CICADA.OS
● LIVE ·
MAGI-01 // SENTRY
CHANNEL · cicada-stable
SRC · GITHUB
TRACKED · LAPTOP OS

Public beta · live USB = test · install = product

CICADA.OS

The private laptop OS you can actually use.

GrapheneOS intent. Hyprland daily driver. Flash the ISO to try; run cicada-install when you want files and wallpaper to stick.

About

BALTHASAR-2

Cicada.OS is a privacy and security focused laptop operating system, developed as an open source project. It hardens defaults, owns the launcher, and ships Graphene-shaped permissions — without making you fight the machine for Wi‑Fi, files, or a browser.

Official releases land on the download page. Installation instructions are on the install page. Claims stay honest about silicon — see the table below.

Product layers

POLICY OS
  • LauncherDock / Wofi / MIME only start Cicada wrappers
  • ScopesDefault-deny network, files, cam, mic
  • Work UIDSecond Unix user — not a folder named Burner
  • BrowserHelium with Vanadium-class managed policy
  • ChannelPinned cicada-stable — not floating Arch extra

Not Google · Not AOSP theater

ENGINE

Cicada will never ship a fake Titan story on Apple EFI. Arch remains the package engine; the product layer is what you touch. Kitty is Owner adb — power user escape, not the UI.

Claims — do not collapse them

THREAT MODEL
ClaimWhen true
Trackers / school filter / cold disk thief Strong passphrase + Helium policy + LUKS — mostly now
LEO with AFU (on or just locked) Never “can’t.” Shorten the window. Still userspace.
Firmware / evil maid on Apple EFI Air Never. Heads/PureBoot is a different laptop.
Cicada is its own OS No unsandboxed dock path; scopes; Work UID; signed channel. Identity, not uncrackability.

Device support

HARDWARE TIERS