← All posts
22 June 20264 min read

Meshanics is live: signed OTA for industrial and edge-AI fleets

We are launching Meshanics - signed over-the-air updates, typed recovery adapters and fleet management for industrial and edge-AI devices, with EU CRA evidence workflows built in.

By The Meshanics team

Today we are launching Meshanics: a zero-trust platform for shipping software, ML models, and configuration to fleets of industrial and edge-AI devices - safely, verifiably, and with records that support product-security and CRA work.

If you run devices in the field - vision systems on a factory line, gateways at remote sites, robots, drones - you already know the quiet terror of an update. One bad push and a unit is bricked at a site three hours away. So updates get rare, manual, and scary, which is exactly how fleets fall behind on security patches. Meshanics exists to make the safe path the default path.

The problem we kept running into

Three things were broken everywhere we looked.

Updates were not safe by construction. Signing was optional and easy to skip under deadline pressure. A failed update meant a truck roll, not a recovery. The unsigned path always existed somewhere, which is the SolarWinds-shaped hole in most fleets.

Shipping ML models was a hack. Teams were copying model files onto devices with scp and a prayer - no canary, no rollback, no record of which weights ran where. For edge-AI products, the model is the product, and it had the worst deployment story of anything on the device.

Compliance was a fire drill. The EU Cyber Resilience Act turns secure updates and vulnerability reporting into a legal obligation. Most teams plan to reconstruct the evidence from logs the week before an audit. That does not survive contact with a regulator.

What Meshanics does

We built the platform around a few rules we refuse to break.

Signed end to end. Containers, models, configs and service binaries are published through The Update Framework. Supported device paths verify the metadata chain and target integrity against a pinned root before activation.

Recovery is part of delivery, not an afterthought. Supported adapters use a health probe and retain prior state so a failed activation can be restored. The guarantee depends on the payload adapter and device recovery boundary; Linux A/B system images are not available today.

Canary waves and halt rules. Stage a rollout 1 percent, then 10, then 50, then 100, with approval gates where you want them. Halt rules pause the whole fleet the moment failures cross your threshold, and devices that already took the bad update follow the configured adapter recovery path.

Edge-AI model OTA as a first-class workflow. Models are signed artifacts with optional manifest metadata and a rollout-checked target hardware profile that travels with the weights. Framework, opset and tensor fields are metadata rather than an on-device compatibility guarantee today. Push a new model to a canary cohort, watch the verified hot-swap land in under a minute on the measured reference path, and restore the retained prior model if its health check fails.

Evidence by construction. Every state change - publish, rollout, approval, device update, rollback - is written to an append-only, hash-chained audit log the moment it happens. Continuous SBOM-to-CVE matching tells you which devices run a vulnerable component, and a confirmed finding can become an evidence case with affected scope and recorded reporting steps. Meshanics records the facts; the manufacturer confirms statutory trigger dates and submission.

Heterogeneous fleets, anywhere. Jetson, Raspberry Pi, and x86 in one fleet. Rollouts target device capabilities, not one golden image. The entire control plane runs on a single on-prem node with no cloud dependency - built for defense, critical infrastructure, and anyone who lives behind an air gap.

Honest framing: we are not "agentless"

We will say this plainly, because the market is full of claims that do not survive a security review. Meshanics is not agentless. An agent runs on each device to verify, activate and report updates, including the recovery supported by each adapter. What you get is zero integration for your own code: your application and model code ship unchanged, inside signed artifacts, through typed delivery adapters. We build on TUF for update security and OCI for container delivery, then add orchestration, model workflows and evidence records on top. Linux A/B system-image delivery is not available today.

The clock that is already ticking

The CRA is not a future problem. Reporting obligations begin on 11 September 2026, and full conformity for products with digital elements sold in the EU is required by 11 December 2027, with fines up to 15 million euros or 2.5 percent of global turnover. A secure, signed update mechanism with a tested recovery boundary and an exportable evidence trail is no longer a nice-to-have. It is something you have to demonstrate.

Start today

The signed-update workflow is free for up to five non-critical evaluation devices. Annual production plans are based on Linux fleet size and deployment, with Compliance & Evidence available per product family. Current numbers and custom deployment boundaries are kept on the pricing page.

You can have a factory-fresh device enrolled with a single command, push your first signed model, and watch it roll out - or roll back - in minutes.

Start for free, see the pricing, or read the documentation. We would love to hear what you are building.

launchotaedge-aicra

Ship and verify fleet updates.

TUF-signed OTA for containers, ML models, configs and service binaries - free for up to five non-critical evaluation devices.