The safe substrate for the next era of computing.
One safe language. One image. Embedded rigor + verified security + a real desktop — at once.
Software is being told, from every direction at once — regulators, defense, the AI boom — to become memory-safe, isolated, and verifiable. The industry's answer so far is to patch a C-shaped world. Sigil is a bet that the substrate itself should change, and sigilOS is the proof it can — running on real metal today.
In one breath
Every company on Earth runs on software that trusts by default — and almost every breach, recall, and 3 a.m. page starts right there. That's a foundation problem, not a patch problem, so we built a new foundation. Sigil is a language where a program can touch only what you explicitly hand it, and where safety is proven mathematically before the code ever runs. sigilOS is a complete operating system written entirely in it — and it already boots on real hardware. One safe substrate that scales from a doorbell to a jet fighter. The world is being ordered to become memory-safe and verifiable; everyone else is retrofitting that onto a fifty-year-old foundation. We're not retrofitting — we're the new one. Built out of Manhattan, Kansas. Back us, and we become the substrate the next era of computing runs on.
Take it with you: the 12-slide deck (.pptx) · the one-page brief (.pdf) · or the full media kit.
The category
Not "another OS" and not "another language." The bet is a safe, verifiable computing substrate — a single memory-safe, capability-secure language and an OS built in it — that spans from a household appliance to a workstation. The wedge is that today you must choose: real-time rigor or a desktop; memory safety or the metal; a verified microkernel or a usable OS. sigilOS is architected to refuse the trade.
Why now
The unique position (the moat)
The defensibility isn't one feature — it's the combination held at once, on one safe language: capability-security by construction, zero-C memory safety, effects and contracts proven before runtime and then erased, and a reproducible verified TCB — from the EFI stub to the desktop, from a Pi 3 to a workstation. Reproducing that isn't a sprint; it's a re-foundation. Incumbents are structurally anchored to their C/C++ substrates and their single-tier markets. See the dimension-by-dimension difference model.
Go-to-market: two motions, one substrate
- Bottom-up (mindshare). Land with things people run today — the Sigil language and Forge (native, shipping on three desktop platforms) — and build a developer and enthusiast community, the Python/Rust/Go adoption pattern.
- Top-down (revenue). Design wins in high-assurance verticals — safety-critical, defense & sovereign, embedded/edge — where the architecture is genuinely rare and the willingness to pay is real.
Stage & traction — stated straight
- The hardest technical risk is retired: an entire capability-secure OS in one memory-safe language boots on real x86-64 hardware, with a self-hosting, reproducibly-verified compiler. This isn't a deck — it's on metal.
- SHIPPING A first native product (Forge) is downloadable today on macOS, Linux, and Windows — the beachhead is live, not theoretical.
- BUILDING Pre-1.0. Driver breadth, Pi bring-up, ecosystem, and the 1.0 milestone are active, developed fully in the open — every win and every hard part on the blog and changelog.
- NOT YET No certifications, no revenue claims, no vanity metrics. The investable thesis is the architecture, the proof-on-metal, and a category that is turning our direction. We'll show you exactly where the line is.
The vision
From the firmware in a household appliance to a tablet, a desktop, medical equipment, and the hardest embedded systems there are — one safe, verifiable substrate underneath all of it. We're not chasing the incumbents; we're building the thing they'll need when the C era's bill comes due.