SecureSMX® · Secure RTOS for Arm Cortex-M

Hackers get in. SecureSMX keeps them contained.

Attackers have moved on from phishing to an easier target: the unprotected embedded and IoT devices already in the field. SecureSMX divides your firmware into fully isolated partitions on the Arm Cortex-M hardware you already use — so a breach in one part cannot reach the rest, and your trusted code keeps running with little or no change.

Open source · Built on SMX RTOS, in production since 1989 · 50 years of embedded systems experience

Why device security is different now

Once a device is hacked, it’s too late.

What’s the problem?

Attackers have moved on from phishing to an easier target: unprotected embedded and IoT devices. Every connected device is now a way in — and once one is breached, the damage to your customers and your reputation is already done. Regulators have noticed: the EU’s Cyber Resilience Act will require connected products sold in Europe to be secure by design and kept patched throughout their life, with real penalties for falling short.

What’s the solution?

SecureSMX® is a secure RTOS for Arm Cortex-M v7 and v8 microcontrollers. It splits your firmware into fully isolated partitions, so an attacker who gets into one can’t get into the others — and can’t crash the system from inside. It is open source, with commercial licensing and support available.

How does it fit my product?

Existing designs: move vulnerable code into isolated partitions one module at a time. Your mission-critical code keeps running with little or no change. New designs: start from a partitioned framework so security is built in from day one. Not on SMX? FreeRTOS and ThreadX ports bring your application over.

Microcontroller circuit board
Connected embedded systems
The CVE problem

Stop patching every CVE at once.

The flood of CVEs in embedded and IoT devices is relentless. Teams that try to fix them all at once ship hasty patches that fail — and burn out in the process.

SecureSMX changes the math. Because every module lives in an isolated partition, you can triage each CVE by the importance of the partition it lands in, and take a measured, wait-and-see approach instead of a fire drill. A breached partition can even be swapped for a stand-in while the rest of the device keeps working.

Without partitioning
One flat attack surface — every CVE is an emergency.
Network stack CVE
Patch now
USB stack CVE
Patch now
3rd-party library CVE
Patch now
Logging module CVE
Patch now
With SecureSMX
Triaged by partition importance.
Crypto & keys · critical
Patch now
Network partition
Scheduled
App partition
Scheduled
SOUP / 3rd-party · isolated
Wait & see
How SecureSMX protects your device

Isolation, engineered in.

The mechanics behind the promise — for the engineers who will build with it.

01

Isolated partitions

Untrusted code runs in isolated, unprivileged partitions, so a malware breach cannot reach the code or data in any other partition — or in privileged mode.

02

Trusted code runs unchanged

Trusted code needs no modification. It keeps running in privileged mode exactly as it always has, with no rewrite required.

03

Doubly protected

Trusted code is guarded twice over — by the privileged-mode barrier and by partition isolation. Two independent walls, not one.

04

Contain with mock partitions

A breached partition can be shut down and swapped for a mock partition, keeping the main system running until a fix is ready to deploy.

05

Patch while running

Breached partitions can be updated with patches while the main system keeps running — no full-system downtime to close a hole.

06

Runtime limits and portals

Partitions are held to strict limits so a hacked one can’t exhaust resources or loop forever, and communicate only through standardized portals.

SMX RTOS and middleware

A complete platform underneath.

SecureSMX runs on top of SMX, a full RTOS used in hundreds of devices since 1989, with integrated middleware:

Get started

Get on the path to security.

Tell us about your device and we’ll show you how SecureSMX fits it. Or go straight to the source on GitHub and start building.

Contact us

Engineers on the other end of the line.

Tell us about your device and where you are with security. You’ll hear back from an engineer, not a sales queue.

Sales & licensing

Pricing, commercial licensing, support contracts, and pre-sales technical questions.

Technical support

Support for customers and evaluators working with SecureSMX and SMX.

Micro Digital Inc. · Irvine, California · (714) 437-7333
Support, training, consulting, and porting by the developers who wrote the code. SecureSMX on GitHub →

We reply within one business day. No newsletters unless you ask.