AkkuratCoreNo Logo Placeholder
Cybersecurity

AkkuratCore

AkkuratCore, based in Dresden’s Silicon Saxony, licenses a hardware security architecture that enforces protection in silicon rather than software. It physically separates application and security domains using Dielectric Trench Isolation (DTI), irreversible E‑Fuse rule fixation, and non‑galvanic Boundary Crossing Points (BCP), delivering node‑agnostic, physically provable security across process nodes. Partners integrate the IP into their own chips (no fab or wafer capex, high‑margin), serving critical infrastructure (KRITIS), smart‑meter gateways, automotive ECUs, industrial automation, and AI‑agent hardware to meet EU Cyber Resilience Act and NIS2 requirements. IP status: German utility model active (DPMA), European patent application filed; counsel Dennemeyer & Associates.

More About AkkuratCore

Founded:
Total Funding:
Funding Stage:
Pre-Seed
Industry:
Cybersecurity
In-Depth Description:
AkkuratCore™ is a Dresden-based semiconductor IP company developing a licensable security architecture that enforces protection physically, in silicon geometry, rather than through software. The architecture separates application and security domains via three physical mechanisms: Dielectric Trench Isolation (DTI), irreversible E-Fuse-based rule fixation, and non-galvanic Boundary Crossing Points (BCP). The security ratio remains node-agnostic across all process nodes, shifting the security proof from statistical probability to physical certainty. German utility model active (DPMA), European patent application filed, IP counsel Dennemeyer & Associates. Target markets include critical infrastructure (KRITIS), smart-meter gateways, automotive ECUs, industrial automation, and AI-agent hardware — driven by the EU Cyber Resilience Act and NIS2, which require physical security evidence operators and manufacturers cannot achieve through software alone. AkkuratCore operates a semiconductor IP licensing model — partners integrate the architecture into their own chip designs, comparable to established semiconductor IP houses. No own fab, no wafer capex, structurally high-margin. Based in Dresden, Germany — Silicon Saxony, Europe's largest semiconductor cluster.
AkkuratCore

AkkuratCore Review (Features, Pricing, & Alternatives)

If your team builds silicon for critical systems, you already know the limits of software-only security. Patches never end, attackers move faster than certification cycles, and auditors increasingly ask for hardware proof, not promises. AkkuratCore is a new kind of semiconductor IP that leans into that reality. Instead of trusting privilege rings, hypervisors, or constant updates, it enforces separation and policy physically, in silicon geometry. In this review and overview, I’ll walk you through what AkkuratCore is, how it works at a high level, where it fits, what you should expect from pricing, and which alternatives to consider alongside it.

Based in Dresden, Germany—right in the heart of Silicon Saxony—AkkuratCore operates with a traditional IP licensing model. You license the architecture, integrate it into your own chip, and manufacture as usual. There’s no wafer capex or foundry lock-in, and the company is positioning itself squarely at the intersection of European regulatory push (NIS2, EU Cyber Resilience Act) and markets where physical assurance is becoming mandatory: critical infrastructure, smart-meter gateways, automotive ECUs, industrial automation, and the edge of AI-agent hardware.

What does AkkuratCore do?

AkkuratCore provides a licensable security architecture for system-on-chips that physically separates application and security domains. Instead of relying on software to keep secrets safe, it uses three on-silicon mechanisms—dielectric trench isolation, one-time fuses that lock rules permanently, and non-galvanic boundary crossings—to enforce which parts of a chip can ever interact and how. In short: it builds a physical wall between “what runs your app” and “what protects your system,” then locks the doors and controls the intercom.

AkkuratCore Features?

The promise of AkkuratCore is simple to say and nontrivial to execute: use silicon geometry and irreversible rules to keep a security domain unreachably separate from the rest of the chip while still enabling strictly controlled, auditable communication. Here’s how that maps into practical features your team can evaluate.

1) Physical domain separation in silicon

AkkuratCore’s core idea is to divide the chip into at least two domains: a security domain (for trust anchors, keys, policy engines, attestation, etc.) and an application domain (for OS, user code, AI workloads, controls). The separation is achieved not just by logic design but by how the chip is physically laid out. The goal is to make accidental coupling and deliberate bypass paths infeasible by construction, not merely unlikely under software assumptions.

  • What it means for you: fewer “what if the kernel is compromised?” scenarios. You architect the chip so that misbehaving software can’t cross a moat it never had a bridge to.
  • Why it matters: auditors and regulators increasingly ask for physical evidence. A layout-level separation is tangible and measurable.

2) Dielectric Trench Isolation (DTI)

DTI is the physical moat. Trenches of dielectric material isolate regions on the die so that transistors in one region are not electrically coupled to transistors in the other. This is a long-standing technique in semiconductor manufacturing; AkkuratCore repurposes it as a security primitive.

