CIQ’s cover photo
CIQ

CIQ

Software Development

Reno, NV 7,032 followers

Rocky Linux, Apptainer, Ascender, Warewulf and Fuzzball

About us

CIQ is building the next-generation of secure and performant software infrastructure for the AI era. Founded in 2020 by open source pioneer Gregory Kurtzer, CIQ helps organizations simplify, unify, and democratize high-performance computing and enterprise IT. CIQ is the founding support and services partner of Rocky Linux and the creator of products like Fuzzball, Warewulf Pro, Ascender Pro, and Rocky Linux from CIQ. The company provides scalable, open infrastructure solutions that empower innovation from the operating system up. Rooted in a community-first philosophy, CIQ is trusted by organizations modernizing for a future defined by data and AI. Learn more at https://ciq.com.

Website
http://www.ciq.com
Industry
Software Development
Company size
51-200 employees
Headquarters
Reno, NV
Type
Privately Held
Founded
2020
Specialties
HPC, High Performance Computing, AI, ML, Orchestration, Linux, FPGA, GPU, Lustre, CPU, Server, Cluster Management, Provisioning, Containers, Software Supply Chain, Research, Science, Big Data, Analytics, and Composability

Locations

Employees at CIQ

Updates

  • View organization page for CIQ

    7,032 followers

    FIPS mode is a configuration. FIPS 140-3 validation is proof. That distinction matters under federal review. Enabling FIPS mode restricts a system to approved algorithms, but reviewers look for an active CMVP certificate covering the exact cryptographic modules and versions deployed. As agencies respond to BOD 26-04 and its three-day remediation clock, their systems still face the same cryptographic scrutiny during the ATO process. For every component in scope, teams need a traceable chain connecting: • The cryptographic module • The version deployed • The CMVP certificate covering that version Brian Dawson’s blog post explains what FIPS 140-3 actually requires, what evidence reviewers accept, and why a certificate for one module or release does not automatically cover another. It also looks at how RLC Pro Hardened simplifies that evidence chain with five active FIPS 140-3 CMVP certificates covering the kernel cryptographic module, OpenSSL, NSS, libgcrypt, and GnuTLS, plus up to 95 percent of the DISA STIG applied out of the box. Learn what your agency needs to prove: https://lnkd.in/eRFxKaZG #FIPS1403 #Cybersecurity #FederalIT #EnterpriseLinux #BOD2604

    • No alternative text description for this image
  • CIQ reposted this

    People conflate this all the time: open weight is not the same as open source AI. In fact, truly community-led open source AI has never really existed. Until now. That’s the idea behind my latest open source project: OpenWALDO. OpenWALDO is open weights, open artifacts, open licenses, open data, and open origins. Together, it makes up what a truly open source AI should mean. Then add the community to it, and you end up with a corpus of weights that is curated, validated, and free to use with provenance. We’re just getting started, and this only works if we build it together. Join us: https://openwaldo.org #opensource #ai #OpenWALDO #WALDO

  • View organization page for CIQ

    7,032 followers

    Open weights opened access to AI models. OpenWALDO opens the foundation behind them. Today, Rocky Linux founder and CIQ CEO Gregory Kurtzer launched OpenWALDO, a community governed open source project building a shared, auditable corpus of AI training data, with CIQ as its sponsor. OpenWALDO pairs licensed, traceable data with an AI Bill of Materials connecting sources, licenses, training runs, and model releases. It builds the substrate, not the models, so every builder can innovate above a foundation anyone can inspect and improve. Learn more and join the community: https://lnkd.in/eUvG99uA #OpenWALDO #OpenSourceAI #ArtificialIntelligence #OpenSource

    • No alternative text description for this image
  • View organization page for CIQ

    7,032 followers

    Monday: mirror the latest content and build a new content view from what production runs today. Midweek: stage the new view with a test group. Run it through the workload validation and security checks your team requires, then approve it for promotion once it passes. Friday: promote the approved view to production. If a change misbehaves, revert to a known good version. That is the lifecycle CIQ Enterprise Linux Manager (ELM) was built to support. Teams can build content views that include, exclude, and pin packages, then move them through dev, test, and production on their own schedule. Snapshots and reverts give teams a clear path back when needed. ELM also supports bare metal provisioning, exposes the full lifecycle through an API, and runs on infrastructure the customer controls, including air-gapped environments. Own the content. Control the cadence. Know what is going to production before it gets there. See how ELM works: https://lnkd.in/eenduJDC ELM is included with all RLC Pro subscriptions. Brady Dibble #EnterpriseLinux #RLCPro #Linux #ITOperations

    • No alternative text description for this image
  • View organization page for CIQ

    7,032 followers

    If LKRG catches a kernel integrity violation, that alert can't just sit in the local log of the host that's under attack. LKRG, included with RLC Pro Hardened, watches the kernel from the inside and flags privilege escalation attempts, unexpected credential changes, and other integrity violations as they happen. Catching them is the easy part. The harder question is getting that signal off the box and in front of your security team in Wazuh, next to the rest of your alerts. Here's what makes it work in the worst case. LKRG's remote logging runs in the kernel itself. When a kernel compromise triggers a panic and the system halts, ordinary userspace log forwarding goes down with it. The kernel-direct path still has a shot at getting the alert out. The article covers: • Why a kernel alert shouldn't live only on the host that raised it • How LKRG's own encrypted remote logging leaves straight from the kernel • Where lkrg-logger fits, and how the events reach Wazuh • The tradeoff between the kernel-direct path and ordinary log forwarding The payoff is kernel security events in Wazuh where your team can act on them, plus a copy kept off the host so it can survive even when the box doesn't. Read it: https://lnkd.in/eXvxQGEa #Linux #Cybersecurity #Wazuh #EnterpriseLinux

