What we build
IoT & Embedded Security Expertise
We combine deep embedded engineering with real-world experience building secure, production devices.
Embedded Platforms & Firmware
We build production firmware for IoT and hardware manufacturers on production-grade microcontroller platforms and real-time operating systems, primarily in C++ with C only where the platform requires it. Bare-metal projects are generally not a good fit - we recommend introducing an RTOS to enable proper system structure and the security mechanisms that follow from it.
- STM32 and Nordic nRF microcontrollers
- RTOS-based systems (Zephyr, FreeRTOS)
- Custom communication protocols
- Industrial and hardware interfaces (RS-485, CAN, UART, SPI, I2C)
We design firmware for reliability, determinism, and long-term maintainability in production environments.
Device Security & Authentication
Security has to be designed into the system from the beginning - it can't be reliably added later. We start by threat modeling the realistic ways a device can be attacked - firmware extraction, device cloning, debug access, backend impersonation - and build device identity, secure boot, key storage, and provisioning around those risks from day one for every product we take on.
- Hardware root of trust and secure boot
- Secure key storage and provisioning
- Device identity, attestation, and authentication
- FIDO2 / passkey-based authentication systems
- Public Key Infrastructure (PKI) and certificate workflows
We design security mechanisms that operate within real hardware constraints while meeting production requirements.
Related reading: IoT Threat Modeling Guide · What Is Secure Boot · Device Identity in IoT
Connected Systems, IoT & Device Security
Security decisions that seem fine during prototyping get expensive to fix once a fleet is in the field. We design onboarding, firmware updates, and lifecycle management for IoT and hardware manufacturers as part of the same security architecture as the device itself - not bolted on after deployment - because a missing update mechanism turns a single vulnerability into a permanent one.
- Cloud-connected embedded devices
- Secure device onboarding and provisioning
- OTA firmware updates and lifecycle management
- Device fleets and large-scale deployments
- Industrial and infrastructure monitoring systems
Our focus is end-to-end device ecosystems - not isolated firmware components.
Related reading: Secure OTA Updates for IoT Devices
Selected Experience
Platanor's engineering is led by Denys Zaliznyak, Co-founder & CTO, with 25+ years in software development focused on cybersecurity and prior work co-founding products in FIDO-based authentication and secure device provisioning. Most projects are delivered under NDA, but the team has extensive experience building production systems including:
Industrial PLC-class controller - real-time industrial device with secure communication and hierarchical device management
Hardware FIDO security key - embedded authenticator with secure key storage and cryptographic operations
E-ink embedded device - low-power system with optimized firmware and reliable update mechanisms
Secure authentication ecosystem - end-to-end system including devices, backend, and identity infrastructure
Custom encrypted communication protocols - secure protocols for constrained embedded environments (BLE, USB, RS-232/485, WebSockets)
Let's talk about your device
Tell us what you're building, and we'll show you exactly how this expertise applies to your product and timeline.