OpenWatch
The compliance OS.
A fleet eye, heartbeat, and control plane. Continuous posture, temporal queries, drift detection, governance workflows, and audit-ready evidence — for any team running Linux at scale.
Production-safe infrastructure for the agentic era
Hanalyx builds the rollback-safe primitives, the control plane, and the spec compiler that let teams — and agents — modify production without breaking it.
“No Linux change should ever be unsafe, unauditable, or unreversible — whether a human or an AI made it. That sentence is our entire company.”
●The portfolio
OpenWatch is the platform. Kensa is the engine. Specter compiles the specs the other two are built from.
The compliance OS.
A fleet eye, heartbeat, and control plane. Continuous posture, temporal queries, drift detection, governance workflows, and audit-ready evidence — for any team running Linux at scale.
The change engine.
Transactional configuration management. 508 rules, 23 typed mechanisms, automatic rollback. A single binary, no agent — the layer the rest of the family runs on.
The spec compiler.
A compiler for specifications — the toolchain we use to build OpenWatch and Kensa, open to anyone who wants machine-enforced spec rigor for their own systems.
Federal certifications
For AI platform teams
Letting an agent run ssh+sudo on your fleet is unbounded. Letting it call Kensa is a contract: every change is captured, validated, and reversible by construction.
Evidence, not assurances
{
"run_id": "kn-2026-05-06-7f3a",
"host": "app-7.prod.example.com",
"agent": "platform-agent/3.2",
"outcome": "rolled_back",
"rule_id": "ssh-disable-root-login",
"frameworks": {
"cis_rhel9_v2": "5.1.20",
"stig_rhel9_v2r7": "V-257947",
"nist_800_53": "AC-6(2), AC-17(2)"
},
"mechanism": "config_value",
"pre_state": { "captured": true, "method": "file_snapshot", "sha256": "f8c9a4...e21b" },
"change": {
"command": "sed -i 's/^PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config",
"exit_code": 0, "duration_ms": 142
},
"validation": {
"passed": false,
"reason": "sshd config-test failed: bad keyword 'PermitRootLogin'"
},
"rollback": {
"triggered": true, "method": "file_restore",
"verified_sha256": "f8c9a4...e21b", "duration_ms": 38, "outcome": "ok"
},
"signed_by": "hanalyx-evidence-key-2026-q2"
}Why now
AI agents are about to make more production changes than humans ever did. That is fine — provided someone can answer one question: can you prove the change was safe, and undo it if it wasn't?
Built on 12+ years securing Linux across the U.S. Army, DHS, FBI, and DoD — where the answer always had to be yes, in writing, with evidence. The same discipline now ships as tooling for the agentic era.
Put OpenWatch and Kensa in front of your fleet — and your agents.