Superbacked OS is a hardened operating system built on Ubuntu Desktop that runs air-gapped by default, entirely from memory and persists nothing to disk.
The problem
Even after you close app, traces of your secrets can persist on disk — hidden in files your computer creates when printing or managing memory.
Malware can record your keystrokes and clipboard, capturing secrets before they are even encrypted. If your everyday computer is compromised, your secrets are exposed.
Internet-connected computers can send your data to an attacker — without any visible sign.
The printing system on macOS and Linux (CUPS) writes a complete copy of printed documents to disk. Even after the print job finishes, the data can be recovered with forensic tools.
Wi-Fi and Bluetooth remain targets even when not in use — turning them off in settings is not enough.
The solution
Superbacked OS leaves nothing behind by design — air-gapped by default, no wireless, no persistence. Verify for yourself that nothing was written to disk.
In air-gapped mode (default), networking cannot start at all — even by accident — and firewall blocks all traffic in and out. Bluetooth is completely disabled in both modes, not just switched off. Your secrets cannot leave device.
Superbacked OS is copied to memory at boot — USB flash drive can be unplugged as soon as login screen appears. Everything written during a session — including print files — vanishes on shutdown and memory is erased the instant it is no longer needed, so secrets do not linger.
USB drives never open automatically and new USB devices are rejected while screen is locked. Every app runs confined, allowed only what its job requires — apps handling secrets are denied network access inside the operating system itself, a second wall beneath the firewall. Administrator privileges are removed after setup, so even a compromised session cannot undo these protections.
Disk always produces same fingerprint (SHA256 checksum). Compare fingerprints before and after use — if they match, nothing was written to disk.
See verification guide →Hardened browser mode
Some tasks — such as backing up two-factor authentication secrets — genuinely need the web. Hardened browser mode is a deliberate choice made when device starts, can never be switched on mid-session and grants network access to a hardened Firefox — and to nothing else.
Firefox runs under its own restricted account with no access to your files and no way to gain control of system. Superbacked app has no network access even in hardened browser mode.
Only browser account can reach the web. Everything else is blocked — including all traffic from Superbacked app.
Settings are locked and cannot be changed from inside browser: always-private browsing, encrypted DNS, HTTPS-only mode and strict tracking protection — no telemetry, accounts, password saving or autofill.
Other apps cannot watch browser windows or record what you type — Superbacked OS removes legacy display technology (X11) that makes window snooping possible.
Hardware
No exotic hardware required — an old laptop makes a perfect dedicated device. Flash a USB drive, boot and start creating blocks.
Compatible with any 64-bit desktop or laptop with 4 GB of memory or more (8 GB required to run entirely from memory and unplug USB flash drive). Boot from USB drive or flash image to internal drive.
Works out of box with printers such as the Brother HL-L2460DW — no driver installation required.
Blocks are scanned using built-in or plug-and-play webcam — 1080p minimum for reliable scanning.
Bundled apps and utilities
Superbacked OS bundles hand-picked apps and command-line utilities for managing hardware wallets and security keys — everything preinstalled, frozen (the image never updates itself) and working offline.
Command-line tool for managing Trezor hardware wallets. Initialize, recover and manage wallets on air-gapped hardware. Smart card readers are supported.
See trezorctl on GitHub →Two-factor codes stored on YubiKey and read straight off key over USB — works fully offline.
See Yubico Authenticator on GitHub →Guided workflow for generating PGP master keys and provisioning subkeys to YubiKeys. Master key only ever exists in memory — power off and nothing remains but subkeys on YubiKey.
See yubikey-prov on GitHub →For high-stakes secrets, use Superbacked OS — a hardened operating system that runs offline and persists nothing to disk.
Copyright (c) Superbacked, Inc.