Building the product is the hard part. Securing its connectivity shouldn't be.

The problem we identified

IoT security is a discipline of its own, not something your product team should have to build from scratch.

Built by Ermit

Connectivity, security, and OTA. Integrated. Autonomous. Field-ready.

The Ermit Secure IoT Module handles connectivity security as a dedicated hardware layer so your host device stays simple, your cloud stays yours, and your team stays focused on the product. Device identity and cryptographic secrets are protected by a dedicated hardware secure element, never exposed in software. The module works with your existing cloud infrastructure, manages certificates autonomously, and ensures firmware and data are never lost in the field without locking you into a proprietary platform.

Into the product

Shipping a connected product is the beginning of a security responsibility.

Most companies shipping connected products are not IoT companies. They know their domain, but connectivity security is a different discipline. The predictable result: shared keys, expired certificates, exposed devices. What if all of that complexity lived in a single hardware module instead?

Ermit Secure IoT Module cutaway view: dark enclosure with internal circuit board, coin-cell holder, shielded module, and green status LED.

Three security surfaces

Harware layer

Ermit Secure IoT Module is a dedicated hardware layer that handles connectivity security for connected products. It integrates into a new or existing product design as a separate physical module, sitting between the host device and the cloud over a serial interface.

Identity + certificates

The host communicates using simple commands; everything else, certificate management, mutual TLS authentication, OTA update management, telemetry forwarding, and event logging, is handled entirely by the module. Cloud compatibility covers Azure IoT Hub and AWS IoT Core; the customer retains full ownership and control of their cloud infrastructure.

Storage + runtime

Device identity and cryptographic material are stored in an NXP SE051 secure element, isolated from software. Certificates are provisioned and monitored. Firmware updates are delivered by Ermit. Encrypted SD storage caches update files, telemetry and events during power loss. Exein Runtime provides continuous behavioral analysis. The architecture targets CRA, RED and ETSI EN 303 645 compliance, with built-in documentation evidence.

How it fits into your product.

One interface. Everything else is transparent.

Diagram: your product (host firmware, sensors, local UI) and the Ermit IoT Secure Module (secure element, certificate lifecycle, runtime) linked by a single communication interface.

01

The only integration point is the communication interface between host and module. Security, connectivity, and credential management happen transparently, invisible to your host firmware.

Built for the field, not just for integration.

Built for the field, not just for integration.

03

The module stays updated, certificates don't expire silently, and data is never lost offline. Your product remains secure for its entire lifecycle - not just at shipping.

Compliance is built in and demonstrable.

Compliance is built in and demonstrable.

02

CRA, RED, and ETSI EN 303 645 alignment is not an architectural afterthought, it is embedded in the design. The documentation trail is already there.

Your cloud stays yours.

Diagram: Ermit Secure IoT module (secure element, OTA engine, runtime) connected via standard API to your cloud (IoT backend, certificate lifecycle, business app, infrastructure).

04

The module works with your existing cloud infrastructure. No proprietary platform required, no vendor lock-in.

How it fits into your product.

Three surfaces. One secure lifecycle.
Legend: red = Provided by Ermit, gray = Your existing components Architecture diagram - Three surfaces: Your Product, Companion App, Ermit Cloud

Hardware foundation, built for field deployment.

The module stays updated, certificates don't expire silently, and data is never lost offline. Your product remains secure for its entire lifecycle, not just at shipping.process, so you have one team accountable for the whole product.

Hardware-protected identity and autonomous certificates.

Every private key is generated on-device and never leaves the secure element. Authentication towards cloud services happens through mutual TLS, with certificates managed autonomously by the module - no manual provisioning, no shared secrets across devices.

Resilience and extensibility.

An encrypted SD card provides local storage for firmware artifacts and resources, decoupling cloud availability from field operations. Combined with store-and-forward buffering, the module ensures that data and updates are never lost during connectivity gaps - everything queues locally and syncs when the network is available. An independent RTC with battery backup maintains accurate timekeeping across power cycles, providing a trusted time source for certificate validation and log timestamping - regardless of network state. The module also exposes expansion connectors, allowing additional field buses and interfaces - Ethernet, LTE, Modbus, CAN, RS-485 - to be added as plug-in boards without redesigning the base hardware.

Artifact Deployment Portal and IoT Secure Module Management Portal

The Artifact Deployment Portal and IoT Secure Module Management Portal form the cloud backbone of the system. The first handles packaging, versioning, and distribution of firmware artifacts and resource files to your fleet - with release management, rollout policies, and deployment tracking built in. The second maintains a dedicated management channel to every deployed module, used exclusively for autonomous module updates, security patches, and platform-level health monitoring, completely separate from your application data. Both portals can be operated by Ermit as a managed service, or deployed and managed directly within your own infrastructure.

Companion App SDK

The Companion App SDK provides a ready-to-integrate mobile library for iOS and Android, covering device onboarding, Wi-Fi credential provisioning, and field diagnostics - available as an SDK to embed directly into your own app.

Integrated Exein Runtime

Integrated Exein Runtime runs directly on the module, providing continuous behavioral monitoring, anomaly detection, and incident reporting - adding an active security layer on top of the architectural protections.

FAQ

Your questions. Straight answers.

  • The module is compact and designed for straightforward mechanical and electrical integration - available with both board-to-board and field-wired interfaces. If your board already exposes a 3.3V–12V power rail and a TTL serial line, no PCB redesign is required. It carries CE and RoHS certification, reducing your compliance workload. Technical documentation and a reference design are available to accelerate integration.

Compliance, backed by evidence

Reduce your compliance surface and documentation effort with an architecture built to meet requirements by design.

Hardware foundation, built for field deployment.

Integrating the Ermit Secure IoT Module reduces the compliance surface of your host device by delegating security-critical functions, hardware identity, certificate management, encrypted communications, and verified OTA, to a dedicated hardened component. This means your certification effort focuses on what your product does, not on rebuilding a security infrastructure. The architectural choices that satisfy CRA, RED, ETSI EN 303 645, and IEC 62443-4-2 are already in place, documented, traceable, and designed for assessment support from day one, so you have one team accountable for the whole product.

Proof Matrix - compliance coverage across CRA, RED, ETSI EN 303 645, IEC 62443-4-2
EU Cyber Resilience Act emblem with CRA mark

Cyber Resilient Act

Built for the CRA. From day one.

The Secure IoT Module is what we built when we decided to solve connectivity security once, properly. Most connected products treat security as a late-stage integration problem. We knew that wasn't right, so we built a module that makes it a non-issue from the start, for any product that uses it.

Application of Article 14

Notification of Vulnerabilities & incidents. Applicable on product placed on the market before December 11th 2027

Full Application of CRA

Applicable on new product placed on the market from December 11th 2027, or Product with substantial modification & placed on the market before.

End of Transition Period

Product cyber certified (EU type) before CRA must be re-certified (ex. CE RED)*

Source: Article 69 CRA

*except if any regulation voted or expiration before this deadline