Manual
Each team keeps its own hardening scripts, and configuration drifts after the first update.
Cyberiad, a Haction product
Cyberiad turns CIS, DISA STIG and ANSSI baselines into approved, signed and delivered server configuration, with the evidence your auditor asks for.
The problem
Hardening means configuring a server to a recognised security standard. Regulated organisations must show how their servers are configured, and the auditor asks: which rules, on which hosts, approved by whom?
Each team keeps its own hardening scripts, and configuration drifts after the first update.
When the auditor asks which rules were applied, on which hosts, and who approved the exceptions, the answer is a spreadsheet.
A new standard version or OS release means doing the work again, with no record of past decisions.
The scale of the task: the security guide for one distribution, RHEL 9, has 1,540 rules, and its DISA STIG profile alone selects 481 of them. Ubuntu, Debian, SUSE and others each have their own guides. (Security guide release 0.1.82.)
How it works
Cyberiad replaces the patchwork with one process: from a recognised standard to auditor-ready proof.
Pick a security guide for your distribution and a baseline, for example CIS Level 1 Server for Ubuntu 24.04. Switch off rules that do not apply and set values such as password or session timeouts. Every change is validated, and the result is computed exactly as OpenSCAP, the scanner auditors use, will evaluate it.
A second person reviews and approves the tailoring (the four-eyes principle). Nobody can approve their own change, and every decision is recorded with its reason.
The approved version becomes an immutable, numbered release, signed with a cloud KMS key and with Sigstore keyless signing in a public transparency log.
Cyberiad delivers the release where you want it: an S3-compatible or Google Cloud Storage bucket, an OCI container registry, a GitHub or GitLab release, or a signed webhook.
Your server pulls the package, verifies checksums and signatures, and applies it with the included script. Cyberiad never connects to the server.
OpenSCAP scans before and after show the effect. Every decision, approval, release and delivery sits in a tamper-evident audit trail.
Value
Standard, tailoring, approval, signed release, delivery and proof in one process, instead of separate scanners, scripts and spreadsheets.
OpenSCAP scans before and after, signed releases anyone can verify independently, and a tamper-evident trail of who decided what and when.
Recognised standards, ready-made rule sets for 40 Linux versions and Haction advisories at every rule: no writing rules from scratch.
Servers pull and verify the package themselves. Cyberiad holds no passwords or keys to them: passive by design.
You do not run the platform; Haction keeps it and its content up to date. Installation in your own infrastructure is possible on request.
Tailorings, packages, releases and audit records export in open formats (XCCDF, JSON, CSV, OCSF-shaped JSON). Signatures verify with standard tools, without Cyberiad.
Expertise ready from day one
Proof
Failing rules before and after applying a Cyberiad signed package to freshly installed servers. Two remediation passes, scanned with OpenSCAP after a reboot.
| System | Standard | Failing before | Failing after | Rules evaluated |
|---|---|---|---|---|
| RHEL 9 | CIS Level 1 Server | 92 | 5 | 295 |
| Ubuntu 24.04 | CIS Level 1 Server | 105 | 7 | 408 |
| Debian 12 | ANSSI BP-028 intermediary | 84 | 10 | 225 |
On RHEL 9 the pass rate rose from 64.9 % to 98.1 % (share of rules that pass, of those that pass or fail; not-applicable rules excluded).
Measured on Haction’s own test machines (stock Google Cloud images), not on a customer estate. September 2026, reproduced on 7 October 2026 with signed release 1.0.2.
The remaining failures are rules that need a site decision (for example a bootloader password), a separate disk partition, or have no automated fix. That is normal, and Cyberiad lists them with advice.
Linux security guides in the catalogue
distinct rules across the catalogue
Haction advisories covering every rule, value and group
checks across 76 test cases matching OpenSCAP 1.4.4
Catalogue and advisory figures as of 27–28 September 2026; OpenSCAP cross-check 26 September 2026.
Inside Cyberiad


Cyberiad Advisories
Every rule, value and group in the catalogue carries curated guidance: why it matters (the threat, the MITRE ATT&CK technique, what fails without it) and how to implement it (what can break, rollout order, values to decide, one command to verify).
Writers flagged every statement they were unsure of, and checkers resolved each against primary sources such as man pages, kernel documentation, distribution sources and NVD/MITRE: 1,567 outcomes, of which 1,093 verified, 292 corrected, 167 softened and 15 removed.
AI assistant
The assistant answers questions such as “Which high-severity STIG rules have no Ansible fix?”, compares profiles and edits the tailoring on request. It does not calculate or remember numbers: it calls deterministic queries over the parsed security guides and reports their results.
Security and architecture
Cyberiad holds no credentials to your servers and never connects to them. Your servers pull the package.
A cloud KMS key (ECDSA P-256) and Sigstore keyless signing recorded in the public Rekor transparency log. Verify with cosign or openssl, without access to Cyberiad.
