Skip to content

LAAVAT PKI and Signing Platform documentation

LAAVAT is a cloud PKI and code-signing platform for embedded and IoT device manufacturers. It provides HSM-backed firmware and secure boot signing, device identity (IDevID/LDevID), and full PKI hierarchy management — with signing keys generated inside AWS CloudHSM and never leaving it. Every operation is available through the web GUI, the REST API, and the signing-tool command-line client.

New here? Start with the Quick Start Guide, or work through the onboarding checklist if your organization is being set up for the first time.

Secure boot, updates and device identity for CRA compliance

If you ship connected products into the EU, the EU Cyber Resilience Act sets mandatory cybersecurity requirements across your product's lifecycle, and its obligations are already phasing in.

Much of what it asks for comes down to what a device can prove. It must run only firmware you authorized, accept only updates that genuinely came from you, and be able to identify itself to the systems it talks to — otherwise "vulnerabilities can be fixed" stays theoretical. Secure boot, signed firmware updates and trusted device identity are the mechanisms that make it real, and they all rest on keys and certificates that have to be managed properly. That is the infrastructure LAAVAT provides.

The CRA Compliance section is written for engineers rather than lawyers — scope, deadlines, the Annex I requirements, and how these capabilities map to them.


This site is the technical documentation for the platform. For product overviews, supported use cases and company information, see www.laavat.io. Support is available at support@laavat.io.