Ironstake vs Redox. What each one commits to, honestly.
The honest comparison. Redox is a lightweight Arch-based distro that ships native Wayland + GTK4 tiling, aimed at tinkerers. Ironstake / NovaOS leads on bundled AI integration, the ready-made gaming / anti-cheat profile, and a beginner-friendly path off Windows 10. Both are real commitments. This is the side-by-side, on eight axes.
For readers who want the next step
The side-by-side is below. The waitlist brief is what follows it.
The full comparison is below: privacy posture, gaming and anti-cheat, bundled AI integration, getting off Windows 10, and the tinkerer’s Arch install question. After reading, the next gated step is the waitlist brief — it spells out the launch contract, the dates involved, and which cohort receives the earliest signed image.
Side-by-side
Eight axes. Same pair, both read end to end.
Each row is one axis the comparison turns on. The verdict sits in the body column on the right, not the leader column on the left.
| Axis | Ironstake (NovaOS) | Redox |
|---|---|---|
| Base OS | Memory-safe kernel, drivers, and core services in one codebase — whole exploit classes disappear with the code, not with patching. | Arch-based, native Wayland + GTK4 tiling, built for tinkerers — a minimal base the reader assembles into a desktop rather than the way it ships. |
| Target audience | Privacy-first readers who want a memory-safe kernel and an on-device AI runtime bundled with the OS. | Tinkerers who want to assemble a Wayland / tiling stack from a minimal Arch base, with no installer interview and no guided defaults. |
| Privacy posture | Telemetry off by default. Opt-in is a separate, reversible choice, and there is no second-tier product without it. | No distro-level telemetry layer. Per-package pacman decisions sit with the reader, and there is no installer-interview nudge — privacy is the reader’s own job, end to end. |
| Gaming support | Ready-made gaming / anti-cheat profile — kernel-side user-mode GPU scheduler, OSS driver model, anti-cheat that targets the game-process boundary only. | You bring your own stack. Steam, launchers, and pacman package choices are the reader’s own; the kernel surface is upstream Arch and the anti-cheat surface is whatever the reader composes. |
| AI integration | Bundled AI integration — an on-device runtime ships with the OS — no data-center round trip, no prompt-redirected inference, no peak-hour latency. | No bundled AI layer at the OS surface. The AI angle is per-app, plugin-, and AUR-installed — every routing choice is the reader’s package list, not an OS service. |
| Stability | Memory-safety at the kernel removes a class of CVEs that patching only narrows; raw coverage map published when the build ships. | Rolling Arch — always-current, but breakable on major libc / mesa transitions. Honesty about the rolling churn is part of the contract. |
| Learning curve | Steep curve for the privacy-first ritual, but ergonomic for the getting-off-Win10 reader — the side-by-side installer keeps the existing OS in the boot menu. | Steep curve by design. Manual config, no installer interview, hand-rolled boot / audio / network — the curve is the product for the reader who chooses it. |
| Install footprint | Single signed image; the side-by-side installer keeps the existing OS intact in the boot menu; nothing leaves the machine at first boot. | Minimal live ISO. The reader partitions, encrypts, and launches manually — no side-by-side installer and no interview step, by design. |
Privacy defaults & telemetry
Off by default vs per-package pacman choices — both sides, stated honestly.
Ironstake treats telemetry as a per-toggle choice with the default set to off, and there is no installer-interview nudge on either side. Redox ships no distro-level telemetry layer at all — per-package pacman decisions sit with the reader. One keeps telemetry off by default; the other treats privacy as the reader’s own job, end to end.
Redox inherits the Arch contract: no distro-level telemetry, no guided defaults, no installer-interview nudge. Privacy is whatever the reader’s package list, .pacnew review cycle, AUR choices, and service configuration make of it. That is — by design — the most privacy-honest default a distro can ship: nothing the distro did, nothing the reader has to opt out of. The trade-off is the same shape as any tinkerer’s distro: every choice is yours, every misconfiguration is yours, and there is no settings-panel that audits it for you.
Ironstake’s commitment goes the other way: telemetry is off at first boot, opt-in is a separate, reversible choice, and there is no second-tier product whose features depend on the data program being on. There is no pre-checked box, no nudge, and no second install required to read the audit logs. The trade-off is the runner-up on first-boot for the reader who wants the installer to make a small choice for them. For the privacy-first reader, that line is the point of the OS.
For the reader who treats “the distro did nothing by default” as the highest privacy posture, Redox is the better answer. For the reader who wants an OS-level data program they can read, audit, and opt in to without re-installing, Ironstake is the better answer. Both paths are reversible at the OS-feature level; both are committed to in writing.
Gaming & anti-cheat readiness
Ready-made gaming / anti-cheat profile vs DIY Stack on Arch.
Redox ships a minimal Arch base and leaves Steam, launchers, and the kernel driver surface as reader-composed choices. Ironstake re-engineers the kernel / driver / anti-cheat surface so the existing library genuinely runs, on a memory-safe base. Kernel surface is the same upstream decision on both sides, but Ironstake re-engineers it.
