Maze Linux is a security, privacy and AI-focused desktop built on Arch. It ships a complete, hardened KDE Plasma Wayland desktop — defensive tools, anonymity tools and local AI already configured and turned on. No assembly required.
Security by default — AppArmor, firewall, auditd and Maze Guard — hardening and defensive tooling enabled from first boot. ClamAV + the QLAM GUI included.
Privacy by default — Tor, Proton VPN, WireGuard and automatic MAC randomization, preconfigured for anonymity. No telemetry, no tracking.
AI-ready — Ollama runs large language models locally and fully offline, alongside a complete dev toolchain and Maze's own AI utilities.
Why Maze? Arch, without the assembly.
Not a minimal base — a finished, hardened workstation you can boot, test live and install in minutes.
Complete KDE desktop — Full KDE Plasma 6 on Wayland with a polished layout, curated widgets and a clean dock. The real system, not a stripped-down spin.
Hardened from boot — AppArmor, firewall, auditd and Maze Guard active out of the box. ClamAV antivirus with the QLAM GUI, rkhunter and lynis included.
Private by design — MAC randomization, Tor, Proton VPN and Session messenger, all preconfigured. Your data stays yours — no tracking, no telemetry.
Local AI & dev — Ollama for offline LLMs, Upscayl, Maze's own AI tools, and a full base-devel + git + Python + paru toolchain ready to build.
A real live ISO — The live image is the full system — same desktop, apps and services. Evaluate everything before installing, even offline.
Still Arch underneath — Rolling release, full AUR access via paru, multilib and Flathub preconfigured. Total control, none of the manual setup.
Secure Boot — Signed with a key unique to your machine, sealing the kernel, initramfs and command line into one image. You approve it once, on first boot.
Full disk encryption — LUKS2 full disk encryption available at install time. The guided installer handles partition setup and key enrollment — your data is encrypted at rest without any manual configuration.
Guided installer — The guided installer takes you from live ISO to a fully configured system in minutes. Partition layout, user setup, LUKS, locale and bootloader — one flow, no manual steps.
Network firewall — firewalld is active from the first boot, and Maze Guard watches the network you're on for MITM attacks, ARP spoofing and rogue gateways — reacting through the firewall when it finds one.
Anonymity built in — Tor routing, Proton VPN and WireGuard are preconfigured. Route traffic through the network you trust in one click.
Auditable by design — No hidden binaries or opaque scripts. Every hardening step is documented, versioned and open for you to inspect.
Defense in depth
Security isn't one feature — it's rings of protection, from the hardware up. Most layers are active from first boot; the rest are one click away.
Hardware & Boot (Root of trust): Secure Boot, Full-disk encryption, USBGuard (optional), Signed kernel image
Network (Perimeter): firewalld, Maze Guard, Encrypted DNS, mDNS/LLMNR off
Privacy & Anonymity (Identity): Tor, Proton VPN, MAC randomization, mat2
Applications (Sandbox): ClamAV + QLAM, Firejail, Curated repos, Signed packages
Break it, and come back.
The thing people fear about a rolling release is an update that breaks the system. Maze prepares the way back before every update.
Always a second kernel — Maze keeps two kernels: the current one and the long-term-support one. If the current kernel will not boot, you pick the recovery kernel from the boot menu — already installed, built and signed.
A snapshot before every update — A btrfs snapshot is taken before and after every pacman transaction. If an update breaks something, you can see exactly what changed and undo it.
Checked before you reboot — After every update the whole boot chain is verified — kernel image, signature, encrypted-disk unlock. If something is wrong, the system warns you before you shut down and tells you what it is.
Was it Maze, or the hardware? — When your machine freezes, maze-doctor tells you why: a USB device that vanished, a disk that stopped answering, overheating — or a real software fault. No more hours spent looking in the wrong place.
Built-in tools
Maze ships its own suite of security and privacy tools — not third-party rebrands, but software built for Maze.
One panel for the whole system — A unified control panel for your entire system. Monitor security services, toggle privacy controls, manage local AI models and run maintenance tasks — all in one place, with live status and copy-ready terminal commands.
Static and live wallpapers, media mode — The default wallpaper of the Maze Linux desktop, in two parts: a KDE Plasma 6 wallpaper plugin and a settings app. Choose static or live wallpapers (GIF and looping video), or add your own MP4, WebM, GIF, PNG and more — your originals are never touched. Media mode shows the song that's playing as a corner card or a full-screen cover with synced lyrics, and the desktop blurs while a window is in focus.
