Zero-Trust Platform Feature Overview

Secure Your Software Supply Chain

 The Zero-Trust Platform (ZTP) is a software security architecture designed to address the risks arising from complex and heterogeneous software stacks by enforcing strong isolation and hardware-backed trust boundaries at the platform level.

The Zero-Trust Platform (ZTP) consists of a hypervisor component and a dedicated Security Services virtual machine (VM). The hypervisor manages system resources and strictly controls access and communication between VMs using unique, cryptographically secured identifiers. The Security Services VM provides centralised security functions to other workloads while remaining isolated from them. It leverages trusted computing technologies offered by the underlying hardware to ensure that even highly privileged software components cannot access protected workloads or sensitive data.

From Server to Edge

The ZTP supports both embedded and server-class platforms by adapting to the respective execution environments. On embedded platforms, it integrates with the custom Peregrine hypervisor and uses Arm TrustZone for hardware-enforced isolation. On server platforms, it operates with KVM and QEMU and relies on AMD SEV-SNP to protect VMs against compromise by the host or other workloads. Through this architecture, the ZTP enables secure boot, remote attestation, full disk encryption, virtual TPM functionality, and secure logging as platform services.

Zero-Trust Platform Overview




By isolating workloads at the hardware level, the ZTP ensures that a compromise of one component does not propagate to others, thereby containing faults and attacks and preserving the integrity of the overall system.


The ZTP has been developed and validated in security-critical domains, including satellite platforms in collaboration with the European Space Agency and military use cases requiring secure multi-vendor software integration. In defence platforms, it ensures strong isolation between mission applications and supports software-defined capability updates, thereby enhancing operational resilience.

One Platform - Many Use Cases

Space

The trends of commercial off-the-shelf hardware and multi-tenancy are revolutionizing the space industry. The ZTP provides a strong isolation for multi-tenant payload systems, its security services allow you to keep control over your satellite.

Defence

Multi-domain operations are the future of defence. Shifting decision-making from C&C directly to frontlines. The ZTP is the technical basis for this change - enabling you to create verifiable trust relations between assets.

Industrial Automation

EU Cyber Resilience Act is coming - and requires basic product security like secure boot. The ZTP has all reuired functionalities built-in already. And if you need only a certain functionality, check our Embedded Security Portfolio.

Zero-Trust Platform Features

  • Hardware-anchored isolation
  • Zero-trust enforcement
  • Security Services
  • Virtual TPM services
  • Secure Boot / Logging
  • Cloud-native workflows
  • Real-time Hypervisors
  • Arm TrustZone / AMD SEV
  • Embedded and server support