top of page
LAAVAT — PKI and signing platform for CRA-ready embedded devices

PKI & Signing Platform for CRA-Ready Devices

EU-hosted · Crypto-agile · PQC-ready

 

We run your PKI, sign your firmware across your chipsets, and issue every device a trusted identity — all as a managed service. Secure boot, signed updates and strong device identity are how CRA Annex I gets met; LAAVAT is the backbone underneath all three.

Trusted by industry leaders

Foxconn — LAAVAT customer
HERE — LAAVAT customer
KONE — LAAVAT customer
Treon — LAAVAT customer
Vaisala — LAAVAT customer
Kemppi — LAAVAT customer
customers

One platform for PKI, signing and encryption

What you deliver to devices — secure boot, secure updates and device identity — rests on three platform capabilities: PKI (CAs and hierarchies, certificate lifecycle, EST and ACME enrolment), code signing (RAUC, Mender, HAB/AHAB, Bootgen, MCUboot, OP-TEE, FIT, Windows, OCI) and encryption (AES-GCM-256 image encryption, key escrow and export).

Underneath: every key in FIPS-validated HSMs, compliance-ready for CRA, NIS2 and IEC 62443, and fully auditable with approvals and RBAC. Integrate via REST or EST; authenticate with Entra ID or Google.

The LAAVAT platform at a glance: secure boot, secure updates and device identity delivered by PKI, code signing and encryption, built on HSM-protected keys

Key Features at a Glance

Three foundations every CRA-ready device needs

Secure by design

01 Secure boot — Only verified firmware runs, anchored in a hardware root of trust with each boot stage authenticating the next.

02 Secure firmware updates — Signed, optionally encrypted update bundles delivered safely over the air, for the product's whole lifetime.

03 Strong device identity — Tamper-resistant per-device certificates for mutual TLS, attestation and clean factory onboarding.

 

See how LAAVAT delivers all three

All three rest on one PKI, signing and encryption backbone. LAAVAT provides it as a managed service: we run your PKI, sign your firmware across your chipsets and issue each device a trusted identity — with HSM-protected keys, approval workflows and a full audit trail, mapped to CRA, RED, NIS2 and IEC 62443-4-1/4-2.

Integrate in a day, not a quarter

Built for builders

Engineering teams sign from their pipeline the same day: REST and EST interfaces, ready-made clients for CI/CD and provisioning stations, a Yocto recipe, and reference flows for MCUboot, HAB/AHAB, FIT, RAUC, Mender and OCI.

 

Security and compliance teams get HSM-backed keys, quorum approvals and an immutable, exportable audit trail — the evidence CRA, RED, NIS2 and IEC 62443 conformity assessments ask for, without building a signing service.

 

Product and manufacturing teams get one product per device family: signing operations, approval rules and access groups configured once and used by every pipeline and every production line.

What Our Customers Say

KONE logo
“Securing our connected products is key in making the world's cities smarter and more sustainable places to live. The LAAVAT solution for centrally managing cryptographic keys used for digital signing and encryption plays an important role in ensuring trust in KONE’s software supply chain. The LAAVAT solution also helps us to adhere to the standards and regulations on cybersecurity, such as IEC 62443.”
Jussi Valkiainen, Head of Product and Application Security
Embedded device manufacturing

Why Choose LAAVAT

Built for silicon

Silicon-specific secure-boot artifact signing, not just generic digest signing: NXP HAB and AHAB, Xilinx Bootgen, TI, and the MCU ecosystems on MCUboot — STM32, Nordic, Renesas, Microchip — plus FIT, RAUC, Mender, OP-TEE and OCI. One platform, every format your products use.

Full key ownership

Export your keys any time. No vendor lock-in. Run as EU-hosted SaaS, with your own HSM in your own AWS account, or on-premises for sovereignty-critical deployments. Business continuity is designed in, independent of LAAVAT.

Run as a service

HSM-backed, governed and audited, with no infrastructure for you to operate. Every CA and signing key is generated and used inside FIPS-validated AWS CloudHSM. SSO, group-based signing policies and quorum approvals come standard. Built for crypto-agility — post-quantum ready as NIST-standardized algorithms roll out on our HSM infrastructure.

The CRA compliance clock is running

Full obligations — secure by design, conformity assessment, CE marking — apply from 11 December 2027, with penalties up to €15M or 2.5% of global turnover. Devices designed now ship into that world, and secure boot and signing infrastructure takes most manufacturers 6–18 months to build. See how the requirements map to secure boot, signed updates and device identity in our CRA compliance guide.

Start your LAAVAT evaluation

Try it before you commit

bottom of page