. . . . .

TRUST ORIGIN · MANUFACTURING

Device trust
starts in manufacturing.

Every connected device needs a permanent, globally verifiable identity. Gapfruit makes trusted device identity simple while helping OEMs prepare for emerging cybersecurity regulations.

TALK TO EXPERTS
TALK TO EXPERTS
HOW IT WORKS
HOW IT WORKS
// device_id _verified
TPM
A8:F1:09:3C
gapfruit
Birth Certificate
[ VALID ]
// rooted in hardware . \ . . verifable for life

01

No hardware changes

02

Open TCG standards

03

Seconds to provision

04

Production ready

// INDUSTRY SHIFT

Trust Expectations for Connected Devices Have Never Been Higher.

Connected devices were traditionally trusted implicitly. Physical access, closed networks, and controlled environments were often considered sufficient proof of authenticity. That assumption no longer holds.

Today's connected devices are long-lived digital assets. They are continuously connected, remotely managed, regularly updated, and expected to operate securely for many years. Trust can no longer be assumed. It must be verifiable. Every software update, cloud connection, and digital service depends on knowing exactly which device is communicating. Regulators are now reinforcing this market shift by defining a common cybersecurity baseline for connected devices:

EU Cyber Resilience Act — full conformity required from Dec 2027

US Cyber Trust Mark — expanding security requirements for connected devices

Trusted device identity is becoming the foundation for secure connected devices.

// INDUSTRY SHIFT

Every connected device needs to prove it is genuine.

Connected devices rely on cloud services, software updates, and secure data exchange throughout their lifecycle. A permanent, verifiable identity established during manufacturing ensures genuine devices can be securely authenticated, onboarded, and trusted for years.

What Trusted Device Identity Enables:

[ ]

0 - 1

Zero-Touch Provisioning

Securely onboard devices without manual intervention.

0 - 2

Zero-Trust Transformation

Establish trusted device identities as the foundation for zero-trust security.

0 - 3

Digital Twin Integrity

Reliably bind every physical device to its digital representation.

0 - 4

Lifecycle Authentication

Continuously verify device identity throughout its operational lifetime.

0 - 5

Counterfeit Protection

Detect cloned devices and prevent unauthorized overproduction.

// THE CHALLENGE

B

13 - 37

ANOTHER.OS

Infrastructureis not your business.

Public Key Infrastructure (PKI) is the proven foundation for digital trust, mature, standards-based, and built for exactly this purpose. The challenge isn't PKI itself. It's what it takes to operate the trust infrastructure behind it. Establishing trusted device identities isn't a one-time implementation. It requires operating a trust infrastructure, including PKI, HSMs, secure provisioning, cryptographic key management, high availability, and specialized security expertise, for the entire lifetime of every device you ship.

That operational responsibility turns a sound security architecture into a permanent commitment most OEMs never intended to take on.

// MODE

OPERATING

The question is no longer whether you need a trusted device identity. The question is whether building and operating the required trust infrastructure is really where you want to invest your engineering resources.

// OPERATING SYSTEM

SWI_

0 - 1

Existing hardware

// OEM DEVICE

0 - 2

TPM hardware root of trust

// SECURE KEY

0 - 3

Birth Certificate

// DEVICE IDENTITY

0 - 4

Trusted Device Identity

// DEVICE IDENTITY

// THE SOLUTION

Your Hardware Already Contains the Foundation for Trusted Device Identity

Most modern industrial devices already include a Trusted Platform Module (TPM), a dedicated hardware security chip that provides a hardware root of trust. Gapfruit transforms this existing hardware foundation into a globally verifiable device identity, fully integrated into your manufacturing process. Every device leaves production with a cryptographically verifiable Gapfruit Birth Certificate, without requiring OEMs to build and operate their own HSM/PKI infrastructure.

EXPLORE THE SOLUTION
EXPLORE THE SOLUTION

// THE SOLUTION

Your Hardware Already Contains the Foundation for Trusted Device Identity

Most modern industrial devices already include a Trusted Platform Module (TPM), a dedicated hardware security chip that provides a hardware root of trust. Gapfruit transforms this existing hardware foundation into a globally verifiable device identity, fully integrated into your manufacturing process. Every device leaves production with a cryptographically verifiable Gapfruit Birth Certificate, without requiring OEMs to build and operate their own HSM/PKI infrastructure.

EXPLORE THE SOLUTION
EXPLORE THE SOLUTION

// THE SOLUTION

Your Hardware Already Contains the Foundation for Trusted Device Identity

Most modern industrial devices already include a Trusted Platform Module (TPM), a dedicated hardware security chip that provides a hardware root of trust. Gapfruit transforms this existing hardware foundation into a globally verifiable device identity, fully integrated into your manufacturing process. Every device leaves production with a cryptographically verifiable Gapfruit Birth Certificate, without requiring OEMs to build and operate their own HSM/PKI infrastructure.

EXPLORE THE SOLUTION
EXPLORE THE SOLUTION

// THE SOLUTION

Your Hardware Already Contains the Foundation for Trusted Device Identity

Most modern industrial devices already include a Trusted Platform Module (TPM), a dedicated hardware security chip that provides a hardware root of trust. Gapfruit transforms this existing hardware foundation into a globally verifiable device identity, fully integrated into your manufacturing process. Every device leaves production with a cryptographically verifiable Gapfruit Birth Certificate, without requiring OEMs to build and operate their own HSM/PKI infrastructure.

