Build & release field kits

StealthForge

Every device, built clean. Every time.

A field tool is only as trustworthy as the build it came from.

StealthForge is the air- gapped machine that builds, licenses, and updates every StealthCommand device from a known-good image — wiped, encrypted, hardened, and signed — so you can prove what's collecting on your network was never tampered with.

What every build delivers

The air-gapped machine that provisions, licenses, and updates every StealthCommand device — a sealed, known-good build in under 30 minutes, with no connection to anything.

Sealed device

Wiped, hardened, signed, field-ready in under 30 minutes.

Signed BSOM

A cryptographically signed bill of materials with every build.

SCAP scan

A DISA STIG compliance scan delivered with the build.

Encrypted drive

Zero-knowledge hardware encryption on every device.

Same build, every time

A deterministic image — identical, repeatable, verifiable.

Just a few steps from raw hardware to a sealed, trusted device.

1. Connect

Attach the device and a certificate-bound laptop. Fully air-gapped — no network needed.

2. Register

Scan for the connected device and register it to your certificate.

3. Deploy

Click once. The automation wipes, encrypts, hardens, signs, and seals the build.

+ Reprovision

Re-image, update, or re-license any device the same way, any time.

The build security model

Trust the device, not a promise

Drive wiped, then zero-knowledge encryption, Ubuntu 24.04 + KOS, a DISA STIG on the OS and Kubernetes, and scratch containers that are cryptographically signed. If any container is altered, the device won't boot.

Hardware and build

Category
Feature
Build
Platform
Protectli FW6E (fanless)
Memory
32–64 GB DDR4
Network
6 × Intel 1 GbE (RJ-45)
Chassis
Aluminum, fanless, NDAA
Processor
Intel Core i7-8550U (4C/8T)
Storage
2–4 TB NVMe
Crypto
AES-NI hardware acceleration
OS/engine
Ubuntu 24.04 + KOS