About
BALTHASAR-2Cicada.OS is a privacy and security focused laptop operating system, developed as an open source project. It hardens defaults, owns the launcher, and ships Graphene-shaped permissions — without making you fight the machine for Wi‑Fi, files, or a browser.
Official releases land on the download page. Installation instructions are on the install page. Claims stay honest about silicon — see the table below.
Product layers
POLICY OS- LauncherDock / Wofi / MIME only start Cicada wrappers
- ScopesDefault-deny network, files, cam, mic
- Work UIDSecond Unix user — not a folder named Burner
- BrowserHelium with Vanadium-class managed policy
- ChannelPinned cicada-stable — not floating Arch extra
Not Google · Not AOSP theater
ENGINE
Cicada will never ship a fake Titan story on Apple EFI.
Arch remains the package engine; the product layer is what you touch.
Kitty is Owner adb — power user escape, not the UI.
Claims — do not collapse them
THREAT MODEL| Claim | When true |
|---|---|
| Trackers / school filter / cold disk thief | Strong passphrase + Helium policy + LUKS — mostly now |
| LEO with AFU (on or just locked) | Never “can’t.” Shorten the window. Still userspace. |
| Firmware / evil maid on Apple EFI Air | Never. Heads/PureBoot is a different laptop. |
| Cicada is its own OS | No unsandboxed dock path; scopes; Work UID; signed channel. Identity, not uncrackability. |
Device support
HARDWARE TIERS- PrototypeIntel MacBook Air 2015–2017 — software privacy only
- DailyFramework / modern ThinkPad — TPM2 + Secure Boot enroll
- Boot storyLibrem / NitroPad + Heads — evil maid answer