DeeDee

DeeDee Linux

Security out of the box

Deedee is a Linux distribution derived from Debian Stable aimed at government and industrial applications with high security and strong component assurance requirements. It is designed from the ground up to provide a stable and wide selection of tools to build upon while also reducing dependencies and attack surface as much as is feasible.

The distribution offers a controlled subset of the packages Debian Stable has, curating the most proven and reliable packages into canonical feature sets – one database software, one desktop environment, one initialization system, etc. These curated packages are shipped with secure-by-default configuration sets, certified in accordance with international security standards and industry best practices.

Packages outside of this curated core set are still available, but aren't hardened by us or considered part of DeeDee. You can use them just as you would today, with the same security and safety considerations as you have for packages in Debian, but without the added security and compliance features DeeDee brings to the table.

Furthermore, supplementary repositories for enterprise applications such as unified Identity-Policy-Authentication suites, security log servers, and source code management are made available where the upstream distribution does not already provide them. 

DeeDee distinguishes itself from existing offerings in three primary ways.

Compatible

If you know Debian, you know DeeDee

DeeDee is binary-compatible with Debian Stable, one of the world's largest and most widely used Linux distributions. Whether it's your own software and know-how or third-party solutions, DeeDee is the same.

If you're running a Debian environment today, running a DeeDee environment tomorrow should be quick and painless. You won't need to reskill your engineers and architects because DeeDee is Debian. You won't need to completely rethink your attack surfaces and redo your existing documentation, because DeeDee is Debian. You won't need to recompile or repackage your own software or switch from any third-party software you might be using, because – you guessed it – DeeDee is Debian.

If you know Debian, you know DeeDee.

Free and open

Security for free, paperwork for sale

DeeDee is free for anyone to use, and all source code is available for review, contributions, and modifications. Supporting documentation for certification processes is available to business customers.

We are ardent supporters of the principles behind open source and transparency, and we believe that many eyes make for fewer incidents. We're committed to making DeeDee as secure a platform as possible, and we acknowledge that we're standing on the shoulders of giants.

As such, DeeDee and everything that makes DeeDee possible is released as free and open-source software. You are in complete control of every line of code or configuration that makes it onto your system from us, and we intend to keep it that way.

For business customers with regulatory considerations and formal certification processes, we offer full access to our library of backing documentation. While most end users have no need for the entire paper trail of how DeeDee is made and how we consider parts of applicable standards fulfilled, formal certification of a system requires these documents as part of the final accreditation.

Security for free, paperwork for sale.

Secure by default

Anything we ship, we ship secured

Functionality included in DeeDee is always configured securely out of the box, following best practices and industry standards. Hardening should be something you can take for granted, and with DeeDee, it is.

All software that becomes part of DeeDee's curated, officially-supported set goes through a selection process that includes evaluation for purpose, security risk mapping, and the development of a hardening profile for the software. These steps ensure that we are aware of and have made a conscious decision regarding everything we ship, and that it integrates well with the security strategies for a DeeDee system.

For example, we utilize systemd's service hardening options for every service that makes it onto the system. We disable, remove, or make inaccessible insecure kernel modules for all kernel packages. We ship firewall configuration, enabled by default, for any software that needs network access. We take all steps necessary to make sure that your system is secure by default, and that any changes – be they from you or from us – are tracked, verified, and deployed with no surprises along the way.

All configuration we ship is integrated the standard Debian way as configuration packages, ensuring your local modifications persist and that you get the benefit of new or changed hardening profiles every time we release one.

Anything we ship, we ship secured.