Put the security on the device, not just in the documents.

PKI-based cryptography, device identity, and key management built for medical devices with limited connectivity, limited memory, and clearances you cannot afford to disturb.

Features

The cipher is rarely the part that fails.

Documentation proves it. This is the part that does it.

Most cybersecurity work produces evidence about your device. This runs on it. Every unit gets a cryptographic identity it can prove, so the security posture your submission describes is the one running in the field.

Modern ciphers, undone by how the keys are handled

One shared secret across the whole fleet, keys handed around a contract manufacturing floor, no way to rotate anything after the device ships. Key generation, provisioning, rotation, and revocation are handled as one lifecycle instead, from the factory through years of field service.

Validated cryptography, sized for the hardware you shipped

Key generation meets FIPS 140-2 and FIPS 140-3 Level 3. The library runs from constrained ARM microcontrollers up to Intel servers, across Linux and Windows, with bindings for C, C++, C# and Java, so it fits the part you already selected rather than the one it would prefer.

How it runs

Issued at the factory, trusted in the field, maintained for a decade.

Three stages, and the third is the one that decides whether the first two were worth doing. A device cleared this year may still be in service in ten, long after the certificates it shipped with have expired.

  1. Including the ones that never touch your network.

    Connected devices get certificates over the network. Devices built in an offline contract facility are provisioned without one, and devices behind a hospital gateway are provisioned through it. That matters because a disconnected device is still a cyber device to the FDA, and it still has to prove who it is to everything it talks to.

    Provisioning

    DeviceModeIdentity
    NetworkIssued
    OfflineIssued
    GatewayEnrolling
    AgentIssued
    Keys generated to FIPS 140-2 and 140-3 Level 3
  2. A certificate is only worth what it refuses.

    Traffic to your cloud is encrypted and mutually authenticated, and so is the lateral traffic between components inside the device, which is the half that usually ships in the clear because it never leaves the system. Anything without a valid certificate is refused, so a counterfeit accessory or an unauthorized attachment does not get to participate at all.

    Trust zones

    LinkChannel
    Encrypted
    Encrypted
    Encrypted
    Refused
    Refused: no certificate from a trusted authority
  3. Provisioning is a project. The lifecycle is the product.

    Certificates expire, keys need rotating, and a compromised or decommissioned unit needs revoking, on a schedule that has nothing to do with your release cadence. Rotation and revocation run on policy across the fleet without a field visit. The installed base is covered too: a drop-in agent adds the same protection to devices already out there, with no source code changes and no disturbance to the clearances they shipped under.

    Key lifecycle

    ActiveTrusted
    RotatingAutomatic
    Expiring soonQueued
    RevokedBlocked
    Rotation runs on policy, without a field visit

What you get

What ships with your device.

A cryptographic identity per device

Every unit gets its own key pair and certificate rather than a secret shared across the fleet, so a device can prove it is what it claims to be to anything it connects to.

Key and certificate lifecycle management

Generation, provisioning, rotation, and revocation handled as one system, from the factory floor through years of field service, including for devices that were provisioned offline.

A library that fits your hardware

Cross-platform from ARM microcontrollers to Intel servers, on Linux and Windows, with C, C++, C# and Java bindings and a small API for the common cryptographic operations. Built for memory-constrained devices rather than ported down to them.

Evidence for your submission

Authentication, data protection, and secure updatability are three of the cybersecurity duties Section 524B puts on you, and this discharges them with verification and validation documentation your quality system can reference.

Know where you are in 1 hour.

Run the free check or talk to a human. Either way, you’ll get a clearer view of readiness without a paywall or lengthy sales call.

Check readiness