Axowl.com
000
%

No Keys. Nothing to Steal.

Roost is Axowl's hardware trust root for networks that never touch the cloud. Three independent chips, each regenerating its own key from the silicon itself, sign every privileged action as a 2-of-3 quorum. Keys are never stored, never exported, never backed up — there is nothing for an insider, a stolen server, or a compromised vendor to take.

Where Closed Networks & Self-Hosted breaks today

Stored keys are stolen keys

Every HSM, TPM and key vault stores a secret somewhere — battery-backed RAM, fuses, an encrypted file. Backups, decommissioned hardware and privileged admins all become extraction paths. One extracted key silently invalidates every signature it ever made.

0 stored keys — Roost stores no key. Each chip regenerates it from its physical fingerprint at boot

Single-vendor silicon, single point of trust

A closed network that trusts one chip vendor inherits that vendor's firmware, its backdoors and its supply chain. Sovereign deployments cannot audit a black box, and a rack HSM is exactly that.

2-of-3 — quorum across chips from different vendors, including an auditable FPGA root with open RTL

Cloud-tethered identity in an air-gapped plant

Identity and audit products assume an internet connection to issue tokens, rotate keys and ship logs. Plants, ships, defense sites and hospitals that must stay offline end up with unsigned local logs and shared passwords.

0 outbound — connections required. Sealed chains leave the site on your schedule, by diode or by hand

Three patents, deployed against this industry's threat model

Each of Axowl's three filed patents maps to a specific structural failure mode in Closed Networks & Self-Hosted. Together they form a single, end-to-end defense.

Hierarchical Distributed Trust Fabric — Three silicon roots, one quorum, no master key

Each chip inside Roost derives its key from a Physical Unclonable Function — the microscopic manufacturing variation of that exact die. Two NXP secure MCUs and one Artix-7 FPGA running Axowl's own RTL sign independently; the box accepts a link only when at least two agree. Pull a chip and the chain continues. Swap one in and it must be enrolled by a person before it counts. No chip, no admin and no vendor ever holds a key that opens the whole box.

Transition-Sealed Integrity System — Every action becomes a link nobody can rewrite

Each signature includes the previous link's hash and a hardware counter that only counts up. Replaying an old command fails because its counter has passed. Editing a record breaks every link after it. The chain can sit on an isolated network for months and still prove, on export, exactly what happened and in what order.

Pre-grant LLM Conflict Verification — Dangerous combinations are refused before they exist

Roost enforces Axowl's permission gate at the hardware boundary. A drone command into a forbidden zone, a robot arm move while a human is in the cell, or a privileged database change without an approval is not logged as a violation after the fact — it is never signed, so it never executes.

Deployment that fits the threat model

Roost is the on-premises form of the Iron tier: the same PUF root, HMAC chain and quorum that Axowl runs on cloud FPGAs, packaged for sites that cannot depend on any external service. Nothing leaves the network unless you carry it out.

Recommended tier: T3 · Iron · On-prem

Deployment path: Roost Box → Roost Rack (1U/2U) → Roost Card (PCIe)

Operational detail: Box — palm-sized aluminium unit, Ethernet and power, sits on a desk or a shelf. First deployments and edge sites.
Rack — the same board set in a 1U or 2U chassis with tamper seals and lid-open detection for server rooms.
Card — PCIe form for fleets, inside the customer's own servers.
All three run identical firmware and speak the same protocol; a self-hosted Axowl instance points at the box the way it points at a cloud FPGA today.

Three concrete deployments

Drones & UAV fleets

The ground station holds the Roost. Every takeoff, waypoint and payload command is checked against policy and signed by the quorum before it leaves the radio. Revoke the operator or the AI agent and the aircraft lands itself; a replayed or forged command never gets airborne.

Factory & warehouse robots

AMRs and robot arms execute only quorum-signed instructions, so an action-level authorization exists for every movement. The sealed chain is the evidence the EU Machinery Regulation (2027) and ISO 10218:2025 ask for after an incident — who authorized what, in which order, unaltered.

Humanoid & remote teleoperation

Operators take control of a humanoid through an Axowl badge, and the whole session — video, commands, hand-overs — is sealed as one chain. The same record doubles as provenance for the training data that session produces.

Air-gapped plants & OT networks

Power, water, pharma and semiconductor sites run Roost as the notary inside the closed network. PLC changes, recipe edits and maintenance overrides are signed locally; the chain is exported through a data diode or carried out on schedule for IEC 62443 and 21 CFR Part 11 audits.

Defense & government sovereign sites

No cloud, no vendor call-home, no stored key to seize. The FPGA root ships with open RTL that a national lab can audit line by line, and the quorum spans chips from different vendors so no single supplier can compromise the site.

Banks & core systems on-premises

Privileged database changes, batch releases and admin logins on the core banking network are signed by Roost, producing logs that a root DBA cannot alter. SOX and local banking regulators receive a chain, not a spreadsheet.

Hospitals & medical devices

Infusion pumps, surgical robots and EMR servers on the hospital network receive device identities anchored in Roost. Access to patient data and device configuration changes carry a hardware signature that satisfies HIPAA and IEC 81001-5-1 logging without an internet link.

Automotive & test benches

ECU test rigs and end-of-line stations sign every calibration and test result at the bench. ISO/SAE 21434 and UNECE R155 evidence is produced as a by-product of running the line, not reconstructed later.

Versus what's deployed today

Today — Rack HSM / cloud KMS

Stores the key and defends it with a battery, a tamper mesh and a vendor's word. Needs the cloud or a licence server to stay useful. One vendor, one silicon, one key — extract it once and everything it signed is in doubt.

With DPSM — Axowl DPSM

Nothing stored, so nothing to extract. Three roots from different silicon, two must agree. Open RTL on the FPGA root. Works with zero outbound connections and exports a chain that proves its own order. Same protocol from a desk box to a PCIe card.

Standards & regulatory frameworks aligned

  • FIPS 140-3 (planned)
  • IEC 62443-3-3 SL3
  • EU Machinery Regulation 2023/1230 (Jan 2027)
  • EU Cyber Resilience Act (2027)
  • ISO 10218:2025
  • NIST SP 800-82
  • EU AI Act Article 12 (logging)