Cyberiad, a Haction product

Linux hardening you can prove.

Cyberiad turns CIS, DISA STIG and ANSSI baselines into approved, signed and delivered server configuration, with the evidence your auditor asks for.

The problem

Hardening is a patchwork of scripts, scanners and spreadsheets

Hardening means configuring a server to a recognised security standard. Regulated organisations must show how their servers are configured, and the auditor asks: which rules, on which hosts, approved by whom?

Manual

Each team keeps its own hardening scripts, and configuration drifts after the first update.

Unproven

When the auditor asks which rules were applied, on which hosts, and who approved the exceptions, the answer is a spreadsheet.

Repeated

A new standard version or OS release means doing the work again, with no record of past decisions.

The scale of the task: the security guide for one distribution, RHEL 9, has 1,540 rules, and its DISA STIG profile alone selects 481 of them. Ubuntu, Debian, SUSE and others each have their own guides. (Security guide release 0.1.82.)

How it works

One lifecycle, six steps

Cyberiad replaces the patchwork with one process: from a recognised standard to auditor-ready proof.

  1. 1. Tailor

    Pick a security guide for your distribution and a baseline, for example CIS Level 1 Server for Ubuntu 24.04. Switch off rules that do not apply and set values such as password or session timeouts. Every change is validated, and the result is computed exactly as OpenSCAP, the scanner auditors use, will evaluate it.

  2. 2. Approve

    A second person reviews and approves the tailoring (the four-eyes principle). Nobody can approve their own change, and every decision is recorded with its reason.

  3. 3. Sign

    The approved version becomes an immutable, numbered release, signed with a cloud KMS key and with Sigstore keyless signing in a public transparency log.

  4. 4. Deliver

    Cyberiad delivers the release where you want it: an S3-compatible or Google Cloud Storage bucket, an OCI container registry, a GitHub or GitLab release, or a signed webhook.

  5. 5. Harden

    Your server pulls the package, verifies checksums and signatures, and applies it with the included script. Cyberiad never connects to the server.

  6. 6. Prove

    OpenSCAP scans before and after show the effect. Every decision, approval, release and delivery sits in a tamper-evident audit trail.

Value

What Cyberiad gives you

One place for the whole lifecycle

Standard, tailoring, approval, signed release, delivery and proof in one process, instead of separate scanners, scripts and spreadsheets.

Proof, not promises

OpenSCAP scans before and after, signed releases anyone can verify independently, and a tamper-evident trail of who decided what and when.

Expertise ready from day one

Recognised standards, ready-made rule sets for 40 Linux versions and Haction advisories at every rule: no writing rules from scratch.

No access to your servers

Servers pull and verify the package themselves. Cyberiad holds no passwords or keys to them: passive by design.

A managed service

You do not run the platform; Haction keeps it and its content up to date. Installation in your own infrastructure is possible on request.

Open formats, no lock-in

Tailorings, packages, releases and audit records export in open formats (XCCDF, JSON, CSV, OCSF-shaped JSON). Signatures verify with standard tools, without Cyberiad.

Expertise ready from day one

No writing rules from scratch

  • Recognised standardsCIS, DISA STIG and ANSSI
  • Rule setswidely used in industry and government
  • Haction advisorieswhy each rule exists and what to watch out for
  • Ready in Cyberiadtailor, approve and deliver

Proof

Numbers, not promises

Failing rules before and after applying a Cyberiad signed package to freshly installed servers. Two remediation passes, scanned with OpenSCAP after a reboot.

Failing security rules before and after hardening with Cyberiad
SystemStandardFailing beforeFailing afterRules evaluated
RHEL 9CIS Level 1 Server925295
Ubuntu 24.04CIS Level 1 Server1057408
Debian 12ANSSI BP-028 intermediary8410225

On RHEL 9 the pass rate rose from 64.9 % to 98.1 % (share of rules that pass, of those that pass or fail; not-applicable rules excluded).

Measured on Haction’s own test machines (stock Google Cloud images), not on a customer estate. September 2026, reproduced on 7 October 2026 with signed release 1.0.2.

The remaining failures are rules that need a site decision (for example a bootloader password), a separate disk partition, or have no automated fix. That is normal, and Cyberiad lists them with advice.

  • 40

    Linux security guides in the catalogue

  • 2,083

    distinct rules across the catalogue

  • 5,776

    Haction advisories covering every rule, value and group

  • 519 / 519

    checks across 76 test cases matching OpenSCAP 1.4.4

Catalogue and advisory figures as of 27–28 September 2026; OpenSCAP cross-check 26 September 2026.

