Overview
Enigm Link provides two operating modes from the official USB:- Desktop app mode: macOS, Windows, and Linux apps run from the official USB and open the Enigm Link secure environment.
- Boot OS mode: compatible computers can boot Enigm Link Boot OS from the official USB to run an isolated Enigm Link environment.
Desktop app
Current production version:
1.0.11.Boot OS
Current production release:
enigm-link-boot-os-2026.06.26.Updates
Current update channel:
stable.Quickstart
The user-facing startup guide for Enigm Link is available in Enigm Link Quickstart. Use the quickstart when you need the operational flow for opening Enigm Link from the official USB, confirming the protected environment, updating the USB, starting Boot OS mode, and finishing the session safely.Product Responsibilities
Enigm Link is responsible for:- Validating that the environment is running from an official Enigm Link USB.
- Starting a controlled browser environment.
- Requiring VPN validation before the environment is presented as protected.
- Supporting controlled updates for desktop apps and Boot OS.
- Preserving official USB identity and metadata during updates.
- Keeping visible platform folders clean for macOS, Windows, and Linux users.
- Providing a reproducible portable environment for supported devices.
- Preventing users from needing to install, provision, or rebuild the product manually.
Relationship With Enigm Command
Enigm Command is the lifecycle and control surface for Enigm Link. Enigm Command can govern:- Product purchase and entitlement.
- Official USB registration.
- Device lifecycle state.
- Update eligibility.
- Operational status visibility.
- Security policy and support workflows.
Documentation Map
- Enigm Link Quickstart explains the user-facing flow for opening Enigm Link from the official USB.
- Official USB explains the sealed USB model, visible content model, and device boundaries.
- Desktop Apps explains macOS, Windows, and Linux app behavior.
- Boot OS explains Enigm Link Boot OS, supported boot targets, and current limitations.
- Secure Browser Environment explains protected-state requirements and VPN validation.
- Updates and Security explains update protection, app updates, Boot OS updates, and fail-closed behavior.
- Troubleshooting explains public support scenarios and expected platform warnings.
Security Considerations
Enigm Link security is based on layered controls:- Official USB identity.
- Device validation.
- VPN-required protected state.
- Controlled update eligibility.
- Manifest and payload validation.
- Build allowlisting.
- Integrity checks.
- macOS signing and notarization.
- Separation between the visible app boundary and Boot OS boundaries.
- Fail-closed behavior when critical security configuration is unavailable.