Verifiable identity and tracking across the fab, OSAT, and OEM/ODM — delivered with a commercial-scale provisioning product that doesn't disrupt the line.
An HSM-backed appliance on the factory floor, paired with cloud-side endorsement, registry, and monitoring. All the trust, none of the single point of failure.
Installed on the factory floor. Handles identity injection, key generation, and tamper-evident log signing at line speed. Offline-tolerant — no cloud dependency at the point of manufacture.
Device registry, endorsement authority, tamper-evident logs, and real-time provisioning telemetry.
Every step signed, every handoff logged, every custody transfer verifiable.
During product, devices generate or receive a unique cryptographic identity rooted in the HSM. Device ID is cryptographically bound to any parameters, e.g. die coordinates and logged.
Post-assembly, the appliance attests the device, endorses its identity, and writes an append-only record to the Identity Cloud.
The OEM/ODM injects device-specific credentials — carrier, payment, firmware keys — tied to the endorsed identity without seeing root secrets.
Bring your own root of trust, or pair with ZeroRISC Build.