Hardware security

Keys that never leave the silicon

We're building a post-quantum signing device and the lab to break it. Secrets are generated, stored and used inside tamper-resistant hardware, and they stay there.

Components

What's inside the device

The signing device is in prototype. Everything below describes the design we're building and testing, and will change as lab results come in.

Certified secure element

Keys live in a secure element evaluated to Common Criteria EAL5+ or higher, with its own protected memory and crypto accelerators.

Post-quantum signing

ML-DSA and SLH-DSA run on the device alongside Ed25519, so hybrid signatures never require exporting a key to a phone or computer.

Auditable entropy

A hardware random source with startup and continuous health tests per NIST SP 800-90B. If randomness degrades, the device refuses to generate keys.

Active tamper response

Mesh, light and voltage sensors detect opening or probing and erase key material within milliseconds.

Measured boot, open firmware

Each boot stage checks the next against a hybrid-signed hash. Firmware source is public, and builds are reproducible so you can confirm what's running.

Air-gapped transport

Transactions move by QR code, never USB or Bluetooth. The device shows exactly what you're signing on its own screen before you approve.

Attack lab

We break our own hardware first

A device has to keep its secrets with an attacker holding it, measuring it and deliberately corrupting it. Each prototype faces the battery below before it moves to the next stage.

AttackHow it worksOur countermeasure
Simple and differential power analysisRecover keys from tiny variations in power draw while signingMasked implementations, randomized execution order, on-chip regulation
Electromagnetic analysisSame idea, using a probe near the chip instead of a power traceShielding, masking and leakage testing with TVLA statistics
Timing attacksInfer secrets from how long operations takeConstant-time code verified by tooling and measurement
Voltage and clock glitchingCorrupt a single instruction to skip a check or leak a valueRedundant computation, verify-after-sign, glitch detectors
Laser fault injectionFlip bits in a decapsulated chip with focused lightSecure element light sensors and error-detecting logic
Supply-chain tamperingSwap or modify parts before the device reaches youDevice attestation keys, tamper-evident packaging, genuineness check at first boot
Development stages

From prototype to production

Hardware can't be patched as easily as software, so each gate is strict. A device that fails a gate goes back a stage.

Prototype

Development boards with off-the-shelf secure elements to validate the architecture.

Lab attack

Full side-channel and fault-injection battery run in-house.

External evaluation

An accredited lab repeats and extends our attacks independently.

Pilot batch

A small run for security researchers and early testers, with a hardware bug bounty.

Production

Certified manufacturing with per-device attestation keys and tracked supply chain.

Follow the hardware from prototype to your hands

Milestones for the device are laid out in the roadmap, year by year.