Skip to content
← Back to Work
On Hold Open Beta Debian Stable KDE Plasma Rust GPLv3

A privacy-first Linux OS built for developers, designers, and systems engineers who ship.

A privacy-first, offline-first Linux operating system built on Debian Stable and KDE Plasma. Four pillars: privacy-first, security-conscious, portable-first, offline-first. Ships hardened by default: sysctl hardening and Mission OS's Rust system services are enabled automatically during install, no post-install script needed. Installer is Calamares, customized with Mission OS branding and a Python post-install module. No telemetry, ever.

GitHub repository card for p4inz-code/mission-os.
Banner art from the project README. Not a product screenshot.
Product pillars
4
Rust system services
2
Installer screens
7
Telemetry calls
0

The problem

Privacy-focused OSes look like they were built for hackers, not people.

Most privacy-oriented Linux distributions signal intent through aesthetics: dark terminals, green text, cyberpunk imagery. That's a signal to the wrong audience. It reads as "for experts only," and the UX usually lives up to it: unexplained toggles, dense options, security features you enable without understanding the trade-offs.

If you want a well-designed, modern desktop OS that also treats your privacy as the default rather than an add-on, the market is thin.

Product-grade design applied to a serious operating system.

Mission OS is designed around the principles of any modern product: clarity, consistency, careful defaults, honest explanations.

Security hardening happens automatically: sysctl hardening and Mission OS's Rust system services are enabled during install, with no manual post-install script required. A separate Mission Hub app, for reviewing and adjusting security, privacy, and storage settings after install, is in early development.

Who it's for

Three people it's built with in mind.

The developer

Wants a Linux laptop that doesn't phone home. Mission OS is Debian Stable with a real KDE Plasma (Wayland) desktop, no telemetry, and hardening applied automatically during install. There's no post-install hardening script to run.

The designer

Wants privacy without giving up a desktop that looks considered. Mission OS ships KDE Plasma with its own design language, Mission Graphite. The desktop is treated as part of the product.

The systems engineer

Wants an audit-friendly Debian base and to read the diff between vanilla Debian and Mission OS. The system services are written in Rust (mission-securityd and mission-driverd) over D-Bus. Mission OS is GPLv3, so every change is inspectable.

Four pillars

Privacy-first

Sensible defaults and honest choices: no telemetry and no mandatory data collection.

Security-conscious

Layered security in the system services: D-Bus fail-closed, PolKit authorization, systemd sandboxing, capability bounding and kernel hardening. sysctl hardening is applied automatically after install.

Portable-first

Designed to run reliably from portable storage (USB-first), while also supporting traditional installs.

Offline-first

Core functionality should keep working without a network whenever practical.

Installer experience

Calamares, customized, with hardening applied automatically.

Welcome → Locale → Keyboard → Partition → Users → Summary → Finished. Seven screens, built on Calamares (the same installer framework used by several major Linux distributions) rather than a fully bespoke installer application.

Mission OS-specific work happens after the visible flow: a post-install step applies sysctl hardening and enables Mission OS's Rust system services automatically, so there's no manual hardening script to run after first boot.

Installer — Partition screen
Concept installer prototype. A real capture isn't published yet.

Current status

Open Beta, on hold.

Mission OS shipped its Open Beta in August 2026, installable today via the Calamares-based installer above. Development is on hold while other products take priority; the separate Mission Hub app for post-install management (settings, updates, recovery, driver management, diagnostics) stayed in early implementation when work paused.