Build & release field kits

StealthForge

Every device, built clean. Every time.

The air-gapped machine that provisions, licenses, and updates every StealthCommand device — a sealed, known-good build in under 30 minutes, with no connection to anything.

A field tool is only as trustworthy as the build it came from. StealthForge is the air-gapped machine that builds, licenses, and updates every StealthCommand devicefrom a known-good image — wiped, encrypted, hardened, and signed — so you can prove what's collecting on your network was never tampered with.

What every build delivers

Sealed device

Wiped, hardened, signed, field-ready — in under 30 minutes.

Signed BSOM

A cryptographically signed bill of materials with every build.

SCAP scan

A DISA STIG compliance scan delivered with the build.

Encrypted drive

Zero-knowledge hardware encryption on every device.

Same build, every time

A deterministic image — identical, repeatable, verifiable.

Three steps from raw hardware to a sealed, trusted device.

1. Connect

Attach the device and a certificate-bound laptop. Fully air-gapped — no network needed.

2. Register

Scan for the connected device and register it to your certificate.

3. Deploy

Click once. The automation wipes, encrypts, hardens, signs, and seals the build.

+ Re-provision

Re-image, update, or re- license any device the same way, any time.

Trust the device, not a promise

Drive wiped, then zero-knowledge encryption, Ubuntu 24.04 + KOS, a DISA STIG on the OS and Kubernetes, and scratch containers that are cryptographically signed. If any container is altered, the device won't boot.

StealthForge shares the air-gapped command appliance with StealthControl. One box provisions every device and turns what they collect into maps, policy, and compliance.

Where teams use it

Provision a new field device ⋅ Re-image a returned unit ⋅ Replace a field device ⋅ Push a licensed update ⋅ Wipe & reset after an engagement ⋅ Prove a clean build to an auditor ⋅ Rebuild kit before the next deployment