Certified secure element
Keys live in a secure element evaluated to Common Criteria EAL5+ or higher, with its own protected memory and crypto accelerators.
We're building a post-quantum signing device and the lab to break it. Secrets are generated, stored and used inside tamper-resistant hardware, and they stay there.
The signing device is in prototype. Everything below describes the design we're building and testing, and will change as lab results come in.
Keys live in a secure element evaluated to Common Criteria EAL5+ or higher, with its own protected memory and crypto accelerators.
ML-DSA and SLH-DSA run on the device alongside Ed25519, so hybrid signatures never require exporting a key to a phone or computer.
A hardware random source with startup and continuous health tests per NIST SP 800-90B. If randomness degrades, the device refuses to generate keys.
Mesh, light and voltage sensors detect opening or probing and erase key material within milliseconds.
Each boot stage checks the next against a hybrid-signed hash. Firmware source is public, and builds are reproducible so you can confirm what's running.
Transactions move by QR code, never USB or Bluetooth. The device shows exactly what you're signing on its own screen before you approve.
A device has to keep its secrets with an attacker holding it, measuring it and deliberately corrupting it. Each prototype faces the battery below before it moves to the next stage.
| Attack | How it works | Our countermeasure |
|---|---|---|
| Simple and differential power analysis | Recover keys from tiny variations in power draw while signing | Masked implementations, randomized execution order, on-chip regulation |
| Electromagnetic analysis | Same idea, using a probe near the chip instead of a power trace | Shielding, masking and leakage testing with TVLA statistics |
| Timing attacks | Infer secrets from how long operations take | Constant-time code verified by tooling and measurement |
| Voltage and clock glitching | Corrupt a single instruction to skip a check or leak a value | Redundant computation, verify-after-sign, glitch detectors |
| Laser fault injection | Flip bits in a decapsulated chip with focused light | Secure element light sensors and error-detecting logic |
| Supply-chain tampering | Swap or modify parts before the device reaches you | Device attestation keys, tamper-evident packaging, genuineness check at first boot |
Hardware can't be patched as easily as software, so each gate is strict. A device that fails a gate goes back a stage.
Development boards with off-the-shelf secure elements to validate the architecture.
Full side-channel and fault-injection battery run in-house.
An accredited lab repeats and extends our attacks independently.
A small run for security researchers and early testers, with a hardware bug bounty.
Certified manufacturing with per-device attestation keys and tracked supply chain.