Custom Security & Embedded Development
Embedded security services for IoT and connected-device manufacturers - we design and build secure device, firmware, and backend systems tailored to your product, including IoT security architecture and secure firmware development.
Who This Is For
Built for IoT and connected hardware manufacturers - from early-stage teams validating a prototype to established manufacturers preparing for production. Most engagements start between early prototyping and preparation for manufacturing.
Custom Development
End-to-end development of security-critical features integrated into your product (not a standalone platform).
- Feature development integrated into your existing product and codebase
- Delivered as source code with full ownership, not a hosted dependency
- Fits into your existing engineering process, not a parallel platform
Architecture & Design
Threat modeling, security architecture, and system design across device, firmware, and backend.
- Threat modeling and risk analysis for your specific product
- Security architecture spanning device, firmware, and backend
- Design decisions mapped to CRA essential requirements
Firmware & Embedded
Secure firmware, device integration, and low-level development tailored to your hardware.
- STM32 and Nordic nRF microcontrollers, RTOS-based systems (Zephyr, FreeRTOS)
- Hardware root of trust, secure boot, and secure key storage
- Reliable, field-tested OTA firmware update mechanisms
Backend & Infrastructure
Backend components for device provisioning, device authentication, secure communication, and OTA firmware updates.
- Device provisioning and identity management
- Firmware signing and update workflows
- Own platform in .NET / Microsoft Azure, or integration with your existing backend
Provisioning & Security Backend
Device security cannot exist in isolation - it requires supporting backend systems for manufacturing, provisioning, firmware signing, and secure updates. We provide a production-ready backend platform, implemented in .NET and designed for Microsoft Azure, delivered with source code and adapted to your infrastructure.
This lets you bootstrap a secure device ecosystem without building backend infrastructure from scratch - a critical part of aligning your systems with modern security requirements such as the Cyber Resilience Act (CRA).
Device Provisioning
Secure identity assignment and provisioning flows integrated into your manufacturing process.
Firmware Signing & Updates
Cryptographic firmware signing and OTA update workflows for secure field deployments.
Device Lifecycle Management
Registration, onboarding, and end-of-life handling across your entire device fleet.
Manufacturing Integration
Backend integration with production lines and manufacturing processes.
Let's scope your device backend
Tell us what you're building, and we'll scope the provisioning, firmware signing, and backend architecture that fits your product and timeline.
Supporting Offerings
Integration Libraries
Ready-to-use libraries that plug directly into your existing codebase.
CRA Documentation Support
Technical files and documentation aligned with CRA requirements.
Delivery Package & Handover
Complete handover with full ownership of source code.
Project Investment
A rough sense of scope before we talk. Every engagement is scoped individually during Discovery - these ranges reflect what past projects of each type have typically cost.
$5K – $10K
Focused Component
A specific firmware feature, security review, or backend integration scoped to a single, well-defined piece of work.
$10K – $50K
Single-Product Security Build
Security architecture, firmware, and backend work for one product line - the most common engagement.
Custom
Larger or Non-Standard Scope
Full-stack device security architecture, firmware, backend, and a complete CRA-ready documentation package - or something that doesn't fit a fixed range. Tell us what you're building.
Contact us →These are indicative ranges, not a quote - the actual cost depends on scope, timeline, and existing infrastructure, confirmed after a short Discovery call.
How We Work
Discovery
Requirements, scope, and threat surface
Architecture
Security design across device and backend
Development
Firmware, backend, and integration work
Delivery
Source code, documentation, and handover
Support*
Ongoing support, under separate agreement
Discovery
Requirements, scope, and threat surface
Architecture
Security design across device and backend
Development
Firmware, backend, and integration work
Delivery
Source code, documentation, and handover
Support*
Ongoing support, under separate agreement
Engagement Model
We operate as an engineering contractor delivering custom security systems integrated into your product. No SaaS, platform services, hosting, or ongoing lifecycle management are included unless agreed separately.
What You Get
Core Deliverables
- ✔ Production-ready source code
- ✔ Build & deployment instructions
- ✔ Complete handover and ownership (upon payment)
CRA-Ready Documentation
- ✔ Technical documentation (architecture, flows)
- ✔ SBOM (Software Bill of Materials)
- ✔ Security architecture documentation (device identity, provisioning, authentication, communication)
- ✔ Threat model and risk analysis
- ✔ Secure firmware update design
- ✔ Provisioning and manufacturing flows documentation
Have a project in mind?
Tell us about your device, product, or idea - we'll help you design the right solution.
Frequently Asked Questions
Practical answers about how we work and what to expect. If your question is not here, ask us directly.
Do you deliver source code, or is this a platform we depend on?
Source code. We build custom firmware, backend, and application components that become part of your product. You get full ownership and handover upon payment - there's no ongoing platform dependency unless you ask for one.
Can you work with our existing firmware or backend, or does everything start from scratch?
Both. We regularly integrate with an existing codebase and infrastructure - adapting protocols, architecture, and security mechanisms to what you already have. A from-scratch build is only needed when there's nothing to build on.
What documentation do we get for CRA purposes?
Technical documentation, an SBOM, security architecture documentation, a threat model and risk analysis, and documentation of your provisioning and firmware update design - the artifacts CRA conformity assessment and technical files require.
Do you provide ongoing support after delivery?
By default, engagement ends at handover. Ongoing support, hosting, or lifecycle management can be scoped as a separate agreement if you need it - we don't bundle it in by default so you're not paying for something you may not want.
How long does a typical project take?
It depends on scope - a focused firmware or backend component can take a few weeks; a full device security architecture with documentation typically takes longer. Discovery is where we scope the actual timeline for your product.
We're still at idea/prototype stage - is it too early to talk to you?
No. Most engagements start between early prototyping and preparation for manufacturing, because that's when security architecture decisions are cheapest to get right and most expensive to retrofit later.
Check your CRA readiness in 20-35 minutes
Our free readiness check guides IoT manufacturers through 56 questions across 9 domains and generates a prioritised compliance action list tailored to your answers — no account required.
Start the CRA Readiness Check →