Guix
SELinux
LUKS
no sudo or such
many apps and environments are chrooted
networked programs also in Xephyr or disconnected from X
guests and nonfree software live in vm
Hopefully coreboot and secure boot? (don't think latter is needed)
no sshd on host unless needed
future setup that'll make "secure"tards seethe :cirno_heh:
@iska please no secure boot
I prefer to run nonfree software in firejail also