  • Benefit: reduces parasitic paths and leakage that could become side channels or fault injection vectors across domains.
  • Considerations: the trenches consume area and influence floorplanning. Your physical design team must plan early so timing, power distribution, and clocking stay clean across domains.

3) Irreversible E-Fuse-based rule fixation

Policies and boundary rules are set and then permanently locked via e-fuses. Once blown, they cannot be reversed. This prevents a malicious update, debug mode, or manufacturing misstep from undoing the separation or altering inter-domain access control after bring-up.

  • Benefit: creates a clear “before and after” lifecycle—flexibility in development, finality in production. Ideal for mass-deployed devices where rollback risk is unacceptable.
  • Considerations: one-way is one-way. You’ll need tight provisioning procedures, golden images, and secure test plans to avoid bricking or misconfigurations.

4) Non-galvanic Boundary Crossing Points (BCP)

The two domains still need to communicate. AkkuratCore uses non-galvanic crossing—no direct metal wires carrying DC current between the security and application domains. Think capacitive, inductive, or similarly decoupled coupling, with strict protocolization.

  • Benefit: reduces surface for voltage glitching, injection attacks, and unintended coupling. Controlled crossings mean fewer surprises in lab fault tests.
  • Considerations: crossings are intentionally constrained. Expect carefully specified bandwidth, handshake, and buffering models. Latency and throughput must be budgeted early, especially for high-rate attestation or key derivation flows.

5) Node-agnostic “security ratio”

AkkuratCore emphasizes that its physical assurances scale with process nodes. The “security ratio” (a conceptual measure of physical separation relative to device geometries) is designed to remain robust as you move from mature nodes to advanced nodes. For you, that means the architecture aims to keep its strength even as transistors shrink.

  • Benefit: roadmaps stay aligned—no lock-in to a single foundry node to maintain the same physical guarantees.
  • Considerations: your foundry’s DRC and PDK rules still matter. Early DFM review is essential to maintain target ratios while retaining yield.

6) From statistical probability to physical certainty

Traditional secure design often relies on probabilistic models: the chance that randomization or obfuscation holds, that certain attacks are too costly, or that software isolation remains intact. AkkuratCore’s pitch is to replace those with physically enforced boundaries and one-time locks so that the “proof” is less about statistics and more about geometry and fuses.

  • Good for: operators under the EU Cyber Resilience Act or NIS2 who must present clear, testable evidence of physical security controls during audits.
  • Also helpful: safety-critical flows where common-cause failure analysis benefits from cross-domain decoupling.

7) Compliance and certification support

While certification outcomes depend on your complete product, AkkuratCore’s approach aligns with the trend regulators and notified bodies prefer: demonstrable, tamper-evident boundaries and restricted attack surfaces. Combining DTI, e-fuse locks, and non-galvanic crossings helps you explain and show why an exploit in the application domain cannot reach roots of trust or credential stores.

  • Use cases: smart-meter gateways in regulated energy grids, automotive ECUs under UNECE R155/R156 contexts, industrial controllers where KRITIS classifications apply.
  • Documentation: expect to integrate physical design evidence (layout annotations, fuse state logs) into your audit packages.

8) Integration into your SoC flow

AkkuratCore is licensed IP, not a fab. You bring it into your RTL-to-GDS flow, place the security and application domains per guidance, wire up boundary crossings, and bake fuse controls into your provisioning steps. In practice, the heavy lifting is in physical design, security architecture, and test development.

  • Architecture: define what lives in the security domain (keys, secure boot, attestation, policy engine) and what stays in the application side.
  • Physical: commit to trenches early so floorplan, power islands, and clocking don’t fight your timing closure late in the schedule.
  • Provisioning: design secure fuse programming and verification at wafer sort or final test.
  • Verification: plan for cross-domain verification with fault injection tests at the interfaces and documented negative test cases.

9) Performance, area, and power trade-offs

Any physical isolation carries overhead. Trenches take area, non-galvanic crossings can gate bandwidth, and duplicated resources in the secure domain add transistors. That said, these costs buy you something software typically can’t: a simpler threat model and clearer evidence. If your volumes are high, the OPEX saved in field incidents, certification friction, and patching can outweigh silicon overhead.

10) Lifecycle and field operations

One of the practical upsides of fuse-locked policy is operational calm. Once devices leave the factory, the rules of your boundaries aren’t subject to change by field updates. That can de-risk OTA frameworks and reduce the blast radius of software bugs. On the flip side, your operations team needs a careful RMA and forensic plan, because post-mortem introspection into the secure domain should remain impossible by design.