Inside Cyberiad

Standard, advisories and AI assistant on one screen

Cyberiad workbench: a searchable tree of security rules on the left and, on the right, a Haction advisory for the rule that disables IP forwarding on IPv4 interfaces.
The workbench: the standard’s rule tree with selected rules and severities, and a Haction advisory at the rule: why it matters, what can break and how to check it.
Cyberiad AI assistant panel with example questions such as “How many high severity rules in this profile have no Ansible remediation?”
The AI assistant answers in plain language. Every number comes from a deterministic query over the security guides, not from the model.

Cyberiad Advisories

Haction’s expert layer at every rule

Every rule, value and group in the catalogue carries curated guidance: why it matters (the threat, the MITRE ATT&CK technique, what fails without it) and how to implement it (what can break, rollout order, values to decide, one command to verify).

Writers flagged every statement they were unsure of, and checkers resolved each against primary sources such as man pages, kernel documentation, distribution sources and NVD/MITRE: 1,567 outcomes, of which 1,093 verified, 292 corrected, 167 softened and 15 removed.

AI assistant

AI you can trust with numbers

The assistant answers questions such as “Which high-severity STIG rules have no Ansible fix?”, compares profiles and edits the tailoring on request. It does not calculate or remember numbers: it calls deterministic queries over the parsed security guides and reports their results.

  • Can only use the actions the signed-in person is allowed to perform.
  • Cannot manage members, roles, tokens or delivery targets.
  • In the evaluation used to choose the model, the selected configuration answered 18 of 18 test scenarios correctly; in production spot checks, 12 of 12 answers were exact.

Security and architecture

Built for security reviews

Passive by design

Cyberiad holds no credentials to your servers and never connects to them. Your servers pull the package.

Two signatures on every release

A cloud KMS key (ECDSA P-256) and Sigstore keyless signing recorded in the public Rekor transparency log. Verify with cosign or openssl, without access to Cyberiad.

Tamper-evident audit trail

Append-only and hash-chained, so any later alteration is detectable. Exports to CSV and OCSF-shaped JSON Lines and streams to a SIEM through signed webhook batches.

Four-eyes approval, enforced

Nobody approves their own revision, and releases are built only from approved revisions. Eight workspace roles, from owner to auditor and viewer.

Policy-based authorisation

Open Policy Agent checks every screen action, assistant tool and API call; denials are recorded. Sensitive actions require a fresh sign-in.

Isolated workspaces

Each organisation has its own workspace, with data isolation enforced in the database itself (row-level security), not only in the application.

Your identity provider

Sign in with Microsoft Entra ID or any OpenID Connect provider. Delivery to cloud buckets uses identity federation, with no stored keys.

Tested

More than 350 automated tests, plus 36 authorisation-policy tests covering 100 % of the policy.

Hosting and sovereignty

Hosted in London, open by design

Cyberiad is a managed cloud service running in Google Cloud’s London region (UK). An instance in an EU region or an installation in your own infrastructure is available on request.

  • Open formats: XCCDF 1.2 tailorings, standard zip packages, CSV and OCSF-shaped JSON audit records.
  • Releases you received keep working and verifying without Cyberiad.
  • The AI assistant uses Google Gemini on Vertex AI. It reads security-guide data and your workspace’s own content, never your servers.

Coverage

Every major Linux distribution, the standards you are asked for

40 Linux security guides

  • Red Hat Enterprise Linux 7, 8, 9 and 10
  • CentOS Stream 9 and 10
  • AlmaLinux 9
  • Oracle Linux 7–10
  • Ubuntu 18.04, 20.04, 22.04 and 24.04
  • Debian 10–13
  • SUSE Linux Enterprise 12, 15 and 16
  • SLE Micro 5 and 6
  • openSUSE
  • Fedora
  • Amazon Linux 2023
  • and others

Baselines included

  • CIS Benchmarks (Level 1 and 2, server and workstation)
  • DISA STIG
  • ANSSI BP-028 (minimal to high)
  • PCI DSS
  • HIPAA
  • NIST 800-53 High and Moderate
  • NIST 800-171 (CUI)
  • German BSI
  • Spanish CCN
  • Australian Essential Eight and ISM
  • and others

Availability of each baseline differs by distribution. You can also upload your own SCAP 1.2/1.3 data streams or XCCDF 1.2 benchmarks. Standard names identify the baselines Cyberiad implements; they do not imply certification or endorsement by the bodies that publish them.