Local AI assistant, fully offline — Maze's built-in AI assistant. Runs fully local through the Ollama backend — no data leaves your machine — or, optionally, switches to the Google Gemini API for cloud-grade models. Chat, code, summarize and run system prompts through one native interface, with model switching, conversation history and zero telemetry.
One-click anonymity layer — One-click anonymity layer: Tor, DNSCrypt and I2P running simultaneously. Track-free circuits, encrypted DNS and P2P overlay active and visible. Includes a PANIC button for instant disconnection.
Serverless messenger over Tor — End-to-end encrypted, no-logs messenger over Tor onion routing. Haze Protocol — your address is a .onion, your words dissolve. No servers, no accounts, no metadata.
Anonymous file drops — Anonymous file and text transfer over Tor. Drop a file, get a .onion share link — password-protected, download-limited, and self-expiring. No accounts, no cloud, no trace.
Public Wi-Fi security monitor — Maze's public Wi-Fi security monitor. It watches the network you're connected to and warns you when something on it attacks you — man-in-the-middle attempts, ARP spoofing, rogue gateways and port scans — and can react through the firewall. Open ports, devices on the network and the live firewall rules on one screen, with a profile per network.
MAC address randomizer — Randomises your network adapter's MAC address, and rotates it on a schedule if you want. Even networks you never join cannot track your device.
Antivirus with a clean interface — ClamAV-powered antivirus with a clean GUI. Real-time protection, quick and full system scans, quarantine and scheduled definition updates — all without the terminal.
Control your desktop from Android — A desktop daemon and companion Android app for remotely monitoring and controlling your Maze Linux desktop over the local network. Mutual TLS pairing, live dashboard, maze-guard killswitches, remote commands, local Ollama chat, two-way file transfer and home-screen widgets — with support for multiple paired computers.
Maze vs other distros
Arch gives you parts; Ubuntu and Fedora give you a plain desktop. Maze gives you a hardened, AI-ready workstation on first boot — and keeps Arch's rolling release, AUR and full control.
Stock Arch
Ubuntu
Fedora
Maze Linux
Out of the box
Minimal base, no GUI
Full GNOME desktop
Full GNOME desktop
Complete KDE Plasma Wayland desktop
Installation
Manual / generic archinstall
Graphical installer
Anaconda installer
Install Maze Linux (Calamares)
Security
You configure it
AppArmor on, firewall off
SELinux on, firewall on
AppArmor, firewall, auditd, Maze Guard on by default
Privacy
You configure it
Telemetry opt-out
Telemetry opt-out
Tor, Proton VPN, MAC randomization preconfigured
AI tooling
None
None
None
Ollama + AI utilities + dev toolchain
Live ISO
Console rescue shell
Full desktop
Full desktop
Full desktop, testable live & offline
Antivirus
None
None
None
ClamAV + QLAM GUI
Release model
Rolling
6-month / LTS
6-month
Rolling, Arch-based
Package manager
pacman + AUR
apt
dnf
pacman + AUR + Maze tools
From download to desktop.
Download the ISO — Grab the latest Live ISO — a single file, verified with SHA-256.
Write it to USB — Flash the ISO to a USB stick with balenaEtcher, Rufus or dd.
Boot & try live — Boot from the USB and explore the full hardened desktop — nothing installed yet.
Install in minutes — When you're ready, the guided installer sets Maze up on your disk.
FAQ
Is Maze Linux based on Arch?
Yes. Maze Linux is built on Arch Linux and follows a rolling-release model, so you always get current packages. You get Arch's power without the manual assembly — a complete, hardened KDE Plasma 6 desktop is ready on first boot.
Do I have to configure the security and privacy tools myself?
No. AppArmor, the firewall, Maze Guard, auditd, Tor, VPN and MAC randomization are already enabled and configured out of the box. Local AI via Ollama is also ready to run, fully offline.
Can I try it without installing?
Yes. Maze ships as a Live ISO — boot it from USB and try the full desktop before installing. When you're ready, a guided installer sets it up in minutes.
Does Maze Linux collect any telemetry?
No. Maze has zero telemetry — nothing phones home and there is no tracking. Privacy is the default, not an option you have to turn on.
What are the hardware requirements?
A 64-bit (x86-64) CPU with UEFI (no BIOS/Legacy), at least 4 GB of RAM (8 GB recommended, 16 GB for local AI) and 40 GB of disk space. Secure Boot and full-disk encryption are supported.
Is it free and open source?
Yes. Maze Linux is free to download and use, and built on open-source software.
Download, boot, install.
Write it to a USB stick, boot the live desktop, and launch the guided installer whenever you're ready.