Hardened. Compliant. Ready in Minutes.

YOUR NEXT DEPLOYMENT ALREADY HARDENED

All the security work is already done before you deploy. Hardened, scanned, and compliant straight out of the box. So your team spends time building products, not configuring servers.

Explore Our Solutions How it works
lynxroute-instance — first boot
CIS Level 1 OS hardening applied
auditd · SSH hardening · kernel hardening
AppArmor · fail2ban · UFW firewall
Trivy CVE scan passed
Unique credentials generated per instance
SBOM at /etc/lynxroute/sbom.json
CIS Conformance Report bundled
Instance production-ready.
Compliance
CIS Level 1HARDENED
CycloneDX SBOMINCLUDED
Trivy CVE scanPASSED
Default secretsZERO
100+
Hardened images
75+
AWS Marketplace listings
100+
Azure Marketplace listings
24h
Support response target
Out of the box

What You Get Out of the Box

Security and compliance work your team would otherwise spend days doing - already done.

CIS Level 1 Hardened

Every image ships with CIS Level 1 OS hardening - auditd, SSH hardening, kernel hardening, AppArmor, and fail2ban pre-configured.

SBOM & CVE Scanning

Every release is scanned for vulnerabilities with Trivy. A CycloneDX SBOM and a CIS Conformance Report are bundled inside every deployed instance.

Zero Default Secrets

Unique credentials and secrets are generated per instance at first boot. No shared passwords, no known defaults - each deployment starts fresh.

Deploy in Minutes

What normally takes your team days of configuration work is already done. Launch from AWS, Azure or Alibaba Cloud Marketplace and be running in production within minutes.

Catalog

Featured Images

AI & LLM · Databases · Security · Backend platforms · Productivity · DevOps. Every image on the same hardened Ubuntu 24.04 LTS base.

Browse all 100+ images
Backend platform

Supabase

Open source Postgres backend with auth, storage and realtime APIs.

AI & LLM

Qdrant

Vector database for AI search and retrieval workloads.

Database

ClickHouse

Column-oriented OLAP database for real-time analytics.

Database

Neo4j

Graph database for connected data and relationship queries.

Security

Wazuh

SIEM and security monitoring platform for endpoints and cloud.

Security

Vaultwarden

Self-hosted password manager compatible with Bitwarden clients.

AI & LLM

Ollama & Open WebUI

Private LLM runtime with a chat interface, running in your own cloud.

DevOps

Temporal

Durable workflow engine for reliable distributed applications.

Also available: AnythingLLM, Plane, Appwrite, Immich, OpenBao, RustDesk Server, Langflow, Typesense, Headscale, Paperless-ngx, OpenHands and 50+ more.

Available on

Explore Our Solutions

Browse and deploy Lynxroute images directly from your preferred cloud marketplace.

AWS Marketplace
75+ listings

Deploy on Amazon Web Services. Browse our full catalog of hardened, production-ready images on our AWS seller profile.

View on AWS
Azure Marketplace
100+ listings

Deploy on Microsoft Azure. Find and launch Lynxroute images directly from the Azure Marketplace catalog.

View on Azure
Alibaba Cloud Marketplace

Deploy on Alibaba Cloud. Launch Lynxroute images directly from the Alibaba Cloud Marketplace.

View on Alibaba Cloud
Supply chain security

How We Build and Maintain Every Image

Hardening is not a one-time step. Each image is built, scanned, monitored and rebuilt on a schedule so it stays production-safe after you deploy.

01 · Build

Reproducible build pipeline

  • CIS Level 1 OS hardening applied to the base
  • Trivy CVE scan before every release
  • CycloneDX SBOM and CIS Conformance Report generated at build time and bundled in the image
  • UFW, fail2ban, AppArmor and auditd pre-configured
02 · Monitor

Continuous vulnerability monitoring

  • Continuous vulnerability monitoring against upstream advisories
  • Out-of-cycle rebuild review when a critical CVE affects a published image
  • Patch communication and upgrade guidance for existing deployments
03 · Release

Scheduled rebuild cadence

  • Scheduled monthly rebuilds on the latest upstream software releases
  • Unique credentials generated per instance at first boot, never baked in
  • No telemetry or call-home in any image
  • Published to AWS, Azure and Alibaba Cloud marketplaces
Support & reliability

Backed by Expert Support

Every image comes with expert support and a 24-hour response target. Deployment questions, configuration help, or a security concern - reach us any time.

Contact support
7 days

Expert support desk

Requests accepted any day of the week.

