is checked against its SHA-256 and its maintainer's signature before it is compiled. The full source of each release is published.

How it works

From USB stick to encrypted file in four steps.

  1. Write the image

    Copy the 26 MB image to a USB stick with dd, Rufus or balenaEtcher. Nothing is installed.

  2. Boot from it

    Start the computer from the stick. esOS boots on UEFI and legacy BIOS machines, from USB or DVD.

  3. Encrypt

    Choose your keyboard with keyboard_setup, mount your storage, and encrypt with a password or an RSA key using esx.

  4. Power off

    Run poweroff. Mounted file systems are unmounted in reverse order. esOS does not touch the computer's own drives unless you mount one.

Inside esOS 1.0

A small system you can read end to end.

esOS is built from source with a fixed set of components. The kernel has every driver built in, the init process is about 500 lines of C, and the image fits in 26 MB.

Full component list with licenses: Licenses.

Versions shipped in esOS 1.0.
KernelLinux 6.18.54 LTS · x86-64-v3 · modules off
Boot loaderGRUB 2.16 · UEFI + legacy BIOS
C libraryglibc 2.44
CryptographyOpenSSL 3.5.8 LTS · cryptsetup 2.8.8 (LUKS2)
ApplicationEncryption Studio X (esx) · .NET NativeAOT
Shell and toolsbash 5.3 · coreutils 9.12 · util-linux 2.42.4
File systemsext4 · FAT · exFAT · NTFS · ISO 9660 · Btrfs · XFS
StorageUSB · NVMe · SATA · SD/eMMC
Keyboard layoutsTR-Q · TR-F · US · UK · DE · FR · ES · IT · RU
Networknone (AF_UNIX only)

esOS 1.0 is available for x86-64 computers.

Intel Haswell (2013) or AMD Excavator/Zen and newer. Secure Boot must be turned off.