// Privacy-first NixOS. Tails meets modern Hyprland.
Every layer hardened. Nothing leaks.
All traffic transparently proxied through Tor at the system level. No app can bypass it. DNS through Tor's DNSPort — zero leaks.
Calamares pre-selects full-disk LUKS2 with Argon2id KDF. You can't skip it. Encrypted swap — no plaintext pages on disk.
Ships with linux-hardened and the full patch set. ASLR maximized, ptrace restricted, ICMP blocked, SYN cookies on.
MAC randomized per-connection. Firewall blocks all inbound by default. Mullvad preinstalled. You're invisible on the network.
Wayland-only. No X11 side-channels. Modern tiling WM with Waybar Tor indicator, Wofi, Dunst, Hyprlock.
Webcam and mic disabled at kernel level — modules blacklisted. USBGuard blocks unknown devices. Re-enable with one command.
Mullvad VPN preinstalled — stack it on top of Tor.
Mullvad ships in the ISO. Log in with your account number — no email, no personal info required. That's kind of the point.
Your traffic goes through Tor first, then Mullvad. The VPN sees a Tor exit node, not you. Tor sees Mullvad, not your destination.
Mullvad has been independently audited multiple times. They literally can't log you — they don't know who you are.
Confirm everything is locked down.
Designed to keep you safe. Every default is hardened — no tweaking required.