ARGA | CoreTM
← Our projectsSecurity & identity / Infrastructure hardening
Beta

ARGA | Secure

Inspect first. Change with control.

An infrastructure security auditor and remediator combining policy validation, selectable controls, structured reports, and bounded remediation with preview and recovery mechanisms.

Why it exists

Designed for
real work.

ARGA | Secure follows a deliberate security workflow: detect the platform, validate policy, inspect selected controls, and apply bounded changes with recovery support. It covers Linux infrastructure and related systems, helping operators make security work reviewable and controlled. The team can discuss the platform and control coverage relevant to your deployment.

What it covers

The capabilities.

01

Platform and policy checks

Detect the platform, validate policy inputs, and select the controls relevant to an audit.

02

Structured audit reports

Produce JSON and Markdown evidence reports that can be reviewed by both operators and tooling.

03

Infrastructure control families

Documented control areas cover accounts, services, filesystems, networks, and integrity.

04

Bounded remediation

The implementation describes bounded Docker, Nginx, and Caddy remediation rather than unrestricted configuration changes.

05

Protected recovery mechanisms

Transaction and recovery APIs are intended to support preview, controlled application, and recovery from changes.

06

Appliance evidence checks

The scope includes OPNsense administration, update, and backup evidence checks. Ask about coverage for your appliance version.

Who it's for

Linux operators

Teams auditing and hardening self-managed Linux infrastructure.

Platform teams

Operators reviewing host, container, and web-edge controls.

Security reviewers

People needing structured audit evidence and controlled remediation.

Current project stage

Beta

ARGA | Secure is in Beta and progressing toward a release candidate. Discuss the platforms, security controls, and recovery workflows you need. Commercial use requires a licensing conversation with the team.

Ask about availability →