Meshanics is live: signed, rollback-safe OTA for industrial and edge-AI fleets
We are launching Meshanics - zero-trust over-the-air updates and fleet management for industrial and edge-AI devices, with EU CRA compliance evidence built in. Here is what we built, and why.
By The Meshanics team
Today we are launching Meshanics: a zero-trust platform for shipping software, ML models, and configuration to fleets of industrial and edge-AI devices - safely, verifiably, and with the compliance evidence regulators are about to require.
If you run devices in the field - vision systems on a factory line, gateways at remote sites, robots, drones - you already know the quiet terror of an update. One bad push and a unit is bricked at a site three hours away. So updates get rare, manual, and scary, which is exactly how fleets fall behind on security patches. Meshanics exists to make the safe path the default path.
The problem we kept running into
Three things were broken everywhere we looked.
Updates were not safe by construction. Signing was optional and easy to skip under deadline pressure. A failed update meant a truck roll, not a recovery. The unsigned path always existed somewhere, which is the SolarWinds-shaped hole in most fleets.
Shipping ML models was a hack. Teams were copying model files onto devices
with scp and a prayer - no canary, no rollback, no record of which weights ran
where. For edge-AI products, the model is the product, and it had the worst
deployment story of anything on the device.
Compliance was a fire drill. The EU Cyber Resilience Act turns secure updates and vulnerability reporting into a legal obligation. Most teams plan to reconstruct the evidence from logs the week before an audit. That does not survive contact with a regulator.
What Meshanics does
We built the platform around a few rules we refuse to break.
Signed end to end. Every artifact - container, model, config - is signed before it exists in the system, using The Update Framework. Devices verify the full metadata chain against a root of trust pinned in the device image. There is no unsigned path, not even in development.
Rollback is a feature, not error handling. Every update declares a health probe. If the new version fails it, the device atomically restores the previous version on its own - no operator, no truck roll. The previous version is always kept on disk.
Canary waves and halt rules. Stage a rollout 1 percent, then 10, then 50, then 100, with approval gates where you want them. Halt rules pause the whole fleet the moment failures cross your threshold, and devices that already took the bad update roll themselves back.
Edge-AI model OTA as a first-class workflow. Models are signed artifacts with a manifest - framework, input spec, target hardware profile, license - that travels with the weights. Push a new model to a canary cohort, watch the verified hot-swap land in under a minute, and revert instantly if your health check flags it. No incumbent ships this turnkey.
Evidence by construction. Every state change - publish, rollout, approval, device update, rollback - is written to an append-only, hash-chained audit log the moment it happens. Continuous SBOM-to-CVE matching tells you which devices run a vulnerable component, and one click turns a confirmed finding into a report that fits the ENISA 24h / 72h / 14d reporting flow. Compliance reads the record, it does not reconstruct it.
Heterogeneous fleets, anywhere. Jetson, Raspberry Pi, and x86 in one fleet. Rollouts target device capabilities, not one golden image. The entire control plane runs on a single on-prem node with no cloud dependency - built for defense, critical infrastructure, and anyone who lives behind an air gap.
Honest framing: we are not "agentless"
We will say this plainly, because the market is full of claims that do not survive a security review. Meshanics is not agentless. A small signed agent runs on each device, and that agent is what makes verified updates and automatic rollback possible. What you get is zero integration for your own code: your application and model code ship unchanged, inside signed artifacts, on top of our rollback-safe delivery layer. We build on proven engines - RAUC for A/B OS updates, TUF for update security, OCI artifacts for delivery - and add the orchestration, the model lifecycle, and the compliance evidence on top.
The clock that is already ticking
The CRA is not a future problem. Reporting obligations begin on 11 September 2026, and full conformity for products with digital elements sold in the EU is required by 11 December 2027, with fines up to 15 million euros or 2.5 percent of global turnover. A secure, signed, rollback-safe update mechanism with an exportable evidence trail is no longer a nice-to-have. It is the thing you have to demonstrate.
Start today
The whole signed-update engine is free for your first five devices - signed OTA, automatic rollback, canary waves, vulnerability watch, and a live compliance readiness report. Paid plans are priced per device and drop as your fleet grows.
You can have a factory-fresh device enrolled with a single command, push your first signed model, and watch it roll out - or roll back - in minutes.
Start for free, see the pricing, or read the documentation. We would love to hear what you are building.
launchotaedge-aicra