Our Products
Three products for connected industry. One gives your device team the foundation for remote control and security. One turns a trade fair into qualified meetings. One measures the cybersecurity risk analysis you already hold. Each is available on its own, and each came out of a live client project.
For device and product teams
TemperCrate
Ship a connected product that is remotely governable, updatable and auditable from its first build, instead of building that layer yourself.
Read more
For trade fair organisers
StandVis
Give every visitor a route to the stands worth their time, and give exhibitors the pre-qualified meetings they renew for.
Read more
For product security and compliance
TARA-AI
Find out what your existing risk analysis is missing while the design is still open, ahead of certification.
Read more
Product for device and product teams
TemperCrate
The foundation your connected product needs, ready on day one, so your engineers spend their months on what customers are buying.
Context and need
Adding connectivity to a product adds four responsibilities to the programme before a single differentiating feature is written. Each device needs an identity that can be trusted outside your network. Software has to reach the installed base and keep a working version available. Equipment in the field has to stay in reach. And the evidence a certification body asks for has to exist in a readable form.
Those four are the same for every connected product, and they are where new hardware programmes lose their first months of senior engineering. The market has priced this clearly: remote update and application deployment are billed per device per month, published rates run from one to three euros, and identity provisioning at end of line is quoted around a dollar per device. What none of that covers is the internal build.
Solution and approach
Identity Created On The Production Line
Each device generates its private key on the board, inside the secure element, during manufacturing, and the key stays there. Devices join the platform because their identity chains back to your own certificate authority. Retiring a unit removes its access and leaves that identity intact.
Every Update Keeps A Way Back
System images are signed at build time and accepted only when authentic. Installation writes to a second slot, and if the new image does not come up the device returns to the one that worked. Releasing an update becomes a routine decision rather than an escalation.
System And Applications Travel Separately
They behave differently, so they take different routes. System images move through hawkBit to a RAUC client on the device. Applications move as signed containers through a registry, over encrypted MQTT, and run isolated with containerd.
Evidence Appears As Your Fleet Runs
Every action lands in a verifiable record, and each device signs its own logs before sending them. Logs are held on the device while it is offline and forwarded when the link returns, so the compliance file builds itself during normal operation.
Part Of The Image, From The First Build
The agent is compiled into the signed system image through a dedicated Yocto recipe, so it belongs to the device rather than sitting on top of it. Developers drive it from a command line, and whoever operates the fleet works from the dashboard.
Result and value created
Months back into the roadmap
Senior engineering that would build this foundation goes into the features your customers are paying for.
Service cost under control
A software correction is a remote action, and every release keeps a working version available on the device.
Market access secured early
Identity, signed updates and audit records are in place from the first build, which is what IEC 62443, NIS2 and the Cyber Resilience Act ask you to demonstrate.
| What you need | Building it in house | A generic device platform | TemperCrate |
|---|---|---|---|
| Device identity | Designed and implemented per project | Usually assigned once the device is already in the field | Created on the production line, inside the secure element |
| System updates | Built and hardened by your team | Included, with rollback in the better products | Signed images, A and B slots, automatic return to the working version |
| Applications | Custom deployment mechanism | Often on the same path as the system | Signed containers on a separate path from the system |
| Audit evidence | Assembled ahead of a review | Activity logs, held centrally | Signed by the device as it operates, ready to export |
| Where it lives | Inside your codebase | An agent installed on the device | Inside the signed system image, from the first build |
Tell us about the device you are designing, and we will show you what it looks like with this foundation in place.
Ask for informationProduct for trade fair organisers
StandVis
Turn footfall into qualified meetings, and give exhibitors the return they weigh when they book the next edition.
Context and need
The meetings that make a fair worth attending are largely the ones nobody planned. A visitor arrives with limited hours and a floor plan they have not studied. An exhibitor invests in a stand and meets whoever passes. The organiser carries responsibility for the value both sides take home, with few levers to shape what happens between them.
Matchmaking platforms address this, and the market prices them accordingly: third party estimates put premium engines between five and twenty five thousand dollars per event, and enterprise licences between twenty and seventy nine thousand dollars a year plus a fee per registrant. Public customer references on one of the leading platforms report around four months to implement. Most of that time goes into aligning the registration flow, because the visitor profile is assembled from fields collected at sign-up.
Solution and approach
One QR Code, Nothing To Fill In
StandVis opens in the browser from a code printed on site. The visitor shares the address of their own company, or describes what they came for. No form, no account, and no dependency on your registration flow, which is why it can be added to an edition already on sale.
The Profile Comes From What The Company Publishes
StandVis reads that website and derives sector, products, materials and markets served. The visitor is recognised for what their company actually does, rather than for the categories they had time to tick when they registered.
Every Match Arrives With Its Reason
Each suggested stand carries the sentence that explains why it is relevant. People act on reasons, so the visitor can weigh each suggestion, and you can see the logic behind what your fair is recommending.
A Route Through The Day
The suggestions become an order: which stands, roughly when, and who to look for. Visitor hours are spent on conversations that had a reason to happen.
Your Fair Keeps The Knowledge
Exhibitors receive pre-qualified meetings, which is the evidence they look for at renewal. And you gain a picture the fair did not previously generate: who the visitors are, what they came for, which stands were asked for most. It exports, and it informs the next edition.
Result and value created
Renewals with evidence behind them
Exhibitors weigh pre-qualified meetings, not footfall, when they decide about the next stand.
Visitors who return
A day spent on relevant conversations is the experience that brings someone back to the next edition.
