Peace of mind you can hold.
Hardware-attested security for the operators running work that matters. FIPS 140-3 Level 3. On-device keypad. Tamper-evident and epoxy-sealed. The Nebbos MCP ships on the device — physical presence gates every elevated action.
Get the highlights
Five commitments. One device.
Encryption
FIPS 140-3 L3
Federally-certified encrypted storage volume. AES-256 XTS.
Authentication
On-device keypad
PIN entry never traverses the host machine. Physical, isolated.
Ruggedness
IP68 · MIL-STD-810G
Waterproof, dust-tight, shock-tested. Field-deployable.
Tamper
Epoxy-sealed
Physical break-in required to open; the seal is the evidence.
Supply chain
TAA-compliant
No adversarial-jurisdiction components. Procurement-ready.
Take a closer look
Every layer designed to be trusted.
Encrypted volume
AES-256 XTS ciphertext at rest. Federal-tier key management with per-device unique wrapping keys. FIPS 140-3 Level 3 certified.
On-device keypad
PIN entered on the device itself, not on the host. A compromised host cannot capture the PIN. Programmable read-only and self-destruct modes for regulated deployments.
Tamper-evident, epoxy-sealed
Any physical intrusion is visible. The internal electronics are potted in place; extraction breaks the seal and voids attestation. There is no invisible way in.
IP68 waterproof, MIL-STD-810G shock
Full immersion, dust-tight, drop-tested to military-grade standards. Field-deployable in regulated, defense, and disaster-recovery contexts.
TAA-compliant supply chain
No components sourced from adversarial jurisdictions. Meets US federal Trade Agreements Act procurement requirements. Chain-of-custody documented from manufacture to activation.
The core
The MCP lives on the device.
The Nebbos MCP is the tool substrate that mediates every elevated action across the Nebbos platform. On other systems it would run in a cloud you can’t see.
On the Nebbos USB, the MCP binary and every credential ship on the encrypted volume. Plug in, authenticate on the keypad, and the MCP starts. Unplug, and elevated permissions are no longer available. The MCP goes where you go — nowhere else.
Built for
The operators running work that must not leak.
Governments
Classified and sensitive workloads.
Regulated enterprises
Finance, healthcare, energy, defense contractors.
Founder operators
The people building the substrate the rest run on.
Values
Three factors. Composed top-down.
Biometric
Approve every action with your device.
Touch ID · Face ID · Windows Hello · Android BiometricPrompt. The private key never leaves your Secure Enclave. No password, no phishable secret, no shared token.
Physical presence
The USB is the second factor.
Elevated tier operations require the Nebbos USB physically plugged in. A remote attacker cannot forge presence — the mount is the assertion.
Enclave-signed
Admin operations pass through the enclave.
Cross-boundary reads, substrate mutations, and quorum-required actions require an enclave-signed approval token. Multi-party ceremonies supported for the highest-consequence changes.
Choose your tier
Three tiers. Twelve total SKUs across the four products.
Each Nebbos USB ships in the tier you buy — L1 basic, L2 privileged, L3 admin. Higher tiers unlock more of the MCP surface, gated by the composition of biometric + USB + enclave-signed approval below.
L1 · Basic
Nebbos USB hardware with basic-tier attestation and encrypted personal store.
Factors · Device-native biometric (Touch ID · Face ID · Windows Hello · Android BiometricPrompt)
Includes · One-time hardware purchase; annual attestation renewal per device
L2 · Privileged
Nebbos USB with privileged-tier attestation, Shell-write authority.
Factors · Biometric + Nebbos USB physical presence
Includes · One-time hardware purchase; annual attestation + Shell-write authority renewal
L3 · Admin
Nebbos USB with admin-tier attestation + enclave-signing authority.
Factors · Biometric + Nebbos USB + enclave-signed approval token
Includes · One-time hardware purchase; annual attestation + enclave-signing authority renewal
Ready to hold the substrate that runs your work?
Enterprise procurement, government agencies, and founder operators: reach out and we’ll walk you through provisioning, tiering, and deployment.
