etminan
About us

A team that got tired of trusting the host it was watching.

Etminan isn't a company that set out to build a product and picked host-integrity monitoring as the market. It came out of a much narrower, more personal frustration — one shaped by a long time spent actually running Unix-like systems, and by watching the same generation of file-integrity tools go unchallenged for a very long time.

Where this started

A long history with Unix-like systems, and a shrinking patience for the state of the art.

We've spent a long time on the operational side of Unix-like systems — the part of the job where you're the one actually trusted to notice when something on a machine has quietly changed. Tools like AIDE, Tripwire, and Samhain have anchored that job for decades, and they still work, but they share the same structural weak point: the record of "what this file should look like" usually lives on the same machine it's protecting (see our honest comparison with all three). We got bored of that being treated as an acceptable trade-off rather than a solvable problem.

Etminan started as an attempt to answer one specific question: what happens if that record is anchored in a TPM instead — a small hardware chip most modern servers already have, built so its own record can't be rewritten by whoever has root on the machine it's watching? See why we built it this way for the reasoning that came out of chasing that question.

Who it's for

Built for places that can't just call out to a vendor's cloud.

From early on, we wanted something that would actually hold up in highly restricted environments — regulated industries, isolated networks, sites where "just call our API" isn't an option, and sometimes isn't allowed at all. That shaped real decisions, not just language on this page: quote verification is pure offline signature math with no TPM or external service required on the verifying side, every component is something you host and control yourself, and the software itself has no telemetry and no phone-home of any kind. If your environment can't trust an outside cloud service with this job, that was the environment we were actually designing for.

Research first

We stayed a research project until the idea actually held up.

This didn't start as something we intended to ship on a deadline. It started as a question worth testing properly before believing it: could a real TPM and Linux's IMA subsystem actually replace a trusted checksum file, and would that hold up against real attempted tampering, not just look reasonable on a whiteboard? We kept this a research project for as long as it took to test that directly, rather than shipping the idea on faith and finding out later. Once the core claims were confirmed working — not just theorized — we released it as open, self-hosted software rather than keep it as an internal experiment.

Where we are

Based in Europe.

The team behind Etminan is based in Europe. We're small, which shapes how we handle support and correspondence — see below.

Get in touch

One inbox, no ticketing system, no promises we can't keep.

Questions about deploying Etminan, feedback on the design, or anything else — there's no support tier or ticketing system behind this, just an email address a small team actually reads. We'll do our best to answer in good time, but replies won't always be instant.

✉  Contact us

Reporting something security-sensitive? See the homepage Contact section for our PGP key fingerprint.