Threat model day 1.
Mainnet week 8.
Every engagement starts with a written threat map of your OTA pipeline. You see a working rejection of a malicious bundle before Sprint 1 ends. By week 8, your registry is live on mainnet and your signing quorum is operational. No black boxes. No "trust us, it works."
Threat map in day 1.
We audit your current OTA pipeline — CI/CD, signing keys, CDN hops, current verification — and produce a written threat model before a line of code is written.
Registry live by week 2.
OTARegistry deployed to testnet. Rust verifier running locally. A test malicious bundle is rejected before the sprint is over — you see it working, not just a design doc.
Multi-sig wired by week 4.
Gnosis Safe quorum configured. First offline signing ceremony completed. The registry requires M-of-N hardware wallets for every future publish. One compromised machine is no longer enough.
Mainnet + SLA by week 8.
Registry deployed to mainnet. Managed signing SLA active. Your next OTA update is the first one verified on-chain. Every future update is public, auditable, and cannot be pushed without the hardware wallet quorum.
Four sprints. Every artifact testable before mainnet.
Sprint 1: verifier rejects a malicious bundle on your machine. Sprint 2: multi-sig quorum stops a single compromised key from publishing. Sprint 3: staged rollouts and instant revoke work on testnet. Sprint 4: mainnet deployment with signing SLA live. You sign off each sprint before we proceed.
- Rust Verifier
- Bundle Hashing
- Registry Contract
- Testnet Deploy
- Multi-Sig Setup
- Signing Ceremony
- JSI Bridge
- Device Test
- Rollout Control
- Revoke / Rollback
- Monitoring
- Load Test
- Security Review
- Mainnet Deploy
- Docs Handoff
- SLA Handoff
Start with a 30-minute threat review.
Walk us through your current OTA setup. We'll tell you where you're exposed — on the call, for free — before any engagement starts. Fixed-price quote within 48 hours.