...Due to its strict firewall policy, anonymization tools are not supported; the system enforces Quad9 DNS and allows only basic internet access.
Hardenwing is Secure Boot compatible and ships with it enabled by default. It uses GNOME (Wayland) as its desktop environment. During the build phase, a hook called Cerrah automatically removes unnecessary Debian and GNOME services that would otherwise expand the attack surface.
Website: https://nixovena.org/hardenwing/