EXPLORE THE SOLUTION
EXPLORE THE SOLUTION

// BENEFITS

Focus on building products. Not infrastructure.

Gapfruit Birth Certificate Provisioning removes the burden of building and operating trust infrastructure. Instead of investing years into HSM/PKI operations, security infrastructure, and proprietary integrations, OEMs can focus on what differentiates them: building great Hardware. What this means for your business:

WITHOUT GAPFRUIT

// Instead of...

Building and operating your own PKI/HSM infrastructure and certificate lifecycle services.

Spending years integrating infrastructure into manufacturing

Managing cryptographic infrastructure as a long-term operational responsibility

Fighting counterfeit devices and unauthorized production

Being tied to proprietary identity solutions and vendor-specific ecosystems

Chasing evolving cybersecurity regulations as individual requirements

WITH GAPFRUIT

// You can...

Focus engineering resources on building products rather than on infrastructure.

Deploy trusted device identities directly within your existing production process.

Reduce operational complexity and security risk.

Protect your brand with cryptographically verifiable device authenticity.

Build on the globally recognized Trusted Computing Group (TCG) standards and avoid vendor lock-in.

Stay ahead of compliance.

// THE CHALLENGE

B

13 - 37

ANOTHER.OS

Trusted Device Identity Integrated Into Your Manufacturing Process

Gapfruit integrates into your existing manufacturing workflow, provisioning each device with a permanent Birth Certificate anchored in its TPM. Devices leave the factory with a globally verifiable identity, without requiring you to operate your own trust infrastructure.

No hardware changes

Standards-based (TCG)

Seconds to provision

Sequence diagram showing Customer, Gapfruit and Digicert lanes in the Birth Certificate provisioning process

// TECHNICAL DETAILS

Built on Open Standards. Rooted in Hardware Trust.

Gapfruit Birth Certificate Provisioning is built on globally recognized security standards and uses the Trusted Platform Module (TPM) as a hardware root of trust. Through TPM attestation, Gapfruit proves that the private key was generated inside a genuine TPM and never leaves the hardware. The result is a globally verifiable, hardware-based device identity that cannot be copied or manipulated. Built on open TCG standards, the solution also ensures interoperability across hardware vendors without proprietary lock-in.

Standard

Purpose

Trusted Platform Module (TPM 2.0)

Hardware root of trust and secure cryptographic operations

IEEE 802.1AR (IDevID)

Standardized device Birth Certificate

X.509 / PKI

Globally interoperable digital identity infrastructure

Trusted Computing Group (TCG)

Open global industry standards for trusted computing

LEARN MORE
LEARN MORE

// Trust

Trusted by Industry Leaders. Built on Global Standards.

Gapfruit Birth Certificate Provisioning is production-ready, built on global standards, and developed with leading digital trust organizations to deliver open, interoperable device identity.

Developed together with DigiCert

Built with the world's leading provider of Digital Trust and PKI services.

Built on Open Standards

Contributor Member of the Trusted Computing Group (TCG), based on TPM, IEEE 802.1AR (IDevID), and X.509.

Production Ready

Successfully deployed in real manufacturing environments.

Designed for OEM Manufacturing

Built specifically for high-volume device manufacturing and long product lifecycles.

DigiCert
Miromico
Trusted Computing Group
Partner logo
Bechtle

// FAQ

Frequently Asked Questions

[ ]

Why Gapfruit Birth Certificate?

Gapfruit Birth Certificate enables OEMs to establish hardware based trusted device identities without building and operating their own trust infrastructure. Instead of investing in PKI, HSMs, secure key management and long-term operations, OEMs consume trusted device identities as a solution integrated directly into the OEM manufacturing process.

Why not just use serial numbers or MAC addresses?

Serial numbers or MAC addresses can be copied or spoofed. They do not provide sufficient authenticity. While a Gapfruit Birth Certificate can be copied, its private key cannot. This proves a device is genuine.

How is the identity protected from cloning?

The device only receives a Gapfruit Birth Certificate if the private key of the key-pair is securely stored inside the TPM and ensured to never be able to leave it. The resulting identity is cryptographically bound to that specific device, making cloning or impersonation practically infeasible.

Why DigiCert?

Gapfruit Birth Certificate is jointly developed with DigiCert, one of the world's leading providers of Digital Trust. OEMs benefit from proven PKI infrastructure.

Why not build this ourselves?

Issuing certificates is easy; operating secure trust infrastructure for years with PKI, HSMs, key protection, provisioning, lifecycle management, is not. Gapfruit Birth Certificate gives you industry-standard solution without the operational burden.

How long does a typical integration take?

The integration mainly exists of adding the Gapfruit software and device config to the existing boot image which is used during manufacturing. Scoping to pilot and production is fast if common build systems are used.

Does it slow down production?

No manual step is required. Provisioning can run once automatically as part of the initial provisioning. Execution only takes a few seconds.

fork()
. . . . .
UNIX · 1971 · PROCESS CREATION
// DIRECTION
How do you engineer trustworthy devices?
Speak with us to learn how Gapfruit can be integrated into your existing development and production processes.
BOOK A CALL
BOOK A CALL
TECHNICAL PAPERs
TECHNICAL PAPERs
// MODE
// OPERATIING SYSTEM
OPERATING
SWI_