A data asset you keep
Visitor profiles, top queries and most requested stands, exportable and ready for marketing and for planning.
| Aspect | Matching from registration fields | StandVis |
|---|---|---|
| What builds the profile | Categories the visitor selects when signing up | The visitor's own company website, read directly |
| Effort for the visitor | A form completed before the event | A QR code and one line, on site |
| Setup for the organiser | Registration flow and platform aligned in advance | Site and registration system stay as they are |
| Form of the result | A ranked list | Ranked stands, each with the reason written out, plus a route |
| When it can be added | Planned into the edition | Also during an edition already on sale |
Bring us your exhibitor catalogue, and we will show you exactly what your visitors would receive.
Ask for informationProduct for product security and compliance
TARA-AI
Know what your risk analysis is missing while the design is still open, not when certification is under way.
Context and need
A connected product sold in the European Union needs a structured cybersecurity risk analysis, and that analysis has to keep describing the product as the design moves on. IEC 62443-3-2 sets the process for industrial systems, ISO/SAE 21434 for automotive, and from 2027 the Cyber Resilience Act makes it a condition for placing a product on the market.
These analyses grow quickly. A device with a few dozen identified assets produces thousands of entries, because every asset multiplies across security properties, attack surfaces and threat categories. Software generates them well, and the tools on the market are priced around that generation. The review is the part that still costs senior hours, and it is the part that decides whether the analysis holds at certification.
Solution and approach
It Starts From The Analysis You Have
Bring it in the form you keep it, spreadsheet included. There is no migration into a new tool before it can tell you something useful.
Three Measurements
Internal consistency, so that mitigations and the threats they answer agree with each other. Coverage, measured against reference catalogues including MITRE ATT&CK for ICS. And completeness, against what IEC 62443-3-2 and ISO/SAE 21434 formally require.
A Prioritised Queue
Findings arrive in the order that deserves attention, one decision at a time, with the context needed to make it. Your analysts spend their hours on judgement, which is the part only they can supply.
Your Engineer Decides, And The Record Shows It
Every finding is accepted, changed or rejected by a person, and each decision is stored with the state it replaced. That record is the audit trail a certification review asks for, produced by doing the work.
Grounded, Not Generic
Where the system reasons over the model, it combines a deterministic rule engine with retrieval grounded on a curated security knowledge base, so what it produces stays inside what the catalogues and the standards actually say.
Result and value created
Found while it is still cheap to fix
A finding raised during design is resolved inside the design phase, with the launch date untouched.
Senior hours on judgement
Your analysts spend their time deciding rather than reading, which is where their experience pays.
An audit trail that writes itself
Each decision is recorded with its previous state, ready for a certification review.
| Task | Threat modelling tools | Review by hand | TARA-AI |
|---|---|---|---|
| Producing the threat model | Their main purpose | Possible, and slow | Supported, and it also accepts yours |
| Measuring an existing analysis | Outside their scope | Depends on the reader and the day | The reason it exists |
| Internal consistency | Checked while the model is written | Found by reading everything | Reported across the whole set |
| Coverage against catalogues | Offered as a library to draw from | Compared manually | Measured, and reported as gaps |
| Audit trail of decisions | Version history of the model | Kept separately | Each decision with the state it replaced |
| Starting point | A new model in their format | The document you have | The document you have, spreadsheet included |
TARA-AI is in early access. We are running it with a small number of teams on analyses they already hold.
Bring one analysis you already rely on, and we will go through what it tells us, together.
Ask for informationWhich One Fits Your Case
We are designing a connected product and the programme has to reach the market on time.
TemperCrate
We already have devices in the field and updating them is a manual operation.
TemperCrate
Our exhibitors ask what return their stand produced.
StandVis
Our fair generates no data about who the visitors are and what they came for.
StandVis
Our product falls under the Cyber Resilience Act and we hold a risk analysis nobody has measured.
TARA-AI
Certification is approaching and we want to know now what the analysis is missing.
TARA-AI
Questions We Are Asked
What does TemperCrate add to an over-the-air update tool?
Over-the-air updating is one part of it. TemperCrate also creates the device identity during manufacturing, inside the board's secure element, ships its agent inside the signed system image, and writes a verifiable record of every operation. It is designed to be present from the first build, so one system covers the product's whole service life.
Does the Cyber Resilience Act apply to my product?
If your product has digital elements and you place it on the European Union market, in general yes, with the main obligations from 2027. In practice you demonstrate how the product is secured and kept secure across its life, which is straightforward when identity, signed updates and an audit trail are designed in from the start.
Does StandVis require changes to our registration system?
No. StandVis is reached through a QR code and runs in the browser, and the visitor profile is built from their company website. Your site and registration flow stay as they are, which is why it can be added to an edition already on sale.
Can TARA-AI work with a risk analysis we already have?
Yes. It takes the analysis in the form you keep it, spreadsheet included, and reports internal consistency, coverage against the reference catalogues, and completeness against IEC 62443-3-2 and ISO/SAE 21434. Your analyst decides what to do with each finding.
What does an engagement start with?
A thirty minute call in which you describe the product, the fair or the analysis in front of you. We come back with the fit, what the first step would cover, and what it requires from your side.
Tell Us What You Are Working On
At Graftholders we are your allies. If one of these three fits your case, we will show you how. If it does not, we will say so and point you towards what does. Either way you leave with a clearer picture than the one you arrived with.
info@graftholders.com
linkedin.com/company/graftholders
Graftholders Srl
Via Cesare Battisti 49
Prata di Pordenone (PN), CAP 33080
