AI bunker has won the 2025 Embedded Awards!

Protect data and OT operations even when primary Linux is compromised

Bunker for Linux offers dual-partition run-time environment composed of:

Open World, a traditional Linux system that can be externally exposed (e.g., network connectivity)
Bunker, a strongly isolated, security-hardened Linux execution environment

Core Features

Pre-installed and pre-configured security hardening, including encrypted filesystem, attack detection and recovery, and countermeasures for side-channel attacks
Seamless communication mechanisms between Open World and Bunker that preserve security
Secure update procedures and built-in support for containerization (e.g., Docker)
Three security profiles to balance security with performance: hard, vigorous, and extreme

The Architecture

Key features

Secure Linux Application in Isolated Partitions: Partitioning between Open World and Bunker employs next-generation Hypervisor technology
Pay Security-Related Overheads only When Needed: Involve resource-expensive security countermeasures for critical component only (i.e., within Bunker), while keeping the performance of non-critical software unaffected
Confidentiality, Integrity & Availability (CIA) Enforcement: Ensures only authorized applications can access sensitive data and prevents tampering
Zero-Trust approach: Even if Open World is breached, Bunker for Linux prevents lateral movement or access to protected applications running within Bunker

Ecosystem

Chip Vendors: NXP, AMD, ST, Altera
Architecture: Armv8/9-A

Download the product description

FAQ

What is Bunker for Linux?

Bunker for Linux is a ready-to-use security solution composed of a set of embedded software components developed to harden Linux-based systems and improve runtime protection against modern and ever-evolving cyber threats.

It helps organizations increase resilience while preserving system stability and operational performance.

Bunker for Linux is designed to provide advanced protection while minimizing performance impact, achieving a better overall performance of the device with respect to the traditional solutions that apply security mechanisms to the entire application. Bunker for Linux allows you to pay security-related overhead only when needed, leaving the non-critical part to perform at high performance.