FAQ
Short answers. Longer threat model: docs/THREAT_MODEL.md in the repo.
What base OS is this?
Arch Linux. Kernel, pacman, and systemd are stock Arch packages from official repos. Cicada is the product layer (desk, scopes, install, channel). We do not rebase to NixOS or Fedora Atomic.
Is this GrapheneOS for laptops?
No. GrapheneOS is an Android OS. Cicada is not a port of AOSP and does not claim Titan,
Auditor, or Graphene’s kernel sandbox. We borrowed the idea of a permission sheet and hostile
defaults — then implemented those with Linux tools (bwrap, policy files, LUKS). Saying
“GrapheneOS” as the base was wrong; if you saw that, the site needed this FAQ entry.
Isn’t this just Arch?
Arch packages power it. The dock and launcher do not hand you raw Arch .desktop files —
they start cicada-run wrappers with per-app scopes. You can still open Kitty and escape to a
normal shell; that is intentional (owner shell), not a secret.
Why not Qubes?
Qubes wins real compartments (VMs). Cicada is a single-user Hyprland daily driver with process-level scopes. Different job. Use Qubes if the threat is malicious PDFs across trust domains.
Does the camera kill really kill?
Software: unloads uvcvideo, forces scopes deny. Root can reverse it.
Hardware kill switches (Librem-style) are the real ceiling.
Can I run this on my Framework?
That is the intended daily-driver tier. Enroll TPM2 and Secure Boot after install. Prototype development still happens on Intel MBA 2015–2017 (no Graphene-class boot story there).