Platforms
- Nordic nRF series SoC
- STM32 microcontrollers
How we work
Standards for firmware, workflow from requirements to delivery, and how we integrate with your stack.
We follow a consistent engineering standard to ensure scalability, maintainability, and production-grade security.
Bare-metal projects are generally not a good fit. We recommend introducing an RTOS to enable proper system structure and security mechanisms.
These requirements ensure that security mechanisms can be properly implemented, audited, and maintained in production systems.
Expert engineering & security integration
We define the project goals and constraints - a clear description of the expected outcome. At this stage we refine requirements together and identify key technical decisions.
We analyze realistic attack vectors such as firmware extraction, device cloning, debug access, and backend impersonation. This defines the security scope and priorities of the system.
Based on the threat model, we design the device security architecture - including identity, provisioning, authentication, firmware updates, and communication.
We produce a detailed specification describing system behavior, interfaces, protocols, and security mechanisms. This document becomes the implementation baseline.
The specification is reviewed with the client and refined as needed. It serves as the agreed foundation for development.
We estimate timeline and budget based on the approved specification. Development begins after alignment.
Implementation is carried out according to the specification, with continuous internal testing. Deliverables may include firmware, tools, and supporting services.
The client validates the solution in the real product environment. Final adjustments and integration fixes are completed at this stage.
After all issues are resolved, the project is finalized and delivered, including updated documentation reflecting the final implementation.
A secure device lifecycle requires supporting backend systems for manufacturing, provisioning, firmware signing, and updates.
We can integrate our firmware and security architecture with your existing backend, adapting protocols and flows to your infrastructure.
Alternatively, we can provide our own backend platform, delivered with source code and tailored to your project requirements.
Our platform is implemented in .NET and designed for deployment on Microsoft Azure, supporting device provisioning, firmware signing, identity management, and lifecycle operations.
Connected devices typically require companion applications for configuration, testing, and daily operation.
We design communication protocols between devices and applications (BLE, USB, or custom transports) with security and reliability in mind.
We can also deliver reference mobile or desktop applications that implement these protocols and demonstrate full device interaction.
We also provide dedicated debugging and testing tools that allow engineers to inspect device behavior, validate communication flows, and troubleshoot issues during development and production.
These applications and tools can be used as a foundation for your own product development, reducing time to market and ensuring correct protocol implementation.
Practical questions about how our engineering process works.
After. Estimation happens once the System Specification is reviewed and approved - Project Estimation is step 6 of our workflow, following Requirements Definition, Threat Modeling, Security Architecture, Specification, and Specification Review. We estimate against an agreed specification, not a rough idea.
Depends on scope, defined at the Requirements Definition stage. Development deliverables can include full firmware, targeted security components integrated into your existing codebase, or both, along with supporting tools and services.
Both. Adding security to an existing embedded system is one of the most common reasons clients engage us - not just greenfield designs.
Almost always an early architectural decision, not an implementation bug: no strong device identity from the start, weak or missing provisioning during manufacturing, secrets stored in firmware or reachable via debug interfaces, or no secure update mechanism. These are cheap to get right early and expensive to fix once a fleet is already deployed.
Most of our projects are delivered under NDA. Confidentiality terms are part of scoping a project, typically agreed before the Requirements Definition stage begins.
We approach every project as a complete embedded and IoT device ecosystem - combining firmware, security architecture, backend integration, and companion applications into a cohesive system.
This ensures that devices are not only functional, but secure, verifiable, and maintainable throughout their entire lifecycle.
Such an approach also helps align device architectures with modern regulatory expectations, including frameworks such as the Cyber Resilience Act (CRA).
See how this approach translates into a project on the Services page.