# A smaller kernel, not a thicker agent

> Root Lock compiles out the subsystems attackers use to bypass controls. Buyer briefs, scanner hygiene, distro fit, and measured evidence.

---

LLMS index: [llms.txt](/llms.txt)

---

**Overview**: Root Lock by HeartSuite runs custom-built Linux kernels (5.19 legacy and 6.18 primary LTS) that remove the subsystems attackers use to bypass security controls, rather than patching around them. This section covers buyer evaluation, support policy, compatibility, scanner hygiene, and reproducible evidence.

## For buyers and procurement

Start here if you are evaluating the Root Lock kernel for a regulated or enterprise fleet:

- [Procurement Brief](procurement-brief/) — Comparison table and decision guide at a glance.
- [Enterprise Adoption Guide](enterprise-adoption-guide/) — CISO and procurement guidance: deployment, fleet operations, Secure Boot status, supply chain, recovery, and honest limitations.
- [Distro Compatibility Matrix](distro-compatibility-matrix/) — Validated and supported distributions, RHEL-family guidance, workload fit, and HJFS alternative.
- [Kernel Support Policy](kernel-support-policy/) — LTS strategy, patch targets, update delivery, version-string semantics, and boundaries versus distribution-vendor maintenance models.
- [CVE Hygiene for Scanners](cve-hygiene-for-scanners/) — How enterprise Linux security teams verify CVE status without upstream version false positives.
- [Supply Chain and Advisory Feeds](supply-chain-and-advisories/) — SHA-256 today; published JSON feeds at `/advisories/` (CONFIG-gate SBOM, OSV with 279 entries, CycloneDX SBOM for `hs-v1.6.4-kernel-6.18.9`); roadmap for GPG/cosign signing and OVAL.

**Reading guide**: Several pages name Red Hat Enterprise Linux (RHEL), RHSA advisories, and OVAL feeds as **familiar anchors** for procurement and vulnerability-management teams. The same errata-first discipline applies on Rocky, AlmaLinux, Ubuntu LTS, Debian, and SUSE.

Root Lock is not a RHEL-only product. The [Distro Compatibility Matrix](distro-compatibility-matrix/) lists validated bases across RPM and Debian families.

## Evidence and technical reference

Every measured number derives from the open-source `kernel-hardening-checker` tool applied identically to HeartSuite and reference kernels. No estimates. Raw evidence files and config SHA-256 hashes are included so any qualified team can verify independently.

- [Evidence Status](evidence-status/) — 6.18.9-hs #37 pack published 2026-08-18; 5.19.6 remains the legacy pack.
- [Comparison Matrix (6.18.9)](kernel-comparison-matrix-6.18.9/) — Fielded 6.18.9-hs #37 measured scores.
- [Comparison Matrix (5.19.6)](kernel-comparison-matrix-5.19.6/) — Legacy stream, fully measured: HeartSuite vs vanilla defconfig, Arch hardened, and KSPP target.
- [Threat model and residual risk](auditor-brief/) — Fielded-pin threat model, measured scores, residual risks, and reproduction commands.
- [LSM Comparison](lsm-comparison/) — HeartSuite vs SELinux, AppArmor, and TOMOYO: enforcement model, bypass-primitive resistance, and co-existence.
- [Analyst Summary](analyst-summary/) — Non-technical summary for journalists and analysts, with fact-checker citations.

---

Section pages:

- [Kernel hardening in one comparison table](/rootlock/kernel-hardening/procurement-brief/): Side-by-side hardening of the fielded 6.18.9-hs Root Lock kernel against bundled checker references — for procurement and architecture reviews.
- [A custom kernel in a regulated fleet](/rootlock/kernel-hardening/enterprise-adoption-guide/): Why the custom kernel exists, who owns vendor risk, Secure Boot status, recovery, and when a no-custom-kernel policy should say no.
- [Which distros boot the Root Lock kernel](/rootlock/kernel-hardening/distro-compatibility-matrix/): Current lab set for Debian, Ubuntu, Rocky, and other bases — kernel line per distro, workload fit on the shipped 6.18 pin, and how to report a problem.
- [How long each Root Lock kernel is maintained](/rootlock/kernel-hardening/kernel-support-policy/): LTS streams, patch targets, 5.19 deprecation, and how Root Lock kernel maintenance differs from a distro vendor's model.
- [Your scanner flags CVEs this kernel does not have](/rootlock/kernel-hardening/cve-hygiene-for-scanners/): Custom kernels false-positive on upstream version compares. The verification workflow, status categories, and evidence auditors accept.
- [How to verify the kernel you downloaded](/rootlock/kernel-hardening/supply-chain-and-advisories/): SHA-256 bundles, published OSV and CycloneDX feeds, config hashes, and which signing steps are still on the roadmap.
- [Which kernel evidence is published today](/rootlock/kernel-hardening/evidence-status/): 6.18.9-hs #37 evidence pack is published (2026-08-18). 5.19.6 remains the legacy measured stream.
- [Hardening matrix for kernel 6.18.9](/rootlock/kernel-hardening/kernel-comparison-matrix-6.18.9/): Measured checker scores and runtime for the fielded 6.18.9-hs #37 pin, with era-matched Arch 6.18.16 and vanilla 6.18.9 defconfig.
- [Hardening scores: 5.19.6 against the field](/rootlock/kernel-hardening/kernel-comparison-matrix-5.19.6/): kernel-hardening-checker comparison of Root Lock 5.19.6 against industry hardened kernels and stock references, with reproduction commands.
- [What a red team should test on this kernel](/rootlock/kernel-hardening/auditor-brief/): Threat model, measured scores, and residual risks on the fielded 6.18.9-hs #37 pin. 5.19.6 remains the legacy pack.
- [SELinux, AppArmor, TOMOYO — a different job](/rootlock/kernel-hardening/lsm-comparison/): LSM policy can be set permissive by root. Root Lock is compiled in. When each model fits containment, and when it does not.
- [Kernel hardening in plain language](/rootlock/kernel-hardening/analyst-summary/): What Root Lock removes from the kernel, why, and how to fact-check the claims — for journalists, analysts, and non-specialists.
