Our Products

Three products for connected industry. One gives your device team the foundation for remote control and security. One turns a trade fair into qualified meetings. One measures the cybersecurity risk analysis you already hold. Each is available on its own, and each came out of a live client project.

Product for device and product teams

TemperCrate

The foundation your connected product needs, ready on day one, so your engineers spend their months on what customers are buying.

Context and need

Adding connectivity to a product adds four responsibilities to the programme before a single differentiating feature is written. Each device needs an identity that can be trusted outside your network. Software has to reach the installed base and keep a working version available. Equipment in the field has to stay in reach. And the evidence a certification body asks for has to exist in a readable form.

Those four are the same for every connected product, and they are where new hardware programmes lose their first months of senior engineering. The market has priced this clearly: remote update and application deployment are billed per device per month, published rates run from one to three euros, and identity provisioning at end of line is quoted around a dollar per device. What none of that covers is the internal build.

Solution and approach

Identity Created On The Production Line

Each device generates its private key on the board, inside the secure element, during manufacturing, and the key stays there. Devices join the platform because their identity chains back to your own certificate authority. Retiring a unit removes its access and leaves that identity intact.

Every Update Keeps A Way Back

System images are signed at build time and accepted only when authentic. Installation writes to a second slot, and if the new image does not come up the device returns to the one that worked. Releasing an update becomes a routine decision rather than an escalation.

System And Applications Travel Separately

They behave differently, so they take different routes. System images move through hawkBit to a RAUC client on the device. Applications move as signed containers through a registry, over encrypted MQTT, and run isolated with containerd.

Evidence Appears As Your Fleet Runs

Every action lands in a verifiable record, and each device signs its own logs before sending them. Logs are held on the device while it is offline and forwarded when the link returns, so the compliance file builds itself during normal operation.

Part Of The Image, From The First Build

The agent is compiled into the signed system image through a dedicated Yocto recipe, so it belongs to the device rather than sitting on top of it. Developers drive it from a command line, and whoever operates the fleet works from the dashboard.

Result and value created

Months back into the roadmap

Senior engineering that would build this foundation goes into the features your customers are paying for.

Service cost under control

A software correction is a remote action, and every release keeps a working version available on the device.

Market access secured early

Identity, signed updates and audit records are in place from the first build, which is what IEC 62443, NIS2 and the Cyber Resilience Act ask you to demonstrate.

How the four responsibilities are usually covered
What you needBuilding it in houseA generic device platformTemperCrate
Device identityDesigned and implemented per projectUsually assigned once the device is already in the fieldCreated on the production line, inside the secure element
System updatesBuilt and hardened by your teamIncluded, with rollback in the better productsSigned images, A and B slots, automatic return to the working version
ApplicationsCustom deployment mechanismOften on the same path as the systemSigned containers on a separate path from the system
Audit evidenceAssembled ahead of a reviewActivity logs, held centrallySigned by the device as it operates, ready to export
Where it livesInside your codebaseAn agent installed on the deviceInside the signed system image, from the first build

Tell us about the device you are designing, and we will show you what it looks like with this foundation in place.

Ask for information

Product for trade fair organisers

StandVis

Turn footfall into qualified meetings, and give exhibitors the return they weigh when they book the next edition.

Context and need

The meetings that make a fair worth attending are largely the ones nobody planned. A visitor arrives with limited hours and a floor plan they have not studied. An exhibitor invests in a stand and meets whoever passes. The organiser carries responsibility for the value both sides take home, with few levers to shape what happens between them.

Matchmaking platforms address this, and the market prices them accordingly: third party estimates put premium engines between five and twenty five thousand dollars per event, and enterprise licences between twenty and seventy nine thousand dollars a year plus a fee per registrant. Public customer references on one of the leading platforms report around four months to implement. Most of that time goes into aligning the registration flow, because the visitor profile is assembled from fields collected at sign-up.

Solution and approach

One QR Code, Nothing To Fill In

StandVis opens in the browser from a code printed on site. The visitor shares the address of their own company, or describes what they came for. No form, no account, and no dependency on your registration flow, which is why it can be added to an edition already on sale.

The Profile Comes From What The Company Publishes

StandVis reads that website and derives sector, products, materials and markets served. The visitor is recognised for what their company actually does, rather than for the categories they had time to tick when they registered.

Every Match Arrives With Its Reason

Each suggested stand carries the sentence that explains why it is relevant. People act on reasons, so the visitor can weigh each suggestion, and you can see the logic behind what your fair is recommending.

A Route Through The Day

The suggestions become an order: which stands, roughly when, and who to look for. Visitor hours are spent on conversations that had a reason to happen.

Your Fair Keeps The Knowledge

Exhibitors receive pre-qualified meetings, which is the evidence they look for at renewal. And you gain a picture the fair did not previously generate: who the visitors are, what they came for, which stands were asked for most. It exports, and it informs the next edition.

Result and value created

Renewals with evidence behind them

Exhibitors weigh pre-qualified meetings, not footfall, when they decide about the next stand.

Visitors who return

A day spent on relevant conversations is the experience that brings someone back to the next edition.

A data asset you keep

Visitor profiles, top queries and most requested stands, exportable and ready for marketing and for planning.