Where Cyberiad fits

It connects the steps other tools cover one at a time

Cyberiad complements the tools you already have: it uses the same OpenSCAP results and the same open remediation content.

How Cyberiad complements other categories of tools
CategoryStrong atWhat Cyberiad adds
Compliance scannersAssessing hosts against benchmarksTailoring workflow, remediation delivery and signed releases
Vendor compliance servicesDepth for one vendor’s OSOne process for mixed estates across distributions
Automation contentApplying changes at scaleApproval, signing and an evidence chain
GRC platformsCollecting evidence and mapping controlsChanging and verifying host configuration

FAQ

Questions we are asked

What is Linux hardening?

Configuring a server to a recognised security standard, for example closing unneeded services, tightening SSH, and setting password and audit rules, so that it is harder to attack and easier to audit.

Which standards does Cyberiad support?

CIS Benchmarks, DISA STIG and ANSSI BP-028 are the main ones; the guides also include PCI DSS, HIPAA, NIST 800-53 High/Moderate, NIST 800-171 (CUI), BSI, CCN, Essential Eight, ISM and others. Availability depends on the distribution.

Which Linux distributions?

40 guides covering Red Hat Enterprise Linux 7–10, CentOS Stream, AlmaLinux, Oracle Linux, Ubuntu 18.04–24.04, Debian 10–13, SUSE Linux Enterprise 12–16, SLE Micro, openSUSE, Fedora, Amazon Linux and more. You can also upload your own SCAP content.

Does Cyberiad need access to our servers?

No. Your servers pull the signed package from your own bucket, registry or repository, verify it and apply it. Cyberiad holds no passwords or keys to them.

Do we need to install an agent?

No. The package uses the distribution’s own OpenSCAP scanner.

How do we know the package was not tampered with?

Every release is signed twice (a cloud KMS key and Sigstore keyless signing in a public transparency log) and ships checksums. You can verify it with cosign or openssl without Cyberiad.

What does the auditor get?

Before-and-after OpenSCAP scan reports, the approved tailoring with its reasons, the signed release that was applied, and an audit trail showing who approved and published what, and when.

Is the rule content proprietary? If the rules are open, what are we paying for?

The rules follow recognised public benchmarks and open SCAP content, which is why OpenSCAP and auditors’ scanners understand them. You pay for everything around the rules: tailoring and approvals, signed and versioned releases, delivery to your environment, proof, the Haction advisories, and a maintained platform that keeps up with new standard and OS versions.

Will hardening break our applications?

Some settings can affect applications. That is why every rule has an advisory that explains what can break and how to roll it out, and why the package can first run in report-only mode. Haction recommends a test environment before production rollout.

Can we see what it will change before applying it?

Yes: report-only evaluation, a generated shell script or Ansible playbook to review, and an HTML guide of the selected rules.

How does the AI assistant avoid making things up?

It does not calculate or remember numbers; it calls deterministic queries over the parsed security guides and reports their results. Its actions are limited to what your role allows.

Where is the service hosted?

Today on Google Cloud in London (UK). An instance in an EU region or an installation in your own infrastructure is available on request.

Can we leave?

Yes. Everything uses open formats (XCCDF, JSON, CSV, OCSF-shaped JSON, standard zip packages), and releases you received keep working and verifying without Cyberiad.

Does it integrate with our SIEM?

The audit trail streams to a SIEM through signed webhook batches and exports as CSV and OCSF-shaped JSON Lines. Native Splunk HEC and Microsoft Sentinel connectors are not available yet.

How do people sign in?

Microsoft Entra ID or any OpenID Connect identity provider, with roles per workspace. Sensitive actions require a fresh sign-in.

How is Cyberiad offered?

As an annual subscription per workspace, tiered by estate size, with unlimited users and all guides and advisories included. There is no per-host metering, so you can harden everything. Haction also offers pilots, tailoring workshops, exception management and audit preparation.

How do we start?

Book the free 30-minute demonstration on a Linux system and standard of your choice.

For advisory firms

Add Linux hardening to your compliance projects

Advisory and consulting firms can offer Cyberiad as a module of their compliance projects. Haction supplies the platform, the content and second-line support, with one workspace per client.

Talk to us about partnering

Next step

30 minutes: Cyberiad on the Linux system you choose

You pick the system and the standard; we show the whole process. Free, in our test environment, with no access to your network.

We’ve got your back.

Katarzyna Wojtczak

Co-Founder, Haction