The agent-first operating system

Your machine. In orbit.

Aeonward turns the computer into a self-describing, sovereign system: native services, an expressive desktop, a capability-aware control plane, and cryptographically signed updates that can recover themselves.

  • x86_64 UEFI
  • aeonkern native
  • Fail-closed install
1 native chainFirmware to userspace
0 Linux runtimeaeonkern production path
Signed driversCapability-scoped CPL3
A / B recoveryAtomic and fail-closed

A different contract

The operating system should not hide from intelligence. It should become legible to it.

Aeonward gives agents the same first-class control surface as people—structured operations, explicit capabilities, deterministic state, and errors that remain values instead of becoming chaos. Every subsystem speaks one machine-readable language without taking the machine away from its owner.

The constellation

An operating system designed as one coherent fabric.

Not a theme over a pile of tools. Aeonward joins compute, services, data, software, networking, and the desktop through native contracts rooted in aeonkern.

01 / NOVA

Services with a pulse.

Nova defines, activates, supervises, health-checks, restarts, and audits every resident service through the same contract used by Aurora and the agent plane.

02 / WEAVE

Data that proves itself.

Weave brings namespaced data, integrity proofs, snapshots, retention, and SafeBase-native storage into the operating-system contract.

03 / FOUNDRY

Build without drift.

Owned environments, offline caches, Python and CLI toolchains—with capability reports before mutation.

04 / CONDUIT

Remote, but pinned.

Fleet enrollment, SSH identity pinning, remote execution, sync, verification, and tunnels without ambient trust.

05 / AURORA

A desktop with intent.

Prism rendering, spatial windows, command summons, hardware surfaces, and keyboard-first recovery.

Aeonward core
AuroraNovaWeaveConduitFoundry

Architecture without theatre

One system. Native all the way down.

Aeonward's production chain is singular: firmware starts the Aeonward UEFI loader, the loader measures and enters aeonkern, and aeonkern brings up capability-scoped drivers, native services, WeaveFS, Nova workloads, and Aurora. Linux is used only on development workstations to compile and test artifacts; it is never part of the installed system.

01

Stable agent ABI

The control language remains constant while the substrate evolves beneath it.

02

Capability boundaries

Hardware and system powers are described, brokered, and auditable.

03

Fail-closed operations

Installation, identity, updates, and destructive flows require exact evidence.

The Aeonward projection

From verified boot to a sovereign computing fabric.

Evidence before promisesEach horizon separates what is already exercised in host and virtual-hardware gates from what still requires broader physical certification. A future capability never silently substitutes for a missing native one.

Now · foundation under proof

Boot, install, recover.

The native chain is being proven as one transaction from UEFI entry to a disk-owned Aeonward boot.

  • Measured UEFI loader and aeonkern handoff
  • Signed capability-scoped NVMe, AHCI and xHCI drivers
  • Target-fingerprinted installation with zero source-media writes
  • WeaveFS persistence, A/B activation and interruption recovery
  • Physical hardware certification remains an explicit gate
Next · native daily system

Hardware becomes a contract.

Aurora grows on top of stable native services instead of inheriting invisible platform assumptions.

  • Broader GPU, audio, Wi-Fi, Bluetooth and power coverage
  • Responsive Aurora composition and secure input paths
  • Nova service activation, health and recovery policies
  • Native networking through DNS, TCP, TLS and fleet identity
  • Inspectable hardware state for people and agents alike
Forward · sovereign ecosystem

Machines that can explain themselves.

The end state is a coherent platform where local intelligence operates with bounded authority and durable evidence.

  • Agent and human parity across every control surface
  • KodeVault-native software, provenance and rollback
  • SafeBase and Weave data with verifiable lineage
  • Fleet orchestration without ambient or hidden trust
  • Portable service contracts across Aeonward machines
The invariant never changes. Firmware → Aeonward UEFI loader → aeonkern → native services → Aurora. Every release advances that chain without inserting a compatibility operating system beneath it.
Stable channel · checking

Update once. Recover always.

Every Aeonward release is signed offline with Ed25519, checked against a monotonic anti-replay sequence, downloaded into a standby runtime, health-tested, and activated with one atomic pointer. If the new runtime fails, Aeonward switches back before the machine is stranded.

Release v0.3.26 Hourly automatic checks Staged rollout ready
Verify trust rootDetached Ed25519 signature
Trusted
Stage standby slotHash, size, version, compile
Atomic
Switch and prove healthServices restart, failure rolls back
Recoverable

Aurora desktop

A cockpit, not a wallpaper.

A spatial, keyboard-first shell where services, hardware, security, data, and agent actions are visible and operable—not buried behind layers of settings.

AEONWARD / AURORA / NATIVE SYSTEM
Native Aeonward Aurora desktop with the compact bottom-left Aeonward launcher, application registry, square icon dock, system bar, and workspace controls
BOUNDED LIVE TELEMETRY
Native Aeonward System Monitor showing bounded live CPU, memory, network, temperature, storage, and an explicit unavailable GPU state
NATIVE VERIFIED APPLICATIONS
Native Aeonward KodeVault application showing verified package and installed application status
AUTHORITATIVE TIME DIAGNOSTICS
Native Aeonward Date and Time control room showing Australia Sydney local time, UTC time, current offset, daylight-saving state, synchronization, and the system realtime clock source
LIVE WEAVE DATA FABRIC
Live native Aeonward renderer showing the Weave data-fabric graph, workspace rail, system status controls, and square icon navigation dock

One final install

From boot media to continuous delivery.

Verify and write the image

Use only a content-addressed Aeonward image and its signed receipt. The guarded writer locks the exact carrier identity, byte count, model, serial and checksum before changing removable media.

Boot the compatibility menu

Boot the read-only preflight first. Aeonward records firmware, framebuffer, CPU, ACPI, PCI, input and storage evidence without granting installation authority.

Secure Boot support depends on the target firmware trust chain. Until Aeonward's trust path is enrolled, disable Secure Boot and Fast Boot, then choose the explicit UEFI USB entry.

Install through the guarded flow

The installer excludes its source, requires exactly one compatible NVMe or AHCI target, displays its live identity and accepts the 16-digit fingerprint only after the operator selects the destructive entry. aeonkern revalidates every boundary before the first write.

Let Aeonward maintain itself

After a USB-removed cold boot, signed updates stage into the inactive slot, preserve the last healthy system and activate only after health evidence. Interrupted or unhealthy candidates roll back without a host operating system.