24h

Response target

We aim to answer every request within 24 hours.

Deployment & configuration guidance

Help getting from marketplace launch to a running, configured instance.

Patch communication & upgrade guidance

Know when a rebuild ships and how to move existing deployments to it.

About Lynxroute

We do the hardening work so your team can focus on what matters.

Our Story

Lynxroute started with a recurring problem across organizations: making VMs production-safe. CIS hardening, CVE scanning, firewall setup, secret rotation - the same careful work, repeated from scratch every time.

We decided to do that work once, properly, and make the result available to everyone through the AWS, Azure and Alibaba Cloud marketplaces.

Our Mission

To make security-hardened open source software available to any team on AWS, Azure and Alibaba Cloud - without the days of configuration work it normally takes to get there. Every image we publish ships with CIS Level 1 hardening, CVE scanning, a CycloneDX SBOM, and a CIS Conformance Report included.

Our Values

Openness

We believe in open source software and open collaboration.

Quality

Every image we publish meets high quality standards.

Reliability

We verify and update software images so you don't have to.

Neutrality

We are vendor neutral. Our images run on all major clouds.

How It Works

Deploy production-ready open source software in three simple steps.

How It Works

From marketplace to production in three steps - no security setup required

Step 1

Pick Your Software

Browse our catalog on AWS, Azure or Alibaba Cloud Marketplace. Every image already includes CIS hardening, CVE scanning, and a full SBOM - the work your team would otherwise spend days on.

Step 2

Launch with One Click

Deploy directly from the marketplace. Unique credentials are generated at first boot. No manual hardening, no security checklist to work through.

Step 3

Run in Production

Your instance is production-ready from minute one. SBOM and CIS Conformance Report are bundled inside for audit or compliance review whenever you need them.

Why Lynxroute?

Everything you need to deploy open source software with confidence

Always Up-to-Date

Always built on the latest software releases so your deployments run verified, up-to-date software.

Multi-Cloud Ready

Deploy on AWS, Azure or Alibaba Cloud. Switch between providers any time with no lock-in.

Enterprise Standards

Every image is hardened, tested, and verified with open source licensing ready for production from day one.

Get in Touch

Whether you're evaluating options, ready to deploy, or just curious about what we offer - we'd love to hear from you.

Have a question about our images or need help finding the right solution for your cloud environment? We'd love to hear from you.

Privacy Policy

Effective September 13, 2026 · Version 1.1

Short version: Lynxroute does not collect, store, or process personal data. We publish hardened virtual machine images on cloud marketplaces. Once you deploy one of our images, it runs entirely within your own cloud infrastructure - Lynxroute has no visibility into your instance, your data, or your usage.

About Lynxroute

Lynxroute is a software publisher that builds and distributes hardened virtual machine images for cloud marketplaces, including AWS Marketplace, Azure Marketplace and Alibaba Cloud Marketplace. Our products are pre-configured, security-hardened Ubuntu 24.04 LTS VM images designed for self-hosted deployment.

We do not operate a SaaS platform, subscription service, or hosted product. We do not have access to any infrastructure you deploy.

What We Do Not Collect

Lynxroute does not collect any personal data. Specifically:

  • We do not collect names, email addresses, or contact information through our VM images.
  • We do not log, track, or monitor your cloud instances after deployment.
  • Our VM images do not include telemetry, analytics, or any call-home functionality.
  • We do not process payment information - all billing is handled exclusively by the marketplace (AWS, Azure or Alibaba Cloud) on your behalf.
  • We do not use cookies, trackers, or fingerprinting on this website beyond what is described below.

This Website

The Lynxroute website is a static informational site. We do not run analytics, advertising networks, or tracking scripts. Standard web server access logs (IP address, request path, timestamp) may be retained temporarily for security and operational purposes and are not shared with third parties.

If you contact us by email, your email address and message content will be used solely to respond to your inquiry and will not be shared or used for marketing.

Marketplace Purchases

When you purchase or subscribe to a Lynxroute product through AWS Marketplace, Azure Marketplace or Alibaba Cloud Marketplace, the transaction is governed by the terms and privacy policies of the respective marketplace provider. Lynxroute receives only the information the marketplace chooses to share with publishers (typically aggregate usage data). We do not receive your payment details or personal account information.

Your Deployed Instances

VM images you deploy from Lynxroute run entirely within your own cloud account. All data processed by the deployed software - user data, configuration, logs - remains within your infrastructure. Lynxroute has no access to it.

