Matomo

Fleet | Cossack Labs

Trusted by organisations that cannot afford to get it wrong

  • Ministry of Defence of Ukraine
  • datasite
  • nec
  • EvoLogics
  • Delta
  • tezos-foundation

Fleet explained

Fleet is a platform for building and operating secure fleets of edge devices across their full lifecycle.

Fleet covers uncrewed vehicles (UxVs), sensors, actuators and data-acquisition equipment. It is built for OEMs and firmware teams embedding security from the build stage; programme and platform operators managing trust across large, heterogeneous or third-party device populations. Fleet's trust model allows to balance pragmatic usability and trust.

Proven in the most challenging environments: application spans the private and public sectors, including power grids and defence, operating under contested supply chains and daily real-world attacks.


Works in environments under constant threat

  • UA DroneID

    Friendly drone identification technology

    UA DroneID is a security and identification technology for unmanned systems that must operate in contested, degraded, and adversarial network conditions. As cybersecurity partner on the programme, we shaped the standard, security, and reference implementation for integration of unmanned systems into control and coordination system.

  • UKRAINE’S MAIN GRID OPERATOR

    Enabling continuous grid operations under active conflict conditions

    We built a hardware-software cross-domain system that integrates with existing energy infrastructure without interrupting operations. Acting as a reserve data acquisition system, it enables national grid resilience against targeted cyber and physical attacks — keeping operators in control even under partial loss of operational control, including during mass attacks on energy facilities.


    Cover device security lifecycle

    Build

    Secure hardware and firmware development tooling.

    Deploy

    Provisioning, identity issuance, key injection.

    Operate

    Remote fleet operations, telemetry, posture monitoring.

    Revoke

    Re-keying, credential revocation, end-of-life disposal.

    Key components

    • Machine identity management

      Device identity issuance, attestation and trust-posture assessment; integrated third-party operator identity with device-to-human mapping and credential hierarchy.

      Device trust management

      Trust decisions that go beyond standard SOC metrics, designed for untrusted-operator scenarios and threat actors with supply-chain or physical access to devices.

      Sensitive parameter management

      Secure storage and lifecycle management for keys, licences and other security assets; integrates with HSMs, pilot ID data and ephemeral authentication tokens from third-party systems.

    • Firmware and payload DRM

      Integrity protection and rights management for firmware and payloads; prevents tampering, unauthorised extraction and deployment to uncredentialed hardware.

      Firmware CI/CD toolkit

      Security-specific stages of firmware delivery: multi-target builds with pre-baked security controls, per-device firmware personalisation and device binding. Not a CI system itself; integrates with existing pipelines.

      Security toolbox

      Integration with HSMs, secure elements, secure enclaves in modern SoCs, external sources of trust, tamper sensors and other hardware security controls.

    • Posture and telemetry

      Continuous collection of device health and security posture; feeds security monitoring and maintenance pipelines, and — with appropriate redaction and sanitisation — vendor predictive-maintenance workflows.

      Fleet orchestration and remote operations

      Remote application installation, script execution and configuration management across large, heterogeneous device populations, including under degraded or intermittent connectivity.

    Start with the problem you are solving

    Request a briefing. We will tell you whether the platform addresses your problem before we show you how.

    Start a conversation

    Get whitepaper

    Apply for the position

    Our team will review your resume and provide feedback
    within 5 business days

    Thank you!
    We’ve received your request and will respond soon.
    Your resume has been sent!
    Our team will review your resume and provide feedback
    within 5 business days