How visitors and exhibitors are usually matched
AspectMatching from registration fieldsStandVis
What builds the profileCategories the visitor selects when signing upThe visitor's own company website, read directly
Effort for the visitorA form completed before the eventA QR code and one line, on site
Setup for the organiserRegistration flow and platform aligned in advanceSite and registration system stay as they are
Form of the resultA ranked listRanked stands, each with the reason written out, plus a route
When it can be addedPlanned into the editionAlso during an edition already on sale

Bring us your exhibitor catalogue, and we will show you exactly what your visitors would receive.

Ask for information

Product for product security and compliance

TARA-AI

Know what your risk analysis is missing while the design is still open, not when certification is under way.

Context and need

A connected product sold in the European Union needs a structured cybersecurity risk analysis, and that analysis has to keep describing the product as the design moves on. IEC 62443-3-2 sets the process for industrial systems, ISO/SAE 21434 for automotive, and from 2027 the Cyber Resilience Act makes it a condition for placing a product on the market.

These analyses grow quickly. A device with a few dozen identified assets produces thousands of entries, because every asset multiplies across security properties, attack surfaces and threat categories. Software generates them well, and the tools on the market are priced around that generation. The review is the part that still costs senior hours, and it is the part that decides whether the analysis holds at certification.

Solution and approach

It Starts From The Analysis You Have

Bring it in the form you keep it, spreadsheet included. There is no migration into a new tool before it can tell you something useful.

Three Measurements

Internal consistency, so that mitigations and the threats they answer agree with each other. Coverage, measured against reference catalogues including MITRE ATT&CK for ICS. And completeness, against what IEC 62443-3-2 and ISO/SAE 21434 formally require.

A Prioritised Queue

Findings arrive in the order that deserves attention, one decision at a time, with the context needed to make it. Your analysts spend their hours on judgement, which is the part only they can supply.

Your Engineer Decides, And The Record Shows It

Every finding is accepted, changed or rejected by a person, and each decision is stored with the state it replaced. That record is the audit trail a certification review asks for, produced by doing the work.

Grounded, Not Generic

Where the system reasons over the model, it combines a deterministic rule engine with retrieval grounded on a curated security knowledge base, so what it produces stays inside what the catalogues and the standards actually say.

Result and value created

Found while it is still cheap to fix

A finding raised during design is resolved inside the design phase, with the launch date untouched.

Senior hours on judgement

Your analysts spend their time deciding rather than reading, which is where their experience pays.

An audit trail that writes itself

Each decision is recorded with its previous state, ready for a certification review.

Where TARA-AI sits next to the tools already in use
TaskThreat modelling toolsReview by handTARA-AI
Producing the threat modelTheir main purposePossible, and slowSupported, and it also accepts yours
Measuring an existing analysisOutside their scopeDepends on the reader and the dayThe reason it exists
Internal consistencyChecked while the model is writtenFound by reading everythingReported across the whole set
Coverage against cataloguesOffered as a library to draw fromCompared manuallyMeasured, and reported as gaps
Audit trail of decisionsVersion history of the modelKept separatelyEach decision with the state it replaced
Starting pointA new model in their formatThe document you haveThe document you have, spreadsheet included

TARA-AI is in early access. We are running it with a small number of teams on analyses they already hold.

Bring one analysis you already rely on, and we will go through what it tells us, together.

Ask for information

Which One Fits Your Case

We are designing a connected product and the programme has to reach the market on time.

TemperCrate

We already have devices in the field and updating them is a manual operation.

TemperCrate

Our exhibitors ask what return their stand produced.

StandVis

Our fair generates no data about who the visitors are and what they came for.

StandVis

Our product falls under the Cyber Resilience Act and we hold a risk analysis nobody has measured.

TARA-AI

Certification is approaching and we want to know now what the analysis is missing.

TARA-AI

Questions We Are Asked

What does TemperCrate add to an over-the-air update tool?

Over-the-air updating is one part of it. TemperCrate also creates the device identity during manufacturing, inside the board's secure element, ships its agent inside the signed system image, and writes a verifiable record of every operation. It is designed to be present from the first build, so one system covers the product's whole service life.

Does the Cyber Resilience Act apply to my product?

If your product has digital elements and you place it on the European Union market, in general yes, with the main obligations from 2027. In practice you demonstrate how the product is secured and kept secure across its life, which is straightforward when identity, signed updates and an audit trail are designed in from the start.

Does StandVis require changes to our registration system?

No. StandVis is reached through a QR code and runs in the browser, and the visitor profile is built from their company website. Your site and registration flow stay as they are, which is why it can be added to an edition already on sale.

Can TARA-AI work with a risk analysis we already have?

Yes. It takes the analysis in the form you keep it, spreadsheet included, and reports internal consistency, coverage against the reference catalogues, and completeness against IEC 62443-3-2 and ISO/SAE 21434. Your analyst decides what to do with each finding.

What does an engagement start with?

A thirty minute call in which you describe the product, the fair or the analysis in front of you. We come back with the fit, what the first step would cover, and what it requires from your side.

Tell Us What You Are Working On

At Graftholders we are your allies. If one of these three fits your case, we will show you how. If it does not, we will say so and point you towards what does. Either way you leave with a clearer picture than the one you arrived with.

Ask for information

info@graftholders.com
linkedin.com/company/graftholders

Graftholders Srl
Via Cesare Battisti 49
Prata di Pordenone (PN), CAP 33080

Contacts

Social Networks

Graftholders

Decluttering Cybersecurity Complexity
Embracing Security