11) Market focus and proof points

AkkuratCore targets markets where tamper resistance and auditability are essential: KRITIS-classified infrastructure, energy metering, automotive, industrial controls, and AI-edge systems managing sensitive data or autonomy signals. The company holds an active German utility model (DPMA) with a European patent application filed and lists Dennemeyer & Associates as IP counsel—useful context for OEMs who care about IP pedigree and freedom-to-operate checks.

12) Business model, support, and pricing

AkkuratCore follows a conventional semiconductor IP licensing model. That typically means a combination of one-time license fees and per-unit royalties, plus design-in support. Because there’s no manufacturing, it’s structurally a high-margin business, which usually translates to responsive support for integration and audits.

  • Pricing: as with most security IP, expect quote-based pricing that depends on scope, node, and volume. Budget for NRE (license + integration support) and per-unit royalties.
  • Engagement: plan a technical discovery call early to align on your node, PDK, security partitioning, and timeline. Ask for app notes and reference floorplans.
  • Legal: coordinate your licensing team on field-of-use terms and indemnities that match your market certifications and volumes.

13) Who is AkkuratCore best for?

  • Device makers under NIS2/CRA scrutiny who need physical evidence of isolation.
  • OEMs whose threat model assumes OS/hypervisor compromise at some point in life.
  • Teams that can afford a small area and planning overhead to simplify attack surfaces and audits later.
  • Products with long lifecycles where policy finality is a virtue, not a constraint.

14) Potential drawbacks to weigh

  • Irreversibility reduces flexibility. Once fuses are blown, policy changes require a new lot or stepping.
  • Physical design complexity increases. Early alignment between architects, PD, and test is non-negotiable.
  • Interface bandwidth is finite. Non-galvanic crossings must be sized and scheduled.
  • It won’t fix insecure software. It merely stops software from reaching places it should never touch.

AkkuratCore Top Competitors

If you’re exploring AkkuratCore, you’ll likely compare it against three broad categories: CPU-based isolation (TEEs), root-of-trust IP blocks with on-chip firewalls, and PUF/key-management solutions. Each solves overlapping but different pieces of the problem. Here are notable options and how they stack up conceptually.

1) Arm TrustZone + CryptoCell (and PSA ecosystem)

Arm TrustZone splits a CPU into Secure and Normal worlds with monitor-mode transitions, supported by Arm’s Platform Security Architecture and companion IP like CryptoCell for cryptography.

  • Strengths: widely adopted, strong toolchain support, mature ecosystem, software flexibility.
  • Trade-offs: isolation is architectural and software-mediated; physical separation is not the core primitive. Well-hardened but still bounded by shared resources and software correctness.
  • When to pick: mobile/embedded SoCs on Arm where TEEs meet your audit requirements and cost is king.

2) Rambus Root of Trust IP (e.g., RT-6xx series)

Rambus offers configurable roots of trust with secure boot, key storage, tamper protections, and isolation features, integrating as IP into SoCs.

  • Strengths: comprehensive security feature sets, DPA-resistant cryptography options, lifecycle tooling.
  • Trade-offs: isolation is often achieved via bus firewalls and privilege controls rather than physical trenches and non-galvanic paths.
  • When to pick: you want a proven RoT IP with rich crypto/security services and robust certification track records.

3) Synopsys tRoot/ARC Secure IP + AMBA/AXI firewalls

Synopsys provides secure enclave IP, ARC processors with SecureShield, and system security IP including interconnect firewalls.

  • Strengths: integrates deeply with popular EDA flows, offers system-level protection and configurable compartmentalization.
  • Trade-offs: relies primarily on logical isolation and interconnect policies; physical domain separation is not the headline mechanism.
  • When to pick: you prefer a single-vendor stack from IP through tools and are optimizing digital controls over physical moats.

4) Secure-IC Root of Trust and security subsystems

Secure-IC delivers RoT IP cores, attack detection, and secure services for embedded SoCs, often with formal threat modeling support.

  • Strengths: holistic view of HW security, integrates countermeasure libraries and attack sensors.
  • Trade-offs: similar to others, base isolation is logical; physical isolation is typically not the defining primitive.
  • When to pick: comprehensive countermeasure set and active attack monitoring are top priorities.

5) Silex Insight eSecure Root of Trust

A modular RoT IP offering secure boot, key storage, and crypto accelerators with configurable isolation and lifecycle control.

  • Strengths: well-structured RoT features, flexible integration.
  • Trade-offs: again, focused on logical and protocol-level enforcement rather than geometric isolation.
  • When to pick: you need a capable RoT and already have a trusted firewall/interconnect strategy.

