What ships today in Herd 1.0.1
Hardened configuration and the tooling to assess and evidence it — free, in the Community edition.
Hardened by default
SELinux enforcing, hardened SSH (keys only, no root login), a restrictive firewall and system auditing (auditd) enabled out of the box — nothing to configure.
Hardening in one command
herd-harden applies a security profile — standard, ospp, cis or pci — via Ansible. Dry-run by default; --apply is explicit.
OpenSCAP assessment
herd-compliance-scan runs an OpenSCAP evaluation (SCAP Security Guide) and scores your system against a chosen profile.
Evidence for auditors
Each scan produces a readable HTML report and a machine-readable ARF file — the artifacts an auditor actually asks for.
FIPS mode & disk encryption
Optional FIPS mode (operates with FIPS-approved algorithms) and full-disk encryption with LUKS.
Free and production-ready
All of the above is in the free Community edition. Security and the operating system are never behind a paywall.
Standard security profiles
Herd ships the SCAP Security Guide, so you assess and harden against widely used baselines.
The bundled profiles let you address the technical controls of
well-known baselines — CIS (Levels 1 and 2, Server),
OSPP, PCI-DSS and a lightweight
standard profile. Pick a profile, run
herd-harden to apply it and herd-compliance-scan to
score and evidence it. The tooling is the same one auditors and infrastructure
teams already know (OpenSCAP / SCAP Security Guide). For our full security
posture and honest scope notes, see the Trust Center.
Compliance-ready from day one
Herd ships hardened, with standard security profiles and verifiable evidence — a readable HTML report and a machine-readable ARF — that address the technical controls of widely used baselines and cut down the work of a security audit.
Try the compliance tooling
Download Herd 1.0.1, run herd-compliance-scan and open the HTML
report. The full walkthrough is in the security documentation.