PlugOS is a portable, secure and private operating system developed by TrustKernel, designed to integrate high security, robust privacy, and rich intelligent experiences into a compact and versatile platform. Unlike conventional systems that compromise usability for security, PlugOS delivers a fully isolated, secure, and highly functional secondary system that can run on mainstream devices without modification.
PlugOS is built as an independent hardware system, enabling users to access a secure operating environment without jailbreaking, rooting, or flashing the host device. Using a USB-C connection, PlugOS can launch on iOS, Android, or Windows devices instantly.
This plug-and-play capability transforms PlugOS into a pocket-sized secondary device, providing unparalleled flexibility across personal, professional, and travel scenarios. Examples include:
By enabling a second secure and intelligent system anywhere, PlugOS eliminates the need for system modification or complex setup, ensuring consistent and efficient user experience across devices.
PlugOS balances security and usability, delivering full access to the Android ecosystem while maintaining strong privacy controls.
PlugOS ensures users can enjoy broad application choice while retaining granular control over permissions, network access, and data flows.
PlugOS breaks the barriers of traditional dual systems, delivering a seamless, efficient, and highly controllable integrated experience. It feels like operating two systems on the same screen, with smooth data flow and effortless switching.
This approach provides strong isolation by default while enabling fluid, user-controlled interoperability.
Conventional devices face countless malware and attack vectors, posing serious risks to user data and digital assets. PlugOS places digital security at its core, leveraging a unique low-level architecture for end-to-end protection.
Built on Trusted Execution Environment (TEE) and virtualization technologies, PlugOS integrates hardware isolation, dual-factor authentication, secure boot, full-disk encryption, and minimized interfaces to resist physical intrusion, system-level exploits, and supply chain attacks. Even in cases of device loss or cold boot attacks, user data remains unrecoverable.
In most mainstream systems, “default data collection” is the norm. Browsing history, keystrokes, location, communications, and habits are quietly logged, analyzed, and monetized under the guise of personalization. PlugOS takes the opposite path.
PlugOS treats user privacy as a core principle, ensuring your digital life belongs only to you. It never engages in data harvesting or behavioral profiling. From system architecture to default policies, PlugOS enforces a strict “local-only, no analysis, user-controlled” philosophy — meaning every digital action remains yours alone.
PlugOS virtualizes peripherals at the OS level, including GPS, SIM info, network state, and environmental sensors. This prevents hardware fingerprint tracking and safeguards identity. Users can dynamically toggle between virtualized sensors and real hardware (e.g., for navigation or calls), balancing privacy with functionality.
A system-level local firewall provides advanced privacy control, auditing all network activity in real time. It detects hidden trackers and unauthorized connections, giving users full visibility and control. Every connection is knowable, controllable, and traceable, ensuring true network privacy.
PlugOS enables end-to-end encrypted backup and recovery, ensuring all data remains encrypted during storage, transfer, and restoration. This grants users true sovereignty over their data — “self-owned storage, self-owned recovery” — with confidentiality and ownership fully protected.
PlugOS redefines portable intelligent operating systems by integrating portability, security, and privacy without sacrificing usability. Its hardware-level isolation, dual-system integration, and privacy-first architecture create a trustworthy digital environment where users remain in full control of their data and experience.