TempestOS

The Operating System for Autonomous Machines

Today's defense platforms are running on general purpose operating systems that were never meant for the job. TempestOS is purpose-built for autonomous systems and the people deploying them.

tempestos@usv-hull-7 ~ boot

TempestOS // Maritime Autonomous Systems Kernel

[OK] Hardware abstraction layer...

[OK] Zero-trust security modules...

[OK] Container orchestration: READY

[OK] STIG compliance: 92%

[OK] SELinux mode: ENFORCING

SYSTEM READY. MISSION PARAMETERS LOADED._

MOSA COMPLIANT·ZERO-TRUST·DDIL-CAPABLE
INITIALIZING ISR SEQUENCE

The Problem

The Integration Crisis Keeping Billions on the Sidelines

The Department of War has invested billions in autonomous capabilities, sensors, AI models, and platforms. But most never reach operational deployment. The bottleneck isn't innovation, it's integration.

Today's autonomous systems are trapped in stovepipes. Each payload requires custom integration with each platform. Vendor lock-in prevents mix-and-match capabilities. And when requirements change, the integration process starts over. Meanwhile, the threat environment moves faster than acquisition timelines can answer. This isn't a hardware problem, it's a software infrastructure problem.

The Old Way: Custom Integration

0:1

Every payload requires custom platform integration

0-24 mo

For a single security authorization

$0M+

In compliance costs per system

Dozens

of capabilities stuck in integration backlog

The TempestOS Way: Integrate Once, Deploy Everywhere

0 : Many

Zero vendor lock-in. Integrate once with TempestOS and access our entire payloads ecosystem.

Days

not years, from payload submission to deployment

0%

STIG-compliant out of the box, zero cyber retrofit

0

Integration covers every platform in the fleet

The Solution

The integration layer bridging the gap between platform builders and payload providers

PLATFORM BUILDERS

Platforms supported by TempestOS

SMALL AUTONOMOUS VEHICLE
MEDIUM AUTONOMOUS VEHICLE
LARGE AUTONOMOUS VEHICLE
TempestOS

TempestOS

INTEGRATION LAYER

PAYLOAD PROVIDERS

All payloads run on every supported platform

ISR
Autonomy Models
Electronic Warfare
Navigation
Sensors
Communications
Command & Control
Effectors

THE SOLUTION

Cybersecure by Design

TempestOS treats cybersecurity as a property of the system itself. The hardening is built in when the operating system is built, so the platform ships secure. Read the whitepaper

Kernel Debloating

Each build includes only the packages and kernel modules its mission requires. Vulnerabilities in components a platform never needs simply do not apply, because that code is absent from the image entirely.

SELinux Enforcement

Mandatory access control defines which system components may interact. A compromised module is confined to what it was already authorized to do, so an attacker cannot pivot across subsystems or escalate through lateral movement.

Software Structure Randomization

Per-build randomization varies the internal layout of each deployed image. An exploit written against one vehicle does not carry to the next, so the cost of attacking a fleet scales with its size.

Cryptographic Fingerprinting

Every TempestOS build carries a cryptographic signature tied to its exact contents. Before an image boots, that signature is verified, so the platform runs only the authentic, approved build and nothing altered between delivery and deployment. Tampering breaks the signature and is caught.

Zero-Trust Architecture

TempestOS is built on a zero-trust model: no component, process, or payload is trusted by default. Access between system elements is governed by explicit policy rather than assumed by location or prior authorization, so every interaction must be verified against what the architecture permits.

Built Through a Secure Pipeline

TempestOS images are produced through a reproducible, fully visible build pipeline rather than assembled in isolation. Each build is signed and passes through automated code and vulnerability scanning, so security is enforced at the moment the image is created, not bolted on afterward.

The Approach in Practice

Most systems stay secure by racing to fix vulnerabilities after they are found. Every new vulnerability starts a scramble to patch it before someone can take advantage. TempestOS is built to make most of that scramble unnecessary.

Over two years, we looked back at the vulnerabilities discovered in the kind of system TempestOS is built on. In seven out of ten cases, TempestOS would have been left unaffected.

The Services Suite

The TEMPESTOS services suite

Tempest Messaging Service (TMS)

The Integration Layer. TMS provides the hub and spoke architecture that enables interoperability between data formats and message protocols. MOSA, industry standards, and proprietary interfaces are translated once into Riptide (Caliburn's common protocol) and served back out to consumers in their native format.

Drawbridge

Communications-as-a-Service (CaaS). Drawbridge manages the available radios and links with operator defined information priorities to keep mission critical information flowing. As comms become limited Drawbridge provides graceful degradation and alleviates the cognitive load of tracking which links are available.

Policy Engine

Autonomy and Data Governance. A single service providing human readable and defined system constraints. Operators can configure limits, priorities, and interactions between software on the platform. Dynamic adjustments to meet mission demands, trusted behaviors when comms are down.

Avalon Connector Service (ACS)

Robotic Secure Login. When vehicles reconnect after days or weeks of DDIL operations, ACS ensures they are safe to rejoin the network. Providing both robotic identity and software anti-tamper validation, ACS ensures the vehicle will deliver its mission data and protects against malicious actors trying to turn vehicles into cyber attack vectors.

Isometric TempestOS stack diagramThree isometric slabs stacked: an applications layer on top, a highlighted lime TempestOS layer in the middle, and a third-party hardware layer at the bottom.THIRD-PARTY HARDWARETEMPESTOSAPPLICATIONS

SYSTEM ARCHITECTURE

A PURPOSE-BUILT STACK FOR AUTONOMOUS PLATFORMS

By Design

Built for the Conditions of Autonomous Machines

DDIL-Capable

Operates in Denied, Degraded, Intermittent, Limited connectivity. Edge-first, not cloud-dependent.

Open Architecture

Built to open standards so capabilities integrate without proprietary lock-in. MOSA-aligned and modular, so platforms stay adaptable as missions and payloads change.

Platform-Agnostic

Deploy on USVs, UUVs, and UAVs. One integration works across your entire fleet. No vendor lock-in.

Container Orchestration

Podman-based microservices. Payload isolation. Resource management at the edge.

Purpose-Built

Not commercial Linux hardened after the fact. Designed from scratch for autonomous operations.

Deployable in Various Sizes

Customizable footprint that fits the form factor of your platform. From swarm-scale drones to large surface and undersea systems, TempestOS scales to match your hardware.