  • View organization page for CIQ

    7,032 followers

    Your Linux fleet should change when your team decides, not when an upstream repository does. Introducing CIQ Enterprise Linux Manager (ELM), the new lifecycle management solution that is available with all RLC Pro subscriptions. ELM gives Enterprise Linux teams a deliberate checkpoint for every change. Nothing reaches a host until it has been reviewed and approved, and every approved state can be tested, rolled forward, or rolled back with confidence. With ELM, teams can: • Control which security patches, bug fixes, and third-party software reach their fleet • Test the next approved state before it reaches production • Return immediately to a known good state if a change causes problems • Operate entirely on their own infrastructure, including fully disconnected environments • Bring new servers online automatically as the fleet grows ELM also integrates with Ascender Pro, synchronizing host vulnerability and inventory data to move teams toward a single control point for lifecycle management, configuration, and automation. CIQ Enterprise Linux Manager is available today for RLC Pro customers. Read the announcement and request a demo: https://lnkd.in/eNHig4g7 #EnterpriseLinux #RLCPro #Linux #ITOperations

    • No alternative text description for this image
  • View organization page for CIQ

    7,032 followers

    The goal sounded simple: cut OS licensing costs. The catch: do it without touching a single production workload. A Fortune 500 global payments company was running mission-critical workloads around the clock across more than 3,000 Linux nodes. Licensing costs were rising, but a less expensive OS would not save money if the move meant rebuilding or recertifying thousands of applications. CIQ moved the company’s estate to RLC Pro. Enterprise Linux binary compatibility meant its existing applications ran without modification. More than 3,000 nodes migrated with no application rebuilds, no recertification, and zero disruption to production workloads. The result: OS licensing costs dropped by more than 40%. And the relationship did not stop with the migration. The customer has since expanded its RLC Pro footprint into a multiyear partnership with CIQ as its infrastructure continues to grow. The savings opened the door. What CIQ delivered in production earned the expansion. Read the customer story: https://lnkd.in/e-rJPEU5 #EnterpriseLinux #RLCPro #FinancialServices #RockyLinux

  • View organization page for CIQ

    7,032 followers

    A production patch may not exist when BOD 26-04’s three-day clock starts. Federal teams still need to know what happened at the kernel while the fix is being tested. For the highest risk vulnerabilities, the remediation deadline begins when CISA adds the flaw to the Known Exploited Vulnerabilities catalog or an agency identifies it on an asset, whichever comes first. Patch availability does not start the clock. That creates a detection gap. Kernel exploits can escalate privileges or load rootkits beneath the user space processes and files monitored by traditional EDR tools. RLC Pro Hardened ships with Linux Kernel Runtime Guard 1.0 enabled from first boot. LKRG continuously checks kernel integrity, records exploitation behavior with a timestamp, and streams the evidence to an agency’s SIEM while its team tests and deploys the patch. LKRG does not replace patching. It provides visibility during the window that patching alone cannot cover. Read why BOD 26-04 requires federal teams to think about detection and remediation as two layers of the same response: https://lnkd.in/ea-VdyWc Brian Dawson #FederalCybersecurity #LinuxSecurity #CISA #RLCProHardened

    • No alternative text description for this image
  • View organization page for CIQ

    7,032 followers

    A global high-frequency trading firm with its own kernel engineers, its own hardware, and 15,000 servers in production just extended its RLC Pro contract through 2029. The firm gave CIQ a year to earn it, on its own certification schedule rather than an upstream release calendar. Its platform team received CIQ-built signed kernels across every supported Rocky Linux version, custom FUSE kernel module patches, package builds for the architectures deployed across its fleet, and same-day resolution of a production request. CIQ proved it could keep pace. The one-year renewal became a three-year commitment. Read the customer story: https://lnkd.in/eZFdGciz #EnterpriseLinux #RockyLinux

  • View organization page for CIQ

    7,032 followers

    CISA’s new open source software guidance gives agencies a framework for managing open source responsibly: assess before adoption, understand who maintains it, track dependencies, patch quickly, and establish the right support model. The next question is how your organization wants to put that guidance into practice. Community Rocky Linux gives your team full control, but it also leaves the hardening model to you. Your team must build, integrate, and maintain the controls needed to detect threats and respond while patches are in progress. RLC Pro Hardened makes proactive defense the starting point. It builds on Rocky Linux with runtime kernel exploit detection, a compliance mapped baseline, FIPS 140-3 validated cryptography, Secure Boot integration, and vendor support from first boot. The open source foundation remains the same. The difference is whether proactive hardening becomes another responsibility for your team or arrives as part of the platform. Explore both approaches: https://lnkd.in/eEuCt4hE #RockyLinux #EnterpriseLinux #Cybersecurity #OpenSource

Similar pages

Browse jobs