Firmware attestation
We capture the hash of the firmware we load at production, and give you software that checks in real time that what’s running is still what we shipped.
Services: inspect, trace, certify
You keep building. We inspect, trace and certify the electronics coming off your line, then install the same process in your plant. Every unit leaves with a human-certified Shield report: a signed record of what’s inside. And when you need more, we sign the firmware, attest it in the field and read the source.
Open to outside plants from Q1 2027Custody log
SampleFlight controllerBuilt at your plant
Certified byPCI security engineer
Signed recordThe gap
Federal restrictions on foreign-made electronics mean primes increasingly have to prove provenance, not just claim it. A supplier’s own PDF doesn’t do that.
| Self-attested today | With a Shield report | |
|---|---|---|
| Who vouches for it | The supplier, in its own document | An independent reviewer who signs the report |
| Firmware | Assumed to match the spec | Inspected on the board itself |
| Chips and board | Listed on a bill of materials | Traced back to their source |
| The record | A file that can be revised later | Hashed and held in our custody |
| Foreign influence | Not addressed | Checked and documented, part by part |
Case in point
In 2026, the Royal Navy found cameras on its K3 Scout uncrewed boats sending signals to an address in China. The camera supplier had given assurances they met U.S. NDAA standards.
See more threats on the recordHow it works
The same work we run on our own line, done inside your plant. Each step adds evidence to the unit’s record.
We inspect the firmware on the board, so nothing runs on it that shouldn’t be there.
We trace each chip, and the board itself, back to where it came from.
We hash the build and hold the record ourselves, so it can’t quietly change after the fact.
A person on our team reviews the evidence and signs off. Not an automated checkbox.
Beyond the four steps
Signing, attestation and source review for the firmware inside your product, backed by our own hardware security module.
We capture the hash of the firmware we load at production, and give you software that checks in real time that what’s running is still what we shipped.
We sign firmware and updates with our own hardware security module, with post-quantum-ready signatures, so an unsigned or altered image doesn’t load.
Keys provisioned at manufacture and held in a U.S. hardware security module, in our custody or yours. The root of trust starts here.
When you have the source, we read it. We look for zero-days, back doors, phone-home and kill-switch logic, and we compile it ourselves so the binary matches.
When you don’t have the source, we take the firmware apart and look for the same things, within a scope you authorize in writing.
When a new firmware revision ships, we hash it, diff it against the last one, and tell you what changed, as an annual service.
The deliverable
One product number and one firmware revision make one report, with the same structure every time, so the tenth looks like the first. Lite, Deep or Source: same report, different depth.
Behind every report: the Component Passport
The structured record behind the PDF: part number, revision, hashes, SBOM, watch list and the delta to the next revision. When a new firmware rev ships, the Passport is where the change shows up.
What an engagement includes
You keep your line, your people and your customers. We bring the process to you and keep it running.
Our team inspects, traces and certifies the work inside your plant, and issues a Shield report for it.
We set up the same inspect, trace and certify process on your line, so it runs with every build.
An annual watch on new firmware revisions, attestation software for the field, and support, so the record keeps pace with your production.
Proven on our line first
Every drive we build carries its own Shield report. It’s the same process we’ll run in your plant, tested first on hardware we stand behind.
Open to outside plants from Q1 2027Shield report
SampleEncrypted SSD · M.2 2280Serial & build hash on file
Certified byPCI security engineer
Signed recordWho it’s for
Show program offices exactly what’s inside the boards you ship.
Answer supply-chain questions with a signed record, not a PDF.
Prove the firmware in your modules is what you say it is.
Give energy, water and data-center operators evidence for what they install.
Hold your suppliers to a record you can actually check.
Our rules
The rules that keep a report worth signing.
No. You keep building. We inspect, trace and certify inside your plant, then install the process so it keeps running on your line.
No. A Shield report is our certified record of what’s inside a specific unit. It supports formal certifications and program reviews, but it doesn’t replace them.
No. We don’t claim every chip is fabbed here. We prove where each one came from, so you and your customer can decide with the facts.
We run the process on our own line today and open it to outside plants from Q1 2027. Talk to us now to plan your line.
Yes. We sign with our hardware security module, and keys can be provisioned and held in the U.S., in our custody or yours.
As an annual service and software engagement, scoped to your plant and product. Contact us for a quote.
Tell us what you build and where. We’ll walk you through the process and what a Shield report covers for your product.