Many manufacturers invest substantial budgets in securing their application software. But the actual programming process — the moment firmware and keys are physically flashed onto the microcontroller — remains the weak point in many production chains.
If plaintext firmware or private keys end up in the wrong hands at this stage, the trust model for an entire device generation collapses: not a quality issue, but a security and liability risk — and, with the CRA, NIS2, the Data Act and, for automotive suppliers, UN ECE R155/R156, increasingly a regulatory one too. btv SEEL® closes the gap exactly where it opens.
In supply chain attacks, most target the code of suppliers. And most of those affected can't say afterwards how it happened.
The second point is the more uncomfortable one. An incident nobody can reconstruct can't be explained in an audit and can't be contained if things go wrong.
At the same time, pressure is building from the other direction: customers increasingly require their suppliers to meet security standards — and actively verify that, for example through their own audits and risk assessments.
So anyone who has components programmed gets asked how that process is secured. And needs to be able to answer.
btv SEEL® CORE – RAM-only principle, no persistent data traces
The technological foundation of the btv SEEL® ecosystem. The patent-pending process processes encrypted firmware exclusively in the volatile memory of the programming environment. At no point are unencrypted temporary files or persistent copies written to storage.
Once programming is complete, an automated, irreversible memory wipe follows. Asymmetric 4K encryption, public-private key procedures and signature-based authentication protect the flashing process against tampering and unauthorized readout. During the critical decryption step, the programming environment has no direct external connection.
On top of that comes a property that can't be configured away: RAM is volatile. No power, no stored data.
btv SEEL® INTERCONNECT – Your PKI stays your PKI
btv SEEL® UNLIMITED – Device identities at scale, audit trail included
Modern IoT, industrial, medical and automotive devices need individual certificates to identify themselves to cloud platforms, apps or manufacturer networks. In series production, that means a very large number of certificates — each unique, each traceably assigned.
btv SEEL® UNLIMITED scales this approach to the assignment of individual device identities. Every single process step is automatically documented and cryptographically signed.
That gives you a complete audit trail — and, if something does go wrong, the ability to pinpoint the affected component batches instead of having to recall an entire device generation.
What we actually deliver is the evidence
For actively exploited vulnerabilities and serious incidents, the Cyber Resilience Act requires an early warning within 24 hours, followed by a report within 72 hours and a final report within 14 days.
24 hours isn't enough time to reconstruct a batch assignment after the fact. Either the data already exists — or you report without being able to narrow anything down.
That's exactly what the btv SEEL® audit trail is built for: programming, certificate issuance and chip-level traceability, documented and uniquely assigned to each component. Audit-proof evidence for your customers, for auditors, and for regulatory requirements such as the CRA, UN ECE R155/R156 or ISO/SAE 21434.
The practical difference: the evidence already exists by the time of the audit. It doesn't get reconstructed afterwards.
Source: Cyber Resilience Act, Article 14
For security-critical industries
btv SEEL® is built for engineering, quality and operations leaders in sectors where a compromised component gets expensive:
- Mobility and transport (automotive, aerospace, rail, maritime)
- Healthcare (medical technology, digital health)
- Industrial production and mechanical engineering (incl. IoT/Industry 4.0)
- Security and defense (defense industry, infrastructure)
- Building technology and cities (smart home, smart city)
- Connectivity and communication (telecommunications, IT)
That means you meet regulatory requirements already at the component level — and keep the choice of how and where you produce.
What a typical project looks like
For automotive suppliers, the starting point is usually the same: regulatory pressure from multiple directions — the CRA deadline, CSMS obligations under UN R155/R156, requirements from ISO/SAE 21434 — and limited internal capacity to build a dedicated security infrastructure for it.
Here's what the path looks like with btv SEEL®:
- Assessment. Which components are affected, which standards apply, which evidence is missing.
- Integration. Your PKI is connected via btv SEEL® INTERCONNECT. Your root certificates stay with you.
- Programming. Firmware is provided encrypted and processed RAM-only.
- Documentation from go-live. The audit trail and cryptographic logs are available from the very first programmed component — not just once the audit happens.
- Audit preparation. The evidence package is ready when the auditor arrives.
You meet the requirements without building a security infrastructure internally.
At a glance
- Patent-pending high-security process: for microcontroller programming.
- Protection of sensitive firmware: right from the production stage.
- RAM-only programming: without permanent storage in plain text.
- Integration of the customer’s own PKI: root certificates remain with the manufacturer.
- Unique device identities: in mass production.
- Complete audit trail: with traceability at chip level.
- Support for CRA, NIS 2 and Data Act requirements: documented and auditable.
FAQ – direct, honest, to the point
btv SEEL® CORE secures the flashing process itself through the RAM-only principle. btv SEEL® INTERCONNECT connects your own PKI, so root certificates never leave your organization. btv SEEL® UNLIMITED scales that to individual device identities in series production — with an automatically documented, cryptographically signed audit trail for every process step.
The mechanism is the same regardless of industry: individual keys per device, RAM-only processing, a complete audit trail. Whether automotive, aerospace, medical technology, Industry 4.0 or critical infrastructure — you generate the compliance evidence out of production itself, instead of reconstructing it afterwards.
Yes. btv SEEL® delivers the evidence that the Cyber Resilience Act, NIS2 and the Data Act require at the component level — traceability down to the individual chip, documented key sovereignty, and a signed audit trail for every process step. Conformity of your end product remains your responsibility; we make sure you can prove it from the point of programming onward.
Secure full control – now.
What if you could meet tomorrow's security and compliance standards today?
The btv SEEL® Ecosystem consistently meets the requirements of: CyberResilience Act, NIS2, Data Act, and other international standards.
Watch the webinar now (GERMAN ONLY)