The compliance artifacts bundled with each image (SBOM, CIS Conformance Report) are static files generated at build time and stored inside the VM. They do not transmit any information.

Third-Party Services

Lynxroute does not embed or integrate third-party tracking, advertising, or analytics services in its VM images or on this website.

Our VM images include open-source software from third-party projects. Each product's software bill of materials (SBOM) is available inside the deployed instance. The upstream projects may have their own privacy policies and terms.

Data Retention

Because we do not collect personal data, there is no personal data to retain or delete. Web server access logs are retained for no longer than 30 days. Email correspondence is retained only as long as necessary to resolve the inquiry.

Security

Lynxroute builds security-focused products and applies the same standards to our own operations. Our VM images are hardened to CIS Level 1 benchmarks before publication. Every build is scanned for known CVEs and includes a CycloneDX SBOM and CIS Conformance Report for auditability.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be noted with a new effective date at the top of this page. Continued use of Lynxroute products after changes constitutes acceptance of the updated policy.

Contact

If you have questions about this Privacy Policy or our data practices, please contact us:

Lynxroute

Contact form: lynxroute.com/#contact

Terms & End User License Agreement

Short version: Lynxroute images bundle open source software under its own licenses with our hardening and configuration work. You may run them in your own cloud account for any lawful purpose. We provide the images as-is with expert support and a 24-hour response target. Billing and refunds are handled by the marketplace you purchased through.

1. Agreement

This End User License Agreement ("Agreement") is between Lynxroute ("we", "us") and the individual or organization deploying a Lynxroute virtual machine image ("you"). By launching a Lynxroute image from AWS Marketplace, Azure Marketplace, Alibaba Cloud Marketplace or any other channel, you accept this Agreement.

This Agreement is in addition to the terms of the marketplace through which you obtained the image. Where they conflict regarding billing, the marketplace terms apply.

2. What you are licensed to use

Each Lynxroute image consists of two parts:

  • Third-party open source software (the operating system and the application), licensed to you under each project's own open source license. The full list of components and their licenses is in the CycloneDX SBOM at /etc/lynxroute/sbom.json inside each instance.
  • Lynxroute hardening and configuration (CIS benchmark configuration, scripts, first-boot logic, compliance reports). We grant you a non-exclusive, non-transferable license to use this material as part of the deployed image, on the instances you run in your own cloud account.

You may not resell, redistribute or republish Lynxroute images or the Lynxroute configuration as a standalone product or competing marketplace listing.

3. Your responsibilities

Once deployed, the instance runs entirely in your infrastructure and under your control. You are responsible for:

  • Securing your cloud account, network configuration and access to the instance.
  • Managing the credentials generated at first boot and any data processed by the software.
  • Applying updates, or migrating to a newer Lynxroute release, when a rebuild is published.
  • Complying with the licenses of the bundled open source software and with applicable law in your use of the software.

4. Updates and rebuilds

We rebuild images on a scheduled cadence and perform out-of-cycle rebuild reviews when a critical CVE affects a published image. New releases are published as new marketplace versions. We do not modify, patch or access instances you have already deployed.

5. Support

Support is available through the contact form on this website and through the marketplace support channel. We aim to respond to every request within 24 hours. Support covers deployment, configuration of the Lynxroute image, and questions about bundled compliance artifacts. It does not cover custom development, third-party integrations, or operation of your wider cloud environment.

6. Fees and billing

All fees are set, collected and refunded by the marketplace through which you subscribed. Lynxroute does not process payments and does not receive your payment details. Refund requests are subject to the marketplace's refund policy.

7. Warranty disclaimer

Lynxroute images are provided "as is". We apply CIS Level 1 hardening, scan every release for known CVEs and bundle an SBOM and CIS Conformance Report, but we do not warrant that any image is free of vulnerabilities, that it satisfies any particular regulatory framework, or that the bundled software is fit for your specific purpose. Compliance of your overall environment remains your responsibility.

8. Limitation of liability

To the maximum extent permitted by law, Lynxroute is not liable for any indirect, incidental or consequential loss, including loss of data, revenue or business, arising from use of an image. Our total liability under this Agreement is limited to the fees you paid for the image through the marketplace in the twelve months preceding the claim.

9. Termination

This Agreement continues while you run a Lynxroute image. It ends when you terminate all instances and cancel your marketplace subscription. Sections 7 and 8 survive termination.

10. Changes

We may update this Agreement. The version in effect is the one published on this page at the time you launch an image. Material changes will be reflected in updated marketplace listings.

Contact

Questions about this Agreement: lynxroute.com/#contact