etminan
About us

A team that got tired of trusting the host it was watching.

Etminan isn't a company that set out to build a product and picked host-integrity monitoring as the market. It came out of a much narrower, more personal frustration — one shaped by a long time spent actually running Unix-like systems, and by watching the same generation of file-integrity tools go unchallenged for a very long time.

Where this started

A long history with Unix-like systems, and a shrinking patience for the state of the art.

We've spent a long time on the operational side of Unix-like systems — the part of the job where you're the one actually trusted to notice when something on a machine has quietly changed. Tools like AIDE, Tripwire, and Samhain have anchored that job for decades, and they still work, but they share the same structural weak point: the record of "what this file should look like" usually lives on the same machine it's protecting (see our honest comparison with all three). We got bored of that being treated as an acceptable trade-off rather than a solvable problem.

Etminan started as an attempt to answer one specific question: what happens if that record is anchored in a TPM instead — a small hardware chip most modern servers already have, built so its own record can't be rewritten by whoever has root on the machine it's watching? See why we built it this way for the reasoning that came out of chasing that question.

Who it's for

Built for places that can't just call out to a vendor's cloud.

From early on, we wanted something that would actually hold up in highly restricted environments — regulated industries, isolated networks, sites where "just call our API" isn't an option, and sometimes isn't allowed at all. That shaped real decisions, not just language on this page: quote verification is pure offline signature math with no TPM or external service required on the verifying side, every component is something you host and control yourself, and the software itself has no telemetry and no automatic phone-home during normal operation — the one narrow, operator-initiated exception being the optional plugin catalog commands (plugins list/install/update), which only ever run when you type them, never automatically. If your environment can't trust an outside cloud service with this job, that was the environment we were actually designing for.

Research first

It moved from a research possibility to a product.

This never set out to be a product. It started as research, born out of not being happy with the options already on the market — could a real TPM and Linux's IMA subsystem actually replace a trusted checksum file, and would that hold up against real attempted tampering, not just look reasonable on a whiteboard? We kept it a research project for as long as it took to test that directly, rather than shipping the idea on faith and finding out later.

Once the core idea was confirmed working — not just theorized — we started running it ourselves, as the host-integrity monitoring on our own systems. It stayed an internal tool for a good while, and over that time it grew: we added several new functions, hardened the rough edges, and turned a proven technical possibility into something dependable to operate day to day. What you can deploy today is built on that original research, but with many enhancements and improvements layered on since — the point at which we decided an internal tool that had earned its place was worth turning into a product other people could run.

Where we are

Based in Europe.

The team behind Etminan is based in Europe. We're small, which shapes how we handle support and correspondence — see below.

Get in touch

Free support that a small team actually reads — plus subscriptions when you need a guarantee.

Questions about deploying Etminan, feedback on the design, or anything else — free support is just an email address a small team actually reads, and we try our best to answer as soon as we can. Replies won't always be instant, so if you need guaranteed response times we offer subscription support with response-time commitments.

✉  Contact us

Reporting something security-sensitive? See the homepage Contact section for our PGP key fingerprint.