Append-only and hash-chained, so any later alteration is detectable. Exports to CSV and OCSF-shaped JSON Lines and streams to a SIEM through signed webhook batches.
Nobody approves their own revision, and releases are built only from approved revisions. Eight workspace roles, from owner to auditor and viewer.
Open Policy Agent checks every screen action, assistant tool and API call; denials are recorded. Sensitive actions require a fresh sign-in.
Each organisation has its own workspace, with data isolation enforced in the database itself (row-level security), not only in the application.
Sign in with Microsoft Entra ID or any OpenID Connect provider. Delivery to cloud buckets uses identity federation, with no stored keys.
More than 350 automated tests, plus 36 authorisation-policy tests covering 100 % of the policy.
Hosting and sovereignty
Cyberiad is a managed cloud service running in Google Cloud’s London region (UK). An instance in an EU region or an installation in your own infrastructure is available on request.
Coverage
Availability of each baseline differs by distribution. You can also upload your own SCAP 1.2/1.3 data streams or XCCDF 1.2 benchmarks. Standard names identify the baselines Cyberiad implements; they do not imply certification or endorsement by the bodies that publish them.
Where Cyberiad fits
Cyberiad complements the tools you already have: it uses the same OpenSCAP results and the same open remediation content.
| Category | Strong at | What Cyberiad adds |
|---|---|---|
| Compliance scanners | Assessing hosts against benchmarks | Tailoring workflow, remediation delivery and signed releases |
| Vendor compliance services | Depth for one vendor’s OS | One process for mixed estates across distributions |
| Automation content | Applying changes at scale | Approval, signing and an evidence chain |
| GRC platforms | Collecting evidence and mapping controls | Changing and verifying host configuration |
FAQ
Configuring a server to a recognised security standard, for example closing unneeded services, tightening SSH, and setting password and audit rules, so that it is harder to attack and easier to audit.
CIS Benchmarks, DISA STIG and ANSSI BP-028 are the main ones; the guides also include PCI DSS, HIPAA, NIST 800-53 High/Moderate, NIST 800-171 (CUI), BSI, CCN, Essential Eight, ISM and others. Availability depends on the distribution.
40 guides covering Red Hat Enterprise Linux 7–10, CentOS Stream, AlmaLinux, Oracle Linux, Ubuntu 18.04–24.04, Debian 10–13, SUSE Linux Enterprise 12–16, SLE Micro, openSUSE, Fedora, Amazon Linux and more. You can also upload your own SCAP content.
No. Your servers pull the signed package from your own bucket, registry or repository, verify it and apply it. Cyberiad holds no passwords or keys to them.
No. The package uses the distribution’s own OpenSCAP scanner.
Every release is signed twice (a cloud KMS key and Sigstore keyless signing in a public transparency log) and ships checksums. You can verify it with cosign or openssl without Cyberiad.
Before-and-after OpenSCAP scan reports, the approved tailoring with its reasons, the signed release that was applied, and an audit trail showing who approved and published what, and when.
The rules follow recognised public benchmarks and open SCAP content, which is why OpenSCAP and auditors’ scanners understand them. You pay for everything around the rules: tailoring and approvals, signed and versioned releases, delivery to your environment, proof, the Haction advisories, and a maintained platform that keeps up with new standard and OS versions.
Some settings can affect applications. That is why every rule has an advisory that explains what can break and how to roll it out, and why the package can first run in report-only mode. Haction recommends a test environment before production rollout.
Yes: report-only evaluation, a generated shell script or Ansible playbook to review, and an HTML guide of the selected rules.
It does not calculate or remember numbers; it calls deterministic queries over the parsed security guides and reports their results. Its actions are limited to what your role allows.
Today on Google Cloud in London (UK). An instance in an EU region or an installation in your own infrastructure is available on request.
Yes. Everything uses open formats (XCCDF, JSON, CSV, OCSF-shaped JSON, standard zip packages), and releases you received keep working and verifying without Cyberiad.
The audit trail streams to a SIEM through signed webhook batches and exports as CSV and OCSF-shaped JSON Lines. Native Splunk HEC and Microsoft Sentinel connectors are not available yet.
Microsoft Entra ID or any OpenID Connect identity provider, with roles per workspace. Sensitive actions require a fresh sign-in.
As an annual subscription per workspace, tiered by estate size, with unlimited users and all guides and advisories included. There is no per-host metering, so you can harden everything. Haction also offers pilots, tailoring workshops, exception management and audit preparation.
Book the free 30-minute demonstration on a Linux system and standard of your choice.
For advisory firms
Advisory and consulting firms can offer Cyberiad as a module of their compliance projects. Haction supplies the platform, the content and second-line support, with one workspace per client.
Next step
You pick the system and the standard; we show the whole process. Free, in our test environment, with no access to your network.
We’ve got your back.