Don't let your device be the way in

Every connected device you sell is a door into your network and your customers'. Before you build a hundred, I check what it carries and how it communicates, and tell you what to fix first.

3D ESP32-EVB board with three protection layers above its ESP32: verified boot, encrypted flash and certificate

What I work with

  • Linux
  • Python
  • Docker
  • ESP32 · Espressif

What I do

01

What it carries

Passwords and keys written into the firmware, open services, libraries with known flaws and default settings.

02

How it talks

Whether what it sends is encrypted and whether the device and the server really recognise each other.

03

How it updates

That nobody can use the update channel to slip another program onto it.

04

Where the data lands

I review the Linux server or gateway that receives the information.

05

A report you can read

Each issue with its risk, how to check it and how to fix it, ordered by urgency.

Animation: verified boot, encrypted flash, eFuses, an mTLS channel rejecting a client without a certificate, a signed OTA rejecting an old version, and a fleet dashboard with SBOM, CVE and standards

Defence in depth, layer by layer

Encrypting the connection isn't enough. A robust device verifies its own firmware at boot, protects what it stores, only talks to peers holding a certificate and refuses unsigned updates and old versions. And you can prove it.

  • Secure Boot v2 and encrypted flash (AES-XTS) with burnt eFuses and JTAG disabled
  • mTLS with one X.509 certificate per device, and signed OTA with anti-rollback
  • CycloneDX SBOM with CVE tracking, plus evidence for ETSI EN 303 645, IEC 62443-4-2 and the CRA

How we work

Four steps and no surprises: at every point you know what comes next, what you get and what it costs.

  1. Let's talk

    You tell me what you need, what you already have and what worries you. No commitment, no jargon.

    You get: An honest view on whether it is feasible and where I would start.

  2. I propose a plan

    In writing: what I will do, what you get, in what order and what it costs. Before starting.

    You get: A fixed proposal with scope, phases and price.

  3. We move in milestones

    You see and test partial deliveries. No black boxes opened at the end.

    You get: Prototypes and versions you can hold and test.

  4. I leave it running

    Files, documentation and support during commissioning. And I am still around afterwards.

    You get: Source files, documentation and someone to call.

Questions I often get

When does it make sense?

Before mass production or installation. Fixing it in the design costs far less than fixing it in the field.

Is it related to EU regulation?

Yes. The Cyber Resilience Act sets security requirements for connected products, and a prior review tells you where you stand.

Do you fix it too?

If you want, yes. And if you would rather your team did it, the report has enough detail for that.

Shall we talk?

Tell me where you are and what worries you. You will hear back from me, not from an automated form, with how I would approach it and, if it fits, a fixed quote.

I can also help with