# LinuxGuard > The control plane for Linux identity and access management — making every identity on your Linux estate (human, non-human, containerised, and agentic) known, governed, and continuously assured. LinuxGuard unifies identity security posture management (ISPM), identity threat detection and response (ITDR), and identity visibility and intelligence (IVIP) for the Linux layer beneath SIEM, EDR, and CSPM: continuous privilege, SSH-key, and non-human-identity posture scoring; ranked, severity-scored identity findings with gated response (lock an account, terminate a session, revoke sudo); and audit-ready compliance evidence across 17 compliance frameworks, including NIS2, DORA, SOC 2, CIS Benchmarks, NIST, PCI DSS, ISO 27001, HIPAA, FedRAMP, CMMC 2.0, DISA STIG, BSI IT-Grundschutz, the EU AI Act, SOX ITGC, the NCSC CAF, 21 CFR Part 11, and EU GMP Annex 11. Linux-native — built for the identity artefacts on each host (sudo rules, SSH keys, PAM chains, service accounts), not adapted from Windows-first or cloud-first tools. Certified with Red Hat and SUSE, validated on Ubuntu. UK-based, NIS2-ready. ## Product & Platform - [LinuxGuard Platform](https://linuxguard.io): The control plane for Linux identity — know who and what can do what across your Linux estate, continuously - [Features](https://linuxguard.io/features): The Linux Identity Control Plane where ISPM, ITDR, and IVIP meet — identity intelligence, risk scoring, SSH & non-human-identity posture, file security, findings, automated response, compliance, and CVE context - [Security & Compliance](https://linuxguard.io/security-compliance): Identity-first security and compliance for Linux — complete identity visibility, privilege monitoring, least-privilege enforcement, real-time drift detection, and audit-ready zero-trust evidence - [Pricing](https://linuxguard.io/pricing): Fixed-fee Founding Pilot (€24,000) plus continuous per-server monitoring billed annually — Starter (up to 100 servers), Midsize (up to 1,000 servers), and Enterprise (unlimited, custom integrations; SSO/SAML on the roadmap) - [Customer Dashboard](https://console.linuxguard.io): Multi-tenant SaaS console for security, IAM, and platform teams - [Documentation](https://docs.linuxguard.io/): Technical docs, integration guides, and agent deployment ## Pilot & Assessment - [Founding Pilot](https://linuxguard.io/pilot): 60-day managed pilot (open to 10 founding organisations, €24,000 fixed fee) that maps every account and privilege path across your Linux estate, risk-scores the findings, and delivers compliance evidence plus a remediation roadmap — white-glove and fully remote - [Linux Identity Maturity Assessment](https://linuxguard.io/maturity-assessment): Free, ungated, anonymous self-scoring tool — 20 questions across 5 domains (identity inventory, privilege control, access governance, service accounts & NHI, compliance & audit readiness), 5–8 minutes, returns a maturity level (1–4) with prioritised gaps ## Solutions - [DORA Linux Identity Pilot](https://linuxguard.io/solutions/linux-identity-audit-dora): Pilot mapped to DORA (Digital Operational Resilience Act) Article 8 ICT asset and access identification — identifies Linux identity and access gaps and delivers the evidence regulators require - [NIS2 Linux Identity Pilot](https://linuxguard.io/solutions/linux-identity-audit-nis2): Pilot mapped to NIS2 Article 21 identity and access controls — maps every privilege path across your Linux servers and delivers compliance evidence ahead of regulatory review - [Why LinuxGuard](https://linuxguard.io/why-linuxguard): Why SIEM, EDR, and cloud tools miss Linux identity — and how LinuxGuard covers the host-level layer they don't ## Case Studies - [Global Payments Firm — Linux Identity Audit](https://linuxguard.io/case-studies/linux-identity-audit-global-payments): How a European financial services firm cut Linux audit prep from weeks to a single export — 412 servers mapped ahead of a DORA deadline; findings included 247 orphaned accounts with active sudo and 183 unowned service accounts ## Company & Resources - [About LinuxGuard](https://linuxguard.io/about): UK-based Linux identity security company founded by Peter Cummings (Founder & CTO, 20+ years IAM experience at Mastercard, EY, Lonza, UBS) and John Skitt (Co-Founder & CEO); built by practitioners from Mastercard, UBS, EY, and the UK Government - [Partner Programme](https://linuxguard.io/partners): For technology partners, MSPs, MSSPs, and advisory and integration partners — what each can deliver to its own clients with LinuxGuard's visibility into Linux identity, including a partner view across client estates and delegated access - [Blog](https://linuxguard.io/blog): Ghost CMS blog covering Linux identity security, privilege and SSH-key governance, non-human identity, zero trust, and NIS2/DORA compliance - [Contact](https://linuxguard.io/contact): Book a demo, request a pilot, or reach the team — support@linuxguard.io ## Legal - [Privacy Policy](https://linuxguard.io/legal/privacy): UK GDPR-compliant privacy policy, data processing, and customer data handling - [Terms of Service](https://linuxguard.io/legal/terms): SaaS platform terms and acceptable use - [Data Processing Addendum](https://linuxguard.io/legal/dpa): DPA for customer data processing - [Software License Agreement](https://linuxguard.io/legal/license): Platform licence terms ## Platform Capabilities ### Identity Intelligence (IVIP) - Live map of every identity — human, non-human, service, and containerised — with relationships, privilege paths, and configuration