Redox’s gaming posture is the tinkerer’s posture: install Steam, install GameMode, install the launchers you want, choose your driver stack, and inherit whatever anti-cheat the upstream Arch kernel and the reader’s package list give you. The trade-off is the same one any Arch-tinkerer’s distro carries: the kernel surface is upstream Arch, the driver surface is upstream Arch, and the anti-cheat surface is whatever Steam Proton, the launcher, and the kernel module set you assemble happen to be. For the reader who treats gaming as a per-launcher property, that is the answer — and it is the same answer the Arch base has shipped for years.
Ironstake’s posture is architectural. The kernel is memory-safe in one codebase, the driver model is OSS, and the anti-cheat contract targets the game-process boundary rather than the screen, the input stream, or the broader desktop session. That is the difference between “good enough, today” and “the contract is written down in advance.” The trade-off is the build is not a daily-driver surface yet — raw coverage maps are published when the build ships, not before. It is the direction, not the line in the sand on day-1.
For the reader who treats the kernel / driver / anti-cheat surface as the deciding line, Ironstake is the better answer. For the reader whose gaming posture is “I’ll assemble Steam, GameMode, and the kernel modules myself on an Arch base,” Redox is the better answer. Both answers hold up on their own terms; they are aimed at different reading audiences, and the deciding line is the kernel surface.
AI integration vs package split
OS-level on-device runtime vs AUR / third-party app stack.
Ironstake ships an on-device AI runtime at the OS layer — one contract is OS-level. Redox has no distro-level AI layer; the AI angle is per-app, plugin-, and AUR-installed — the contract is package-level, not OS-level.
Redox inherits the wider Arch ecosystem and the typical AI-today stack: a chat client, a developer-tool wrapper, a browser extension, a local LLM pulled in from the AUR. Every routing choice is the reader’s package list. The audit surface is per-app, and the OS layer does not arbitrate which prompts flow where. The trade-off is the same as it is for any tinkerer’s distro: maximum reader choice, no OS-level guarantee about “where my prompt lives.”
Ironstake ships an on-device AI runtime at the OS layer, with a no-data-center-round-trip contract and a no-prompt-redirect contract. The runtime is the same component that serves the smart-window, the on-device summariser, and the inference-at-the-edge features the OS ships with. The trade-off is the runtime is committed to, but the daily-driver surface ships later in 2026 — the audit logs are public, the build is what produces the install coverage.
For the reader who treats “where does my prompt live” as a first-class OS-level concern, Ironstake is the better answer. For the reader who treats the AI angle as a per-app property managed through pacman and the AUR, Redox is the better answer. Both contracts hold; the deciding line is the OS-layer surface, not the launcher.
Getting off Windows 10
Beginner-friendly side-by-side install vs tinkerer’s Arch migration.
Both projects carry a real answer to the Win10 cliff. Ironstake answers it with a side-by-side install that keeps the existing OS in the boot menu, off-telemetry by default — the beginner-friendly path off Win10. Redox answers it with the tinkerer’s Arch migration: minimal ISO, manual partitioning, hand-rolled boot / audio / network. The deciding line is whether you want a privacy-first ritual or a build-it-yourself install.
Redox’s Win10 migration is the tinkerer’s migration: a minimal live ISO, manual partitioning, hand-rolled encryption, hand-rolled boot, audio, and network configuration, and no installer interview to step you through any of it. For the reader who already has an Arch migration on their CV and wants the tinkerer’s contract from the Win10 cliff onward, that is a real answer. The trade-off is the trade-off of any tinkerer’s distro: the first evening is real, the curve is the product.
Ironstake’s installer is the side-by-side kind: it keeps the existing OS in the boot menu, the same partition table, and the same launcher / library path. Telemetry is off by default, the opt-in is its own line item, and the reader can run a free-evening trial without committing. For the reader who is migrating off Win10 and wants a beginner-friendly path that does not compromise the privacy-first commit, that is the answer. The trade-off is the same as it is on any privacy-first build: the ritual is documented, the audit logs are public, and the first hour is read-the-documentation hour rather than do-things hour.
Both answers are real. The deciding line is which one the reader’s intent fits. Use Ironstake if the beginner-friendly path off Win10 with telemetry off by default is the answer you need. Use Redox if the tinkerer’s Arch migration and the minimal ISO are the answer you need. The version that fits the reader’s intent is the one that earns the install.
Head to the Downloads dashboard →
Signed-in readers have early access to the build images already published for the waitlist cohort.
What both sides commit to
The contract that holds, regardless of which OS you pick.
The contract is short, and it is the same on both sides.
Committed to, on either side
- Privacy is the reader’s own line item on either side — whether by an OS-level off-by-default contract or by no distro-level telemetry layer at all.
- Auditable code paths. No proprietary blobs in the boot path on either side.
- A real first hour, not a marketing mirror. The reader knows which commit they have installed at the end of the day.
- The kernel / driver / anti-cheat surface is documented in advance, on both sides — in writing, on day one.
Honest gap · both sides
- No migration tool for Windows today, on either side. The reader runs the same “you do your own backup” contract.
- Hardware compat lists are “as installs land” — the OS that comes with the most coverage map gets the most honest list.
- We will not promise a specific day for the build on either side. The build ships when it ships.
- You hear from us the day the build ships, on one email. No weekly note, no drip campaign, no funnel.