An open-source TPM device-attest-01 CA server
-
Updated
Mar 8, 2026 - Go
An open-source TPM device-attest-01 CA server
FastAPI extension for device request verification on iOS devices using Apple’s DeviceCheck service.
Post-quantum custody architecture. Separates key capability from spending authority. Every custody operation requires predicate evaluation before signing is permitted. Fail-closed by design.
Hardware-bound ECDSA signing via Secure Enclave (macOS) and TPM 2.0 (Linux/Windows). Keys never leave the chip.
Hardware-rooted identity and trust-token SDK for apps, agents, and devices.
Add a description, image, and links to the device-attestation topic page so that developers can more easily learn about it.
To associate your repository with the device-attestation topic, visit your repo's landing page and select "manage topics."