6) Intrinsic ID (SRAM PUF) and PUFsecurity/eMemory

PUF-based IP derives unique device keys from silicon characteristics, removing the need for injected secrets and aiding secure identity.

  • Strengths: strong device-unique keys without NVM, reduces key-at-rest risk.
  • Trade-offs: PUFs secure key material, not the whole isolation story. They pair well with, but don’t replace, a domain-separation architecture.
  • When to pick: you prioritize unclonable identities and key management, potentially alongside an isolation scheme like AkkuratCore.

7) On-chip interconnect firewalls and NoC-based isolation (Arm AMBA firewalls, Arteris security options)

Many SoCs deploy AXI/APB firewalls and secure NoC features to isolate masters/slaves and enforce policy in hardware.

  • Strengths: granular access control, good for partitioning peripherals and accelerators.
  • Trade-offs: still galvanic, still shares silicon fabric, and typically depends on configuration correctness and software policy.
  • When to pick: cost-sensitive designs where logical segmentation suffices for your risk and audit posture.

8) Discrete secure elements (NXP EdgeLock, Microchip ATECC series)

Off-chip security chips store keys, perform crypto, and attest the host across an external interface (I2C, SPI).

  • Strengths: quick add-on, proven certifications, clear lifecycle controls.
  • Trade-offs: adds BOM and supply chain complexity, vulnerable bus surfaces, latency, and not an on-die physical separation.
  • When to pick: retrofits, low-to-medium security needs, or when SoC redesign isn’t viable.

9) Custom, in-house hardening and trenches

Larger semiconductor houses sometimes build bespoke physical separations and analog-hardened interfaces.

  • Strengths: tightly tailored to your SoC and threat model.
  • Trade-offs: expensive, time-consuming, and tough to audit consistently. Knowledge loss and maintenance risk are real.
  • When to pick: top-tier volumes and a dedicated internal security silicon team.

Where does AkkuratCore sit? It’s most distinct from the TEE/RoT crowd in that it makes the physical boundary the first-class security primitive. It can complement many of the above—pairing a physically separated security domain with a robust root of trust and PUF-derived keys makes sense in high-assurance designs. If your audits and markets demand hardware evidence and you’re comfortable paying some area and planning overhead, AkkuratCore becomes compelling.

Wrapping Up

AkkuratCore takes a refreshing, back-to-basics stance: if you don’t want your application world to touch your security world, don’t connect them. Carve the die with dielectric trenches, cross the gap only through non-galvanic channels, and lock the rules with one-time fuses. That shifts your argument from “our software is strong” to “our silicon doesn’t let software try.” For European OEMs facing NIS2 and the Cyber Resilience Act, that’s a powerful audit story.

Is it for everyone? No. If you’re shipping cost-sensitive consumer IoT with modest risk, conventional TEEs and interconnect firewalls may be “good enough” and faster to integrate. If you need maximum post-deployment flexibility, one-way fuse locks might feel too rigid. And if your physical design team is stretched thin, you’ll need vendor support and schedule room to get the floorplan and crossings right.

But if you build KRITIS-class systems, smart-meter gateways, automotive ECUs, industrial controls, or AI agents that handle sensitive decisions, the math changes. A smaller, better-defined attack surface and stronger audit evidence can beat the marginal mm² and an extra week of floorplanning. The technology aligns with modern certification expectations and fits naturally into a semiconductors-as-licensed-IP business model—no fab, no capex, and the freedom to choose your node while keeping a consistent level of physical assurance.

Before you decide, consider asking the AkkuratCore team the following:

  • Process/node readiness: Which PDKs and foundries have been validated or guided? Any DRC nuances for trenches?
  • Crossing characteristics: Bandwidth, latency, error detection, and resilience to voltage/clock glitches.
  • Area/power budget: Typical overhead ranges for a reference partitioning comparable to your SoC scale.
  • Provisioning flow: Best practices for fuse programming, verification, and failure handling during test.
  • Verification kits: Fault-injection test guidance, formal proofs, and documentation you can reuse in audits.
  • Coexistence: How to pair the architecture with roots of trust, PUFs, or existing TEE software stacks.
  • Lifecycle: RMA procedures, forensic strategies that preserve isolation, and field update implications.

If you want to move security from a patch treadmill to a physical boundary, AkkuratCore is worth a serious look. The company is rooted in Europe’s biggest semiconductor cluster, Silicon Saxony, and operates with a familiar IP licensing model that should fit most SoC business plans. For more details or to engage their team, you can visit the official site at akkuratcore.com.

Bottom line: AkkuratCore won’t eliminate the need for good software, but it can change the rules of engagement by making some classes of software attack irrelevant to your most sensitive secrets. In a world where regulators demand proof and attackers search for soft boundaries, that’s a strong proposition.