# Embetrix > Embedded Linux and security engineering. Embetrix is an independent embedded Linux and security engineering practice, founded and run by Ayoub Zaki, based in Germany and working with product teams worldwide. Over 20 years of experience helping teams design, build and maintain secure embedded Linux devices, from BSP and Yocto development to system security, OTA updates and product industrialization. ## Services Full details: https://embetrix.com/services ### Design and security architecture For new products and platform redesigns. We define an implementable embedded Linux architecture and resolve security decisions before they become expensive to change. - Security requirements for CRA, RED Delegated Act and IEC 62443 - Threat modelling and security architecture - Yocto or Buildroot platform architecture - Hardware root of trust and secure boot-chain design - PKI, certificate and device-identity architecture - OTA update and recovery strategy ### Build and integrate We bring up hardware, develop the Linux platform and integrate security features into a reproducible build and release process. - BSP development and board bring-up - Yocto layers, distributions and Buildroot integration - Secure boot, OP-TEE, secure storage and PKCS#11 - HSM-backed image and release signing - Applied cryptography and secure key-management integration - Reproducible builds and CI/CD pipelines ### Test and release We connect builds, signing, provisioning and tests on real hardware so each release is repeatable and important failure paths are checked before deployment. - Hardware-in-the-loop and Robot Framework testing - Network, security and peripheral testing - OTA, rollback, recovery and power-loss testing - SBOM generation and vulnerability scanning - Release signing and production provisioning - Open-source licence compliance and release evidence ### Update and maintain For deployed products. We establish reliable update and recovery paths, support vulnerability handling and maintain the Yocto or BSP platform over time. - OTA update system integration - Signed, encrypted and staged fleet rollouts - Atomic rollback and field recovery - CVE monitoring, triage and patch management - Certificate lifecycle management - Long-term Yocto, BSP and product security compliance support ### Engagements - Assessment: Review an existing platform and provide written findings with recommended priorities. - Implementation: Deliver a defined technical scope with agreed deliverables and handover to the team. - Ongoing support: Support releases, security updates and long-term platform maintenance. ## Contact Need help with embedded Linux or product security? Email us or book a call. - Email: info@embetrix.com (typical response within one working day) - Book a call: https://calendly.com/embetrix/30min - Contact page: https://embetrix.com/contact - LinkedIn: https://www.linkedin.com/in/ayoub-zaki-embetrix - GitHub: https://github.com/embetrix - Based in Germany, working with product teams worldwide. ## Open Source Maintained open-source projects (https://embetrix.com/open-source, https://github.com/embetrix): - [meta-stm32mp15x](https://github.com/embetrix/meta-stm32mp15x) (BitBake): OpenEmbedded/Yocto BSP layer for STM32MP15x based MPUs. - [meta-raspberrypi-secure](https://github.com/embetrix/meta-raspberrypi-secure) (BitBake): meta-raspberrypi add-on Yocto layer for enhanced security and OTA update. - [rpifwcrypto-pkcs11](https://github.com/embetrix/rpifwcrypto-pkcs11) (C): PKCS#11 module that exposes the Raspberry Pi firmware OTP ECDSA key through the PKCS#11 interface. - [stm32mp-sign-tool](https://github.com/embetrix/stm32mp-sign-tool) (C++): Utility for signing and verifying firmware images compatible with STM32MP MPUs. - [satobox](https://github.com/embetrix/satobox) (BitBake): A privacy-focused, secure Bitcoin full-node solution designed for embedded Linux devices. - [bmap-writer](https://github.com/embetrix/bmap-writer) (C++): A Yocto bmap-tools alternative written in C++. ## About - [About Embetrix](https://embetrix.com/about): Ayoub Zaki, Founder, embedded Linux engineer. ## Other pages - [Jobs](https://embetrix.com/jobs): Open embedded Linux and product security roles. - [Impressum](https://embetrix.com/impressum): Provider identification and legal information. ## Blog - [Cyber Resilience Act: Are Embedded-Device Manufacturers Ready for September 2026?](https://embetrix.com/2026/07/21/cyber-resilience-act-reporting-september-2026): CRA Article 14 reporting starts 11 September 2026 before the main 2027 deadline. What embedded device manufacturers must prepare now. ## Optional - [Full content](https://embetrix.com/llms-full.txt): detailed company, services, contact, open-source and article content in one file.