Hardware Security Base
Hardware-Backed Identity & Secure Boot
Hardware Root-of-Trust and secure boot verification on supported microcontrollers.
⚡ CRA Article 14 reporting obligations approaching · Details →
TegmenSoft brings software component visibility, vulnerability operations, and secure update workflows into a unified control plane built specifically for embedded and connected product lines.
MCU Minimum Profile
256 KB Flash · 64 KB RAM
MPU / OS Architecture
ARM64 · x86_64 · Embedded Linux
Transport Security
TLS 1.3 / mTLS, AES-256-GCM
Cryptographic Signatures
Ed25519 / RSA-PSS
Transparent status of all platform capabilities and deployment models.
| Capability / Feature | Status Badge | Deployment Scope |
|---|---|---|
| Web SBOM Scanner & OSV Matching | Available | Free Web Tool (In-Browser Parsing) |
| CycloneDX 1.7 & SPDX 2.3 Export | Available | Browser & API Specification Export |
| Dynamic SBOM Engine (Binary Analysis) | Pilot | Enterprise Pilot Program |
| Field Telemetry & Exploit Warning | Pilot | Enterprise Pilot Program |
| Secure OTA (Signed & A/B Rollback) | Pilot | Enterprise Pilot Program |
| ENISA SRP Reporting Assistance | In Development | Structured Notification Drafting |
| PUF / Hardware-Backed Identity | Roadmap | Selected Microcontroller Hardware |
Architecture & Security
From hardware identity to cloud telemetry: built on row-level tenant isolation and cryptographic verification.
Hardware-Backed Identity & Secure Boot
Hardware Root-of-Trust and secure boot verification on supported microcontrollers.
Low-Footprint Runtime
Modular libraries designed for efficient execution on resource-constrained MCU/MPU hardware.
Multi-Tenant Security Control Plane
Row-level tenant isolation and encrypted data storage architecture.
Platform Capabilities
Combine software component discovery, vulnerability correlation, prioritization, and secure updates in a single platform.
Software Bill of Materials & Vulnerability Correlation
Discovers open-source and commercial dependencies, matching them against the OSV database. Outputs machine-readable SBOMs in SPDX 2.3 and CycloneDX 1.7 formats.
Active Exploitation & Anomaly Observability
Detects active exploitation events from connected field device logs and provides early warning indicators to security operations teams.
Structured Draft Preparation
Converts detected active exploits and severe security incidents into structured notification drafts aligned with ENISA and CSIRT templates, ready for human review.
Signed Firmware & A/B Partition Rollback
Protects operational continuity with cryptographically signed updates, dual partition (A/B) rollback, and canary deployment controls.
Secure Update Workflows
Cryptographically signed updates with A/B partition rollback support to maintain device operational continuity.
Ed25519 or RSA-PSS signed update packages. Devices verify signatures against embedded root public keys before executing updates.
Dual partition layout allows devices to automatically roll back to a known working image if an update fails during boot.
Only modified binary blocks are transmitted, optimizing bandwidth for cellular, 2G, and NB-IoT deployments.
Hardware Regulatory Compliance
How TegmenSoft replaces fragmented manual compliance spreadsheets with an automated, chip-to-cloud security control plane.
| Compliance Domain | Traditional Manual Approach | TegmenSoft Unified Control Plane |
|---|---|---|
| SBOM Management (CycloneDX / SPDX) | Static Excel spreadsheets updated manually per release; outdated immediately upon deployment. | Automated build-time & runtime lockfile parsing with zero server code upload and live OSV correlation. |
| CRA Article 14 Early Warning (<24h) | Emergency manual email exchanges; high risk of missing statutory 24-hour notification deadline. | Pre-structured ENISA Single Reporting Platform (SRP) schema drafting with human-in-the-loop sign-off. |
| Secure Firmware Updates (OTA) | Unsigned HTTP downloads or manual technician on-site visits; vulnerability to bricking. | Cryptographically signed (Ed25519) delta packages with dual-bank A/B partition automated rollback. |
| Technical Documentation (10-Year Retention) | Scattered local drives; difficult audit trail retrieval during market surveillance inspections. | Immutable audit trail with cryptographic component lineage and continuous verification. |
Security Architecture
Row-level tenant isolation, encrypted transit, and cryptographic code verification from device hardware to cloud control plane.
Schedule a 30-minute technical review call with our engineering team to assess your product architecture and potential pilot scope.