Pinned root
Enrollment gives each device the tenant trust root it will use to validate future metadata rotation.
TUF security
TLS protects a connection. TUF protects the update decision even when a repository, registry, CDN or network path is untrusted. Devices verify signed metadata, target hashes, lengths, versions and expiry before accepting bytes.
Good fit
Product boundary
Enrollment gives each device the tenant trust root it will use to validate future metadata rotation.
Offline root authority and scoped online publishing roles reduce the effect of one key or service compromise.
Versioned and expiring metadata lets the client reject older or indefinitely replayed repository state.
Transport is not trusted to choose or modify target bytes; signed metadata fixes their path, size and hash.
Explicit limit
TUF proves that authorized metadata selected exact bytes. It does not prove that those bytes are vulnerability-free, operationally healthy, or legally compliant, so Meshanics applies separate admission, health and evidence controls.
Questions
No. The static Linux agent installs on the device and activates signed payloads through typed adapters. Health behavior and recovery limits are configured for the artifact, not embedded in customer application code.
No. Meshanics records and exports evidence for the manufacturer's compliance work. The manufacturer remains responsible for product scope, risk decisions, conformity assessment, reporting, and declarations.