Fleet updates without the leap of faith.
Meshanics ships containers, configs and ML models to industrial device fleets - signed, verified on-device, and able to roll themselves back. EU CRA compliance evidence built in. Zero integration for your application and model code.
our cloud · your cloud · fully air-gapped on one on-prem node
of artifacts signed - no unsigned path exists, not even in dev
verified model hot-swap on-device, previous version retained
from factory-fresh device to enrolled, attested fleet member
ENISA early-warning window your update record is ready for
Fleet updates you can bet production on
Built on proven open standards - The Update Framework (TUF) for update security and OCI for container images, with models and configs as independently signed TUF targets - orchestrated into one control plane.
Signed end to end
Every artifact - container, ML model, config - is signed before it exists in the system. Devices verify full TUF metadata chains against a root of trust pinned in the device image. There is no unsigned path, not even in dev.
Rollback is a feature, not error handling
Each update declares a health probe. If the new version fails it, the device atomically restores the previous version on its own - no operator, no truck roll. The previous version is always retained.
Evidence by construction
Every state change - publish, rollout, approval, device update, rollback - is an append-only audit event the moment it happens. Compliance reporting reads from the record, not from reconstruction.
Canary waves & halt rules
Stage 1% → 10% → 50% → 100%, with approval gates where you want them. Halt rules pause the fleet the moment failures cross your threshold.
Heterogeneous fleets, anywhere
Jetson, Raspberry Pi and x86 in one fleet. Rollouts target device capabilities, not one golden image - even behind NAT or fully air-gapped.
Signed - and vetted
Signing proves an update is authentic, not safe. Meshanics blocks rollouts carrying open critical CVEs - with an audited override when you've made the call.
Continuous vulnerability watch
Each artifact's SBOM is matched against known CVEs continuously. See fleet exposure by severity, then turn a confirmed finding into a CRA-timeline report in a click.
Talks to the rest of your stack
Signed webhooks fire on every rollout, halt and new CVE - into Slack, PagerDuty or your own service. Outbound only, metadata only.
Configs placed where they belong
Deliver a config to the exact path a service reads, then reload it - signed, with the previous file kept for instant rollback. Only allowlisted paths are accepted.
Connect your devices
A single static agent (<15 MB, arm64/amd64) registers over mutual TLS and reports its hardware profile. Identity lives in the device certificate - never in a payload.
Publish signed artifacts
Push a model, container or config with one call. It's signed into the update repository before anything is recorded.
Roll out with confidence
Pick a fleet, a wave strategy and a health probe. Watch devices verify, swap and report live - and roll themselves back if anything is off.
Factory-fresh to fleet in one command.
The device generates its own key - it never leaves the device - exchanges a one-time token for a signed identity and the root of update trust, then appears in your console within seconds. How it works →
$ curl -fsSL https://meshanics.com/install.sh | sudo bash -s -- --token mesh_…ML models as first-class deployable units
Treat a model as a first-class deployable unit: deploy, canary and roll back vision models (ONNX, TensorRT, TFLite) across device fleets the same way you ship code - each model independently signed, versioned and rollback-safe.
- [✓]Verified hot-swap in seconds - new model live on-device in under a minute, signature-checked before the swap
- [✓]Canary cohorts for models - try the new weights on 5 devices before the other 500
- [✓]Instant rollback - your health check flags a bad model and the device reverts to the previous one, still on disk
- [✓]Model manifests - framework, input spec, target hardware profile and license travel with the artifact
What the DIY update stack actually costs
Every OEM has shipped updates with scripts and good intentions. It works - until the one time it doesn't, in front of a customer, or an auditor.
DIY · Optional, hand-rolled, easy to bypass under deadline pressure
Meshanics · Mandatory - the unsigned path does not exist in the code
DIY · Bricked unit, truck roll, angry plant manager
Meshanics · Health probe fails → device restores the previous version itself
DIY · scp and a prayer
Meshanics · First-class signed artifacts: canary cohorts, manifests, instant rollback
DIY · Manual key ceremonies per device
Meshanics · One command - key generated on-device, never leaves it
DIY · Custom scripts pushing images to each device; credentials copied onto devices
Meshanics · Connect GHCR, ECR, Artifact Registry, JFrog or Harbor; pull through by digest, credentials stay in the control plane
DIY · Find out from the news, then grep which devices are affected
Meshanics · Continuous SBOM × CVE matching, severity-ranked, one click to a CRA-timeline report
DIY · Signed or not, it ships to every device the moment someone hits deploy
Meshanics · Rollout blocked on open critical CVEs; every admission decision is audited
DIY · Reconstructed from logs the week before the audit
Meshanics · Append-only record written as updates ship; exportable
DIY · Cloud-only tooling stops at the firewall
Meshanics · Entire control plane runs on one on-prem node
We assume the supply chain is the target
Update infrastructure has SolarWinds-class blast radius, so Meshanics is built like it: offline roots of trust, scoped online signing, verification at the edge - and nothing else trusted in between.
Offline root keys
TUF root and targets keys live on an air-gapped machine, never our backend. Online signing is scoped to a delegated namespace - a compromise stays contained.
Untrusted transport
CDNs, registries and storage are treated as hostile. Devices verify signatures, hashes, lengths, versions and freshness - anything tampered, stale or replayed is rejected on-device.
mTLS everywhere
Every device holds its own X.509 identity (hardware-backed where the silicon allows). Identity comes from the certificate, never a request payload.
Air-gap & on-prem ready
The whole control plane runs on a single on-prem node with no cloud dependency - built for defense and critical infrastructure.
No payload telemetry
We see metadata, never your artifact contents or data. Auditable by your security team - and ours.
Attack-tested updates
The device client ships with negative tests for the attacks that matter - tampered artifacts, frozen metadata, rollback replays, wrong-key signatures. Rejection is the default.
Compliance as a product feature, not a PDF
The EU CRA requires secure update mechanisms, vulnerability handling and evidence. Meshanics generates that evidence as a by-product of how updates actually ship - and the same engine serves the other regimes you answer to.
- [✓]Secure-update attestation - demonstrate a signed, verified, rollback-safe update path per product
- [✓]Complete update history - per device, per product, signed and append-only
- [✓]Vulnerability timelines - SBOM-driven affected-fleet queries supporting the 24h / 72h / 14d ENISA reporting flow
- [✓]Exportable reports - hand your notified body the record, not a reconstruction
CRA is the first wedge. The same append-only audit log, SBOM vulnerability watch and readiness engine map to each framework's requirements - pick the framework, read the live readiness, export the signed report.
From this date, actively exploited vulnerabilities and severe incidents must be reported on the ENISA 24 h / 72 h / 14 d timeline. Full conformity follows 11 Dec 2027.
The higher of €15 M or 2.5% of worldwide annual turnover, for non-compliance with essential cybersecurity requirements - secure updates among them.
Put your fleet on rails.
Industrial OEMs, device makers and teams shipping regulated products to real hardware - we're building the roadmap with you.
Become a design partner