# LinuxGuard > LinuxGuard is a Linux-native, identity-first security platform — the control plane for Linux identity and access management. It makes every identity on a Linux estate (human, non-human, containerised, and agentic) known, governed, and continuously assured, unifying identity security posture management (ISPM), identity threat detection and response (ITDR), and identity visibility and intelligence (IVIP). Delivered as a SaaS platform and a managed Founding Pilot. UK-based, NIS2-ready, and built by practitioners with decades of Linux IAM experience. ## About LinuxGuard LinuxGuard addresses a gap that generalist security platforms consistently miss: the Linux identity layer. Most enterprise security tools were built for endpoints, directories, and the cloud, and adapted for Linux afterwards — they watch network traffic, endpoint processes, and cloud configuration, but not the identity artefacts on the Linux host itself. NOPASSWD sudo rules, shared and stale SSH keys, orphaned service accounts, PAM configuration drift, and excessive group memberships accumulate silently in Linux estates and create the lateral-movement paths and privilege-escalation routes that account for the majority of serious breaches. The industry data is stark: the majority of modern enterprise attacks use no malware — attackers simply log in with valid credentials that should have been revoked. Closing this gap requires identity-first security: continuous visibility into who — and what — can do what, enforced as a zero-trust principle across every Linux server. LinuxGuard was built specifically to make this invisible layer visible. The platform maps every user, group, sudo rule, SSH key, PAM configuration, and service account across a Linux estate using a lightweight agent that reads from the filesystem, audit logs, and PAM configuration on each host. The result is a continuously updated inventory of the Linux identity surface — an identity graph that makes privilege relationships explicit instead of implicit, updated as configurations change. LinuxGuard is the first Linux-native IVIP (identity visibility and intelligence platform), and it converges three needs into one control plane: identity security posture management (continuous scoring of accounts, SSH keys, sudo policies, and PAM configs), identity threat detection and response (ranked, severity-scored findings with gated containment), and identity visibility and intelligence (a live map of every identity, relationship, and privilege path that feeds the broader IAM stack). On top of that graph, it produces auditor-ready compliance evidence for 17 compliance frameworks — NIS2, DORA, SOC 2, CIS Benchmarks, NIST, PCI DSS, ISO 27001, HIPAA, FedRAMP, CMMC 2.0, DISA STIG, BSI IT-Grundschutz, the EU AI Act, SOX ITGC, the NCSC CAF, 21 CFR Part 11 and EU GMP Annex 11 among them — from actual Linux configuration. LinuxGuard is designed for security, IAM, and Linux infrastructure teams — particularly European mid-market organisations and regulated financial-sector firms operating 50 or more Linux servers under increasing NIS2 and DORA pressure, without the internal Linux security expertise to address it systematically. ## Company LinuxGuard Ltd was incorporated on 14 July 2025 and the platform launched in September 2025 as the first Linux-native IVIP platform. In Q1 2026 LinuxGuard achieved Red Hat, SUSE, and Ubuntu certifications. It is a UK-registered company; the platform and services are UK GDPR-compliant, with data-residency options for UK and EU regulated industries. ## Founder & Team **Peter Cummings — Founder & CTO** Peter Cummings has spent more than two decades fixing unmanaged Linux identity and privilege inside global enterprises — the person organisations call when thousands of Linux servers underpin core services but no one can clearly answer "who can do what, where, and why?" He started his career compiling open-source stacks on early Linux web servers, then moved from building systems to securing them, leading identity, access, and infrastructure security programmes for highly regulated organisations across banking, payments, life sciences, energy, and government. His most formative work came at Mastercard, where he redesigned Linux authentication and authorisation for a global payments infrastructure, and at Lonza, where he rebuilt a fragmented IAM function into a modern, automated, audit-ready platform. Similar engagements at UBS, EY, ING, SEB, BEC, and within the UK Government gave him a repeatable playbook for making Linux identity