USB-C hardware security modules for PKCS#11 and PKI. Every private key is generated inside a smart card on a Common Criteria EAL6+ certified platform and is non-extractable, so there is no export path to misuse: for certificate authorities, code signing, TLS server keys, document signing and SSH. Driverless on Windows, Linux and macOS, with secure boot, signed firmware updates and attestation of the card fitted.
