In development — v0.1 coming soon

One command.
Full environment.

NixOS · Hyprland · Security-first · Reproducible

Sigilos is a security and privacy-focused Linux distribution built on NixOS with Hyprland. No bloat. No desktop environment overhead. A curated professional environment — declared once, reproduced anywhere, deployed in minutes.

Join the Waitlist Learn More
NixOS Hyprland Wayland-native Reproducible Security-first Nix Flakes USB Portable Zero Telemetry LUKS2 Encryption DNS-over-TLS MAC Randomization NixOS Hyprland Wayland-native Reproducible Security-first Nix Flakes USB Portable Zero Telemetry LUKS2 Encryption DNS-over-TLS MAC Randomization
0 Telemetry calls
1 Command to deploy
Reproducible installs
sigilos@live — zsh
sigilos ~ sigilos-install --mode usb --profile security
→ Scanning target device...
✓ Device detected: /dev/sdb (64G)
→ Partitioning with GPT + LUKS2...
✓ Encrypted partition created
→ Deploying NixOS configuration...
✓ Base system: nixos-unstable
✓ Window manager: Hyprland
✓ Security tools: loaded
✓ Dev environment: loaded
→ Finalizing...
✓ Sigilos ready. Boot from USB or install to disk.
sigilos ~

Built different.
By design.

Every decision in Sigilos exists for a reason. No defaults kept for legacy reasons. No packages included for convenience.

01
NixOS foundation

Fully declarative configuration. Every package, every service, every setting defined in code. Reproduce your exact environment on any machine, any time.

02
Hyprland — no desktop

A tiling Wayland compositor replaces GNOME, KDE, and XFCE entirely. Faster, lighter, and fully keyboard-driven. Your screen space belongs to your work.

03
Security tooling

A curated set of security and penetration testing tools pre-configured and ready to use. Enumeration, exploitation, forensics, and analysis — all available out of the box.

04
USB portable

Run a full Sigilos environment from a USB drive. No installation required. Persistent storage optional. Leave no trace.

05
Quick installer

No NixOS knowledge required to get started. A single command deploys a fully configured system. Profiles for security, development, or both.

06
Privacy by default

No telemetry. MAC address randomization. DNS-over-TLS out of the box. Default-deny firewall. Full disk encryption on install. AppArmor profiles for sensitive tools.

Why not just use
Parrot or Kali?

Both are excellent tools. Sigilos is built for professionals who want reproducibility, minimalism, and a modern Wayland workflow alongside security tooling.

Feature Sigilos Parrot Kali
Declarative config
Reproducible builds
Wayland-native
Tiling WM
Security toolset
USB live mode
Rolling updates

Under the hood.

Base
NixOS unstable
Window Manager
Hyprland (Wayland)
Display Server
Wayland native
Shell
Zsh + custom prompt
Config format
Nix flakes
Package manager
Nix + home-manager
Encryption
LUKS2 on install
DNS
DoT by default
Inspired by
Parrot OS · Kali · Tails

Your environment.
Already built.

Sigilos is in active development. Join the waitlist to get notified when v0.1 drops and be among the first to test it.