Gapfruit OS

Deployed for OEMs building devices where trust
must be proven, not assumed.
For regulated industrial, energy, and communication environments where device authenticity, integrity, and resilience are required throughout long operational lifecycles.
What makes Gapfruit OS different
The Seven Properties of Highly Secure Devices define the architectural conditions required for trustworthy, attack-resilient systems. Gapfruit OS implements these properties natively and extends them to long-lived, safety- and security-critical deployments.
Gapfruit OS anchors device identity and measurements in TPM-backed hardware, enabling cryptographic proof of device origin and state from manufacturing onward.
Only the microkernel and minimal runtime components are trusted; device drivers, file systems, and network stacks run outside the TCB.
Multiple independent mechanisms prevent escalation even when individual layers fail.
Each component runs in isolated sandboxed compartments with least privilege and minimal access to resources.
Device identity is established using TPM attestation and PKI-backed certificates (Birth Certificates, update signatures, service identities).
Gapfruit enables secure lifecycle evolution through transactional, signed, and reversible updates.
Runtime faults are reported, recoverable, and traceable without halting critical system functio
NOPWhy Gapfruit OS exists
long-lived, trustworthy devices.
Gapfruit OS exists because trustworthiness cannot be retrofitted into systems that were never designed for it.
Core principles
Each component executes inside a microkernel-enforced sandbox with least-privilege capabilities. There is no ambient authority; all access must be explicitly granted. Isolation is bidirectional:
influence the internal state
Gapfruit OS governs system relationships at three levels to maintain predictable behavior and verifiable integrity across the entire lifecycle.
How Gapfruit OS enforces trustworthiness in the field


The system monitors component behavior and restores function deterministically:


Gapfruit OS incorporates Linux drivers through the Device Driver Environment (DDE):
.avif)
Gapfruit OS devices operate as fully defined, cryptographically versioned digital twins: