A bounded evaluation, not a vague transformation project
The pilot is designed for platform, security, and operations teams evaluating a repeatable way to produce Linux images for fleets, appliances, kiosks, edge systems, or agent infrastructure.
Artifact proof
Build one representative ISO or disk image from a versioned recipe and retain the build record.
Runtime proof
Boot the produced image in a VM and exercise agreed functional or visual checks against the running system.
Evidence review
Review the CycloneDX inventory, artifact hashes, test results, and the evidence gaps your process still needs.
How the pilot runs
- 01
Scope
Agree on the workload, Linux base, deployment boundary, acceptance checks, and the people who need to review the result.
- 02
Build and validate
Create the image, boot the actual artifact, run the agreed checks, and iterate on defects that are inside the pilot scope.
- 03
Decide
Deliver the artifact and evidence with a clear fit, gap, integration, and production-readiness assessment.
Security review without certification theater
We separate product evidence from company certifications. OpenFactory does not currently claim SOC 2 Type II or ISO 27001 certification; those readiness programs are being established and their status is published plainly.
Pilot questions
What should we bring?
Bring one workload, its required packages and services, target hardware or virtualization constraints, deployment boundary, and a small set of acceptance checks.
Does a pilot guarantee an air-gapped deployment?
No. Disconnected and customer-controlled deployment requirements are evaluated during scoping. The pilot documents what works now and what would require additional engineering.
What evidence is available today?
OpenFactory can provide build records, artifact identifiers and hashes, CycloneDX SBOM output, and VM test results. Required controls beyond those are identified during the review.
