Security evaluation
We carry out security evaluations of chip-based systems, including authorized penetration testing, under the system owner’s written authorization and an agreed scope. Every evaluation ends with a written report and a remediation plan, followed by a retest.
For the steps of an evaluation and who signs off each one, see How we work.
What we evaluate
- Chip firmware and its update path
- Authentication between a chip and its host
- Key provisioning and key lifecycle
- Debug and test interfaces
- Resistance to physical attacks, including side-channel and fault-injection testing
How deep we go
We agree the depth with you when we agree the scope. A design review and a full evaluation both end with a retest.
- Design review
- We review your design documents and source code before silicon or firmware is final.
- Full evaluation
- We test samples of the system hands-on, including authorized penetration testing, under the system owner’s written authorization and within the agreed scope.
- Retest
- After either one, we retest the fixes and confirm which findings are closed. The retest runs under the original written authorization, or a renewed one if the agreed test window has closed.
What you receive
- A written report setting out each finding with its evidence, impact and severity
- A remediation plan, with the fixes ranked by risk
- Retest results showing which findings are closed
- Written confirmation that your samples, firmware and data have been returned or destroyed
For how we handle your samples, firmware and data, see Confidential handling.
Boundaries
We test only systems you own or are authorized to have tested, within a scope agreed in advance, and only after the system owner has authorized the work in writing.
- Who signs
- If you are commissioning the work for the owner, the owner signs the authorization.
- Only the agreed targets
- We test the agreed targets hands-on, under the agreed rules, and nothing outside them.
- Stop and contact
- If testing could affect safety, or could reach anything outside the agreed scope, we stop and contact you before going further.
- Work we decline
- Requests to circumvent another party’s protections without that party’s authorization. Owning a device does not by itself let you authorize us to circumvent protections that belong to someone else, such as a supplier’s or manufacturer’s authentication. For that we need that party’s written authorization.
Start an evaluation
Email us what the system is, who owns it, and whether the owner has authorized testing.