Built here. Proven clean.Florida · Texas

Services: inspect, trace, certify

Your line. Our proof.

You keep building. We inspect, trace and certify the electronics coming off your line, then install the same process in your plant. Every unit leaves with a human-certified Shield report: a signed record of what’s inside. And when you need more, we sign the firmware, attest it in the field and read the source.

Open to outside plants from Q1 2027

Custody log

Sample

Flight controllerBuilt at your plant

  1. Received for inspectionOn your line
  2. Firmware inspectedImage reviewed on the board
  3. Chips & board tracedEach component to its source
  4. Build hashedRecord held in PCI custody
  5. Certified & signedShield report issued

Certified byPCI security engineer

Signed record

The gap

Meeting the spec isn’t the same as proving it.

Federal restrictions on foreign-made electronics mean primes increasingly have to prove provenance, not just claim it. A supplier’s own PDF doesn’t do that.

How a Shield report compares with a self-attested supplier document
Self-attested todayWith a Shield report
Who vouches for itThe supplier, in its own documentAn independent reviewer who signs the report
FirmwareAssumed to match the specInspected on the board itself
Chips and boardListed on a bill of materialsTraced back to their source
The recordA file that can be revised laterHashed and held in our custody
Foreign influenceNot addressedChecked and documented, part by part

Case in point

In 2026, the Royal Navy found cameras on its K3 Scout uncrewed boats sending signals to an address in China. The camera supplier had given assurances they met U.S. NDAA standards.

See more threats on the record

How it works

Four steps. One signed record.

The same work we run on our own line, done inside your plant. Each step adds evidence to the unit’s record.

  1. Step 1: Inspect the firmware

    We inspect the firmware on the board, so nothing runs on it that shouldn’t be there.

    You getFirmware findings, recorded against the unit
  2. Step 2: Trace the chips and board

    We trace each chip, and the board itself, back to where it came from.

    You getA provenance record for every component
  3. Step 3: Hash it in our custody

    We hash the build and hold the record ourselves, so it can’t quietly change after the fact.

    You getA tamper-evident build record in PCI custody
  4. Step 4: Certify it

    A person on our team reviews the evidence and signs off. Not an automated checkbox.

    You getA human-certified Shield report that travels with the unit

Beyond the four steps

Firmware you can prove.

Signing, attestation and source review for the firmware inside your product, backed by our own hardware security module.

Firmware attestation

We capture the hash of the firmware we load at production, and give you software that checks in real time that what’s running is still what we shipped.

Signed firmware

We sign firmware and updates with our own hardware security module, with post-quantum-ready signatures, so an unsigned or altered image doesn’t load.

U.S. key custody

Keys provisioned at manufacture and held in a U.S. hardware security module, in our custody or yours. The root of trust starts here.

Source code review

When you have the source, we read it. We look for zero-days, back doors, phone-home and kill-switch logic, and we compile it ourselves so the binary matches.

Reverse engineering

When you don’t have the source, we take the firmware apart and look for the same things, within a scope you authorize in writing.

Component watch

When a new firmware revision ships, we hash it, diff it against the last one, and tell you what changed, as an annual service.

The deliverable

What’s in a Shield report.

One product number and one firmware revision make one report, with the same structure every time, so the tenth looks like the first. Lite, Deep or Source: same report, different depth.

Behind every report: the Component Passport

The structured record behind the PDF: part number, revision, hashes, SBOM, watch list and the delta to the next revision. When a new firmware rev ships, the Passport is where the change shows up.

  1. 01
    IntakeSerials, photos, packing list, source and your written authorization.
  2. 02
    IdentityController or SoC, vendor, claimed country of origin, and the tool versions we used.
  3. 03
    Image custodyFilename, size and SHA-256 of every image, how we obtained it and who hashed it.
  4. 04
    Update storyWhether updates are signed, the signing identity if known, and rollback posture.
  5. 05
    Debug inventoryConsoles, test commands, leftover strings and unexpected hosts.
  6. 06
    Third-party mapBlobs, libraries, compiler marks and country notes.
  7. 07
    FindingsNone, observation or vendor action, each with a severity and an owner.
  8. 08
    Not testedThe explicit limits of the work. We never claim zero risk.
  9. 09
    Sign-offAnalyst, reviewer, date and tool versions. A person signs, not a model.

What an engagement includes

Built for your plant, not ours.

You keep your line, your people and your customers. We bring the process to you and keep it running.

01

We certify your units

Our team inspects, traces and certifies the work inside your plant, and issues a Shield report for it.

02

We install the process

We set up the same inspect, trace and certify process on your line, so it runs with every build.

03

Watch, attestation and software

An annual watch on new firmware revisions, attestation software for the field, and support, so the record keeps pace with your production.

Proven on our line first

We run it on our own units before yours.

Every drive we build carries its own Shield report. It’s the same process we’ll run in your plant, tested first on hardware we stand behind.

Open to outside plants from Q1 2027

Shield report

Sample

Encrypted SSD · M.2 2280Serial & build hash on file

  • Firmware inspectedVerified
  • Chips & board tracedTo source
  • Hashed in PCI custodyOn file
  • Assembled in the U.S.Source controlled

Certified byPCI security engineer

Signed record

Who it’s for

For manufacturers whose customers need proof.

Defense industrial base manufacturers

Show program offices exactly what’s inside the boards you ship.

UAS makers

Answer supply-chain questions with a signed record, not a PDF.

Radio & comms module makers

Prove the firmware in your modules is what you say it is.

Critical-infrastructure suppliers

Give energy, water and data-center operators evidence for what they install.

Primes & integrators

Hold your suppliers to a record you can actually check.

Our rules

How we work, and what we won’t do.

The rules that keep a report worth signing.

  1. No exploits, ever.We don’t publish exploits or proof-of-concept code, and we don’t bypass protections on shipping hardware.
  2. A person signs.A model can draft; it never signs. Every report carries a named analyst and reviewer.
  3. Scoped, evidenced risk.We never claim zero risk. We state what we tested, what we found and what we didn’t test.
  4. Your firmware stays yours.Customer firmware is never used to train AI, and it stays in U.S. custody.
  5. Written authorization first.No work starts on a handshake. Serials and permission go in the scope memo.

FAQ

Questions buyers ask.

Don’t see yours? Ask us directly.

Contact the services team

Do we have to move production to you?

No. You keep building. We inspect, trace and certify inside your plant, then install the process so it keeps running on your line.

Is a Shield report the same as FIPS, NIAP or CMMC?

No. A Shield report is our certified record of what’s inside a specific unit. It supports formal certifications and program reviews, but it doesn’t replace them.

Do you claim every chip is made in America?

No. We don’t claim every chip is fabbed here. We prove where each one came from, so you and your customer can decide with the facts.

When can we start?

We run the process on our own line today and open it to outside plants from Q1 2027. Talk to us now to plan your line.

Can you sign our firmware with our own keys?

Yes. We sign with our hardware security module, and keys can be provisioned and held in the U.S., in our custody or yours.

How is it priced?

As an annual service and software engagement, scoped to your plant and product. Contact us for a quote.

Put your line on the record.

Tell us what you build and where. We’ll walk you through the process and what a Shield report covers for your product.