across the estate - Privilege exposure mapping: see exactly which identities can escalate to root on every server - Dormant and at-risk account surfacing before attackers find them - Per-identity timelines: reconstruct logins, sudo commands, and config changes for any identity ### Identity Security Posture Management (ISPM) - Continuous posture scoring across human accounts, service identities, SSH keys, sudo policies, and PAM configs — 22 weighted risk signals, continuously updated - Per-account composite risk scores (0–100) with inline explanation of the factors driving each score - Fleet-wide risk ranking, filterable by server group, team, or environment ### SSH Keys & Non-Human Identity - Continuous inventory of every authorised SSH key — age, algorithm, reuse, and ownership - Key hygiene grading: flag weak algorithms, aged keys, and keys shared across accounts or servers - Non-human identity classification and ownership mapping to team, purpose, and credential age ### Identity Threat Detection & Response (ITDR) - Ranked, severity-scored findings attributed to the identity behind each change, built for the Linux threat surface - Real-time drift detection for new accounts, changed permissions, and SSH-key additions - Gated containment: lock an account, terminate a session, revoke sudo, or disable an SSH key — behind mandatory approval, with automatic rollback - Remediation actions are defined by Ed25519-signed descriptors, and remediation scripts are checked at the abstract-syntax-tree level before they are allowed to run ### File Security - Track access to and changes on sensitive files, attributed to the specific identity responsible - Detect personal data and secrets in matched file content — scanning runs on your own server and file content never leaves it ### Compliance & Audit - Continuous, audit-ready compliance evidence mapped to framework controls from actual Linux configuration - Frameworks: 17 compliance frameworks, including NIS2, DORA, SOC 2, CIS Benchmarks, NIST, PCI DSS, ISO 27001, HIPAA, FedRAMP, CMMC 2.0, DISA STIG, BSI IT-Grundschutz, the EU AI Act, SOX ITGC, the NCSC CAF, 21 CFR Part 11, and EU GMP Annex 11 - CVE context tied to affected hosts and identities ## Data Collection - Lightweight agent providing deep, Linux-native visibility - Maps privilege paths from the filesystem, audit logs, and PAM configuration on each host - Read-only, non-invasive collection - Packaged for Debian, RPM, and Alpine hosts; built for amd64, arm64, armhf, and riscv64; runs under systemd, OpenRC, runit, or s6 ## Certifications - Red Hat Certified Technology (Red Hat Enterprise Linux, CentOS Stream, Fedora) - SUSE Ready (SUSE Linux Enterprise) - Validated on Ubuntu (Canonical Software Partner Programme) - Debian: tested ## Key Differentiators - Linux-native: purpose-built for the host-level identity layer, not adapted from Windows-first or cloud-first tools - Covers what SIEM, EDR, and CSPM miss: sudo rules, SSH keys, PAM chains, and orphaned service accounts - ISPM + ITDR + IVIP converged for Linux in a single platform (the IVIP intelligence layer is Gartner-recognised) - Deep, Linux-native visibility from a lightweight agent - Personal-data and secret detection runs on the customer's own Linux hosts — file content never leaves their servers - Audit-ready evidence designed for NIS2 and DORA - UK-based, GDPR-first architecture - Built by practitioners with 20+ years inside Mastercard, UBS, EY, and the UK Government - Honest reporting: where a signal has not been collected the console says so, rather than rendering an unmeasured value as a zero or an all-clear ## Use Cases ### Linux Identity Governance - Complete inventory of users, groups, sudo rules, SSH keys, PAM configs, and service accounts - Detect non-human identity sprawl and unowned service accounts - Privileged access reviews with context for who can do what on each server ### Privilege & Zero Trust - Detect privilege drift and forgotten NOPASSWD sudo rules that create escalation paths - Enforce least privilege with continuous monitoring and real-time alerting - Shrink blast radius by cutting hidden privilege paths before they are exploited ### Compliance Readiness - NIS2 (Article 21) and DORA (Article 8) evidence for European mid-market and financial-sector organisations - SOC 2, CIS Benchmarks, NIST, PCI DSS, ISO 27001, HIPAA, FedRAMP, CMMC 2.0, DISA STIG, BSI IT-Grundschutz, EU AI Act, SOX ITGC, NCSC CAF, 21 CFR Part 11, and EU GMP Annex 11 access-control and audit-trail evidence - Board-ready compliance packs generated from actual Linux configuration ### Identity Threat Detection & Response - Findings ranked by severity for privilege escalation and lateral movement - Continuous detection of configuration and privilege changes on critical systems - Gated response: lock an account, terminate a session, revoke sudo ## Target Audience - Security, IAM, and Linux infrastructure teams — CISOs, IT directors, DevOps/SRE, and platform engineers - European mid-market enterprises under the NIS2 Directive - Financial services and regulated industries under DORA, SOC 2, and PCI DSS - Organisations running production Linux estates (typically 50+ servers) that need identity and compliance evidence ## Integrations - Outbound findings and identity events via webhooks, syslog, and Splunk HEC - REST API giving IGA and SIEM platforms a scoped view of the Linux identity estate - Ticketing and collaboration: auto-create Jira tickets; send alerts to Slack and Microsoft Teams - Enterprise tier: custom integrations and data pipelines; SSO/SAML on the roadmap