Features

Features and
tools

Neovanguard brings together identity, payment and security tools in packages managed by pacman. The services run on your own machine.

Feature 01

Nostr identity

The installer can create the local account from a Nostr key, encrypted with a password using NIP-49. An encrypted vault stores the profile and settings so they can be restored on another installation.

local account with a Nostr keysettings vaultNIP-46 remote signerlocal Nostr relay
Feature 02

Bitcoin and Lightning

Includes Bitcoin Core to run a full node, Core Lightning for payment channels and Sparrow for managing wallets and UTXOs. It also provides Elements for Liquid and Cashu tools.

bitcoindCore LightningSparrowElements (Liquid)eCash (Cashu)
Feature 03

System security

The default configuration keeps logs in RAM, applies noexec to /dev/shm and /var/tmp and uses restrictive nftables rules. Processes that handle keys use hardened_malloc.

/var/log on tmpfsnoexec on /dev/shm and /var/tmprestrictive nftableshardened_mallocTor on demand
Feature 04

Vault mode

A session available from the boot menu for signing operations. The wallet uses a directory in RAM, discarded at shutdown, with tools to isolate the network and sign PSBTs.

Cold Vault at bootwallet in RAMairgap by commandPSBT signing
Command line

neo-* commands

The neo-* commands help you manage nodes, wallets, networking and security. Run --help to see the options of each command. Some examples are listed below.

neo-*commands with help via --help
  • neo-status: Shows the state of the node, Lightning, relay, network and memory.
  • neo-zap: Sends sats over Lightning to an npub, address or invoice.
  • neo-utxo: Analyzes UTXOs and suggests consolidations.
  • neo-ln: Checks the state and liquidity of Lightning channels.
  • neo-mempool: Checks fees and the state of the local mempool.
  • neo-sign: Signs a PSBT in an isolated environment.
  • neo-vault: Opens a wallet in a directory in RAM.
  • neo-shamir: Splits and rebuilds the seed with secret sharing.
  • neo-paper: Generates a template for a physical seed backup.
  • neo-qr: Transfers data between machines by QR code.
  • neo-airgap: Disables networking at the kernel level.
  • neo-killswitch: Blocks traffic outside the configured tunnel.
  • neo-tor: Sets up traffic routing through Tor.
  • neo-mac: Randomizes the MAC address of network interfaces.
  • neo-screenguard: Blocks screenshots while a seed is displayed.
  • neo-entropy: Checks the entropy available on the system.
  • neo-integrity: Verifies the integrity of installed binaries.
  • neo-audit: Checks the system's security settings.
  • neo-relays: Measures relay latency and sorts the list.
  • neo-mesh: Finds Neovanguard machines on the network and exchanges notes.
  • neo-nuke: Runs the emergency RAM wipe and powers off the machine.
  • neo-wipe: Wipes the session data.

The remaining commands cover power, network and memory management and session data cleanup.

Desktop environment

Plasma, with the Birfree theme

KDE Plasma is the default desktop environment, configured through the KDE settings application. The Birfree theme brings together Neovanguard's colors, icons and boot screen.

Other desktop environments can be installed with pacman -S, using the packages available for Arch Linux.

Try it with the Live image