both visible and governable without slowing the business down. LinuxGuard is the productised version of that playbook — a lightweight agent, an opinionated "Zero Trust for Linux" model, and an identity-graph engine that makes privilege relationships explicit. **John Skitt — Co-Founder & CEO** John Skitt leads go-to-market strategy, sales operations, and partnership development at LinuxGuard. With over 12 years in B2B SaaS across North America and Europe, he specialises in taking technical security products into regulated industries — financial services, critical infrastructure, and the public sector. He focuses on making the case for Linux identity security simple, credible, and actionable for the buying committee, from CISO to compliance lead. ## Founding Pilot The flagship LinuxGuard engagement is the Founding Pilot: a 60-day, fixed-scope, fixed-fee managed engagement (EUR 24,000) that turns a Linux identity blind spot into a documented, evidence-backed baseline. It is open to 10 founding organisations, each of whom receives white-glove service and a direct hand on the roadmap at the same fixed fee. **What the pilot covers:** The engagement maps every identity artefact across the client's Linux estate — every user account (active and orphaned), every group membership, every sudo rule (including NOPASSWD rules, wildcard entries, and rules unreviewed for years), every SSH key (including shared keys granting access to multiple servers), every service account and its permissions, and every PAM configuration that could enable privilege escalation. It is conducted remotely using read-only data collection that does not modify any system or disrupt any workload. A senior LinuxGuard engineer is dedicated to the pilot from kickoff to handover — including migration off existing tooling, wiring into what the client already runs, and working with their auditors — available on demand and hands-on remotely, never on-site. **The deliverables:** 1. **Privilege map** — A complete inventory of every identity and privilege path across the Linux estate, showing who can reach what and by which route. This becomes the baseline for ongoing monitoring. 2. **Risk-ranked findings report** — A prioritised list of privilege risks ordered by exploitability and blast radius. 3. **Compliance evidence pack** — Evidence of where the Linux identity configuration meets and where it falls short of the relevant regulatory requirements (NIS2, DORA, SOC 2, CIS, NIST), formatted for auditor review. 4. **Least-privilege remediation roadmap** — A phased plan with specific actions per finding, prioritised to close the highest-risk gaps first, that the client's engineering team can act on immediately. **Who it is for:** Security, IAM, and Linux infrastructure leaders at European mid-market organisations (typically 50 or more Linux servers) under NIS2 or DORA pressure who need demonstrable identity controls and audit evidence within a defined timeframe — and any organisation preparing for SOC 2 Type II or CIS assessment where Linux identity controls are a known gap. **Timeline:** 60 calendar days from kickoff to final report, conducted entirely remotely, with no disruption to production systems. Organisations unsure of where they stand can start with the free, ungated, anonymous **Linux Identity Maturity Assessment** (linuxguard.io/maturity-assessment) — 20 questions across five domains, returning a maturity level (1–4) with prioritised gaps in 5–8 minutes. ## Platform Capabilities The LinuxGuard SaaS platform provides continuous versions of the visibility the Founding Pilot delivers as a point-in-time baseline. **Identity Intelligence (IVIP):** A live map of every identity — human, non-human, service, and containerised — with relationships, privilege paths, and configuration across the estate. Privilege exposure mapping shows exactly which identities can escalate to root on every server; dormant and at-risk accounts are surfaced before attackers find them; and per-identity timelines reconstruct logins, sudo commands, and config changes. **Identity Security Posture Management (ISPM):** Continuous posture scoring across human accounts, service identities, SSH keys, sudo policies, and PAM configs — 22 weighted risk signals, continuously updated. Every account carries a composite risk score (0–100) with an inline explanation of the factors driving it, and the whole fleet can be ranked by risk and filtered by server group, team, or environment. **SSH Keys & Non-Human Identity:** Continuous inventory of every authorised SSH key — age, algorithm, reuse, and ownership — with hygiene grading that flags weak algorithms, aged keys, and keys shared across accounts or servers. Non-human identities are classified and mapped to an owning team, purpose, and credential age. **Identity Threat Detection & Response (ITDR):** Ranked, severity-scored findings attributed to the identity behind each change, built for the Linux threat surface. Real-time drift detection flags new accounts, changed permissions, and SSH-key additions, with gated containment — lock an account, terminate a session, revoke sudo, or disable an SSH key — behind mandatory approval, with quarantine and automatic rollback, and every action recorded in a chain-hashed, tamper-evident audit log. Remediation actions are defined by Ed25519-signed descriptors, and remediation scripts are checked at the abstract-syntax-tree level — parsed and analysed rather than matched against a list of banned strings — before they are allowed to run. **File Security:** Track access to and changes on sensitive files, attributed to the specific identity responsible. Detectors flag personal data and secrets in matched file content, running on the customer's own host — file content never leaves their servers. **Compliance & Audit:** Continuous, audit-ready compliance evidence mapped to framework controls from actual Linux configuration, with CVE context tied to affected hosts and identities. **Data collection:** A lightweight agent with deep, Linux-native visibility. Collection is read-only and non-invasive, mapping privilege paths from the filesystem, audit logs, and PAM configuration on each host. The agent is packaged for Debian, RPM, and Alpine hosts, built for amd64, arm64, armhf, and riscv64, and runs under systemd, OpenRC, runit, or s6, so Alpine containers, ARM edge devices, and non-systemd hosts are covered rather than excepted. **Honest reporting:** Where a signal has not been collected — a host that has not reported, a check that has not run — the console shows that it has not been collected rather than rendering it as a zero. An unmeasured value is never presented as an all-clear. ## Compliance Frameworks LinuxGuard ships 17 compliance frameworks, each scored continuously from the actual Linux identity and access configuration on the estate rather than from a questionnaire. All seventeen are described below, including the four that sector regulation drives — SOX ITGC, the NCSC CAF, 21 CFR Part 11 and EU GMP Annex 11. **NIS2 Directive:** LinuxGuard addresses NIS2 Article 21 requirements for identity governance, access-control measures, and incident detection and response. The Founding Pilot produces the identity inventory and gap analysis NIS2-regulated organisations need to demonstrate to national authorities. Non-compliance penalties reach EUR 10M or 2% of global turnover. **DORA (Digital Operational Resilience Act):** LinuxGuard supports the DORA Article 8 requirement to identify and document ICT assets and the accounts that hold privilege on them — mandatory since January 2025 with no transition period — particularly for financial-sector organisations running Linux-based trading systems, core banking, and payment-processing infrastructure. **SOC 2 Type II:** Access-control evidence and audit-trail documentation applicable to SOC 2 CC6 (Logical and Physical Access Controls) and CC7 (System Operations). **CIS Benchmarks:** Automated assessment against CIS Linux hardening controls with remediation guidance mapped to each recommendation. **NIST:** Control mapping for federal contractors and regulated industries, covering AC (Access Control), AU (Audit and Accountability), and IA (Identification and Authentication) control families. **ISO 27001:** Evidence collection for A.9 (Access Control), A.12 (Operations Security), and A.16 (Information Security Incident Management) Annex A controls. **PCI DSS 4.0:** Privileged-account monitoring and access logging for Linux systems in cardholder-data environments, aligned to Requirements 7, 8, and 10. **HIPAA:** Access-control and audit-trail coverage for Linux systems that handle protected health information, evidenced from the accounts, sudo rules, and SSH keys that can reach them. **FedRAMP:** Access-control and audit evidence for Linux systems in scope for a FedRAMP authorisation, scored from actual host configuration rather than a point-in-time questionnaire. **CMMC 2.0:** Access-control and audit practice evidence for defence-industrial-base contractors running Linux, produced from the same identity inventory. **DISA