Remote infrastructure site representing controlled Linux operations

Enterprise technical pilot

A technical pilot for regulated Linux fleets

Bring one representative workload and the boundary it must operate within. We will build, boot, test, and document the image, then report what is ready, what needs integration work, and what should not move forward.

Bootable Linux artifactValidation on a real VMCycloneDX SBOMWritten fit and gap review

A bounded evaluation, not a vague transformation project

The pilot is designed for platform, security, and operations teams evaluating a repeatable way to produce Linux images for fleets, appliances, kiosks, edge systems, or agent infrastructure.

Artifact proof

Build one representative ISO or disk image from a versioned recipe and retain the build record.

Runtime proof

Boot the produced image in a VM and exercise agreed functional or visual checks against the running system.

Evidence review

Review the CycloneDX inventory, artifact hashes, test results, and the evidence gaps your process still needs.

Scope a technical pilot

Give us the operating boundary and one representative workload. We will respond with fit, open questions, and a proposed validation plan.

Evidence and compliance needs

How the pilot runs

  1. 01

    Scope

    Agree on the workload, Linux base, deployment boundary, acceptance checks, and the people who need to review the result.

  2. 02

    Build and validate

    Create the image, boot the actual artifact, run the agreed checks, and iterate on defects that are inside the pilot scope.

  3. 03

    Decide

    Deliver the artifact and evidence with a clear fit, gap, integration, and production-readiness assessment.

Security review without certification theater

We separate product evidence from company certifications. OpenFactory does not currently claim SOC 2 Type II or ISO 27001 certification; those readiness programs are being established and their status is published plainly.

See security and assurance

Pilot questions

What should we bring?

Bring one workload, its required packages and services, target hardware or virtualization constraints, deployment boundary, and a small set of acceptance checks.

Does a pilot guarantee an air-gapped deployment?

No. Disconnected and customer-controlled deployment requirements are evaluated during scoping. The pilot documents what works now and what would require additional engineering.

What evidence is available today?

OpenFactory can provide build records, artifact identifiers and hashes, CycloneDX SBOM output, and VM test results. Required controls beyond those are identified during the review.