STIG:** Deviation detection against DISA STIG hardening baselines for Linux — kernel parameters, systemd units, PAM configuration, and audit profiles. **BSI IT-Grundschutz:** Identity and access evidence for German public-sector bodies and operators working to the BSI IT-Grundschutz modules. **EU AI Act:** Access-control and traceability evidence for the Linux infrastructure AI systems are built and served on — who and what can reach it, and what changed. **SOX ITGC:** Privileged-access review and segregation-of-duties evidence over the Linux hosts behind financial reporting, drawn from the same continuously updated inventory rather than a separate manual pull at testing time. **NCSC CAF:** Evidence for Principle B2 outcomes — verification, authentication, authorisation, least privilege and review — on the Linux hosts behind an essential function, produced from the same findings as the NIS2 Article 21 evidence. **21 CFR Part 11:** Access-control, audit-trail and authority-check evidence for §11.10(d), (e) and (g) on GxP Linux hosts, with privileged actions attributed to the named person behind a shared admin login. **EU GMP Annex 11:** Access-control and attribution evidence for the security expectations Annex 11 sets over computerised systems, drawn from the accounts, sudo rules and SSH keys on the Linux hosts underneath them. ## Certifications - Red Hat Certified Technology — Red Hat Enterprise Linux, CentOS Stream, Fedora - SUSE Ready — SUSE Linux Enterprise - Validated on Ubuntu — under Canonical's Software Partner Programme - Debian — tested ## Integrations - Outbound findings and identity events via webhooks, syslog, and Splunk HEC - REST API giving IGA and SIEM platforms a scoped view of the Linux identity estate - Ticketing and collaboration: auto-create Jira tickets; send alerts to Slack and Microsoft Teams - Enterprise tier: custom integrations and data pipelines; SSO/SAML on the roadmap ## Partner Programme https://linuxguard.io/partners — for organisations that serve their own clients with LinuxGuard. - Technology partners: the OS-level identity state of a client's Linux estate — identity-attributed findings, per-account risk scores and human and non-human identity data — delivered into the partner's platform over the REST API and outbound webhooks - Managed service providers (MSPs): a continuous identity and privilege inventory and exportable compliance evidence for each client estate, with a partner view across client estates and delegated access to operate on a client's behalf - Managed security service providers (MSSPs): identity-attributed findings into the SOC's existing SIEM, and gated containment (lock account, terminate session, revoke sudo, disable SSH key) behind mandatory approval with automatic rollback and a tamper-evident audit trail - Advisory and integration partners: host-level insight and evidence for any client — who holds privileged access, server by server — and, for regulated clients, evidence mapped to framework controls so the regulatory process runs more smoothly - Partners receive a not-for-resale licence for their own estate, subject to LinuxGuard's fair use policy - Each client's data is held in its own tenant; scanning runs on the client's own hosts and file content never leaves them ## Pricing **Founding Pilot** — EUR 24,000, fixed scope, fixed fee, 60-day managed engagement, open to 10 founding organisations. **Continuous platform** — Per-server Linux identity monitoring billed annually: - Starter — from EUR 200 / server / year, up to 100 servers (continuous identity & privilege monitoring, per-account risk scoring, compliance evidence exports, standard support) - Midsize — from EUR 75 / server / year, up to 1,000 servers (everything in Starter plus fleet-wide visibility, custom monitor-to-enforce policies, priority support) - Enterprise — custom, unlimited servers (everything in Midsize plus dedicated CSM & SLA, custom integrations & data pipelines; SSO/SAML on the roadmap) Current pricing is always available at linuxguard.io/pricing. ## Contact - Website: linuxguard.io - Contact / book a demo: linuxguard.io/contact - Pricing: linuxguard.io/pricing - Email: support@linuxguard.io ## Legal LinuxGuard is a UK-registered company. The platform and services are UK GDPR-compliant, with data-residency options for UK and EU regulated industries. - Privacy Policy: linuxguard.io/legal/privacy - Terms of Service: linuxguard.io/legal/terms - Data Processing Addendum: linuxguard.io/legal/dpa - Software License Agreement: linuxguard.io/legal/license