
Access control for the machines
Know who enters your factory and control what machines they may power and use. Authorise it, block it, and prove it, even without any available network.
Most industrial equipment has no login, no screen and no IP address. It has a key switch, a padlock, and a paper logbook. Trust-Buster adds a trust layer around it without opening it, modifying it, or connecting it to any network.
Trust-Buster for Compliance and Cybersecurity

Why you need it
Friday, 23:20. A five-axis machine starts up in a shared workshop. It runs for forty minutes, produces eleven parts, and stops. On Monday, someone notices.
Who started it? The building badge proves someone entered the building. It says nothing about the machine. The machine's hour counter says forty minutes — unattributed, unsigned, reset at the last service.
With Trust-Buster, starting that machine requires three things at once: the person is physically present, their identity is proven by hardware, and the intervention was planned. All three, or nothing. The log entry is signed: who, which machine, when, under which rule, allowed or denied.

What you actually buy
The hardware on your site
The Cube — the decision unit. A fixed appliance with radio sensors and communications, installed per room, per building or per cabinet. It holds the policy, evaluates it locally, signs the log, and commands the effectors. It carries a secure element for hardware-rooted identity.
Effectors — the enforcement points. Small units that sit outside the machine, on its power cable. One per controlled outlet. They enforce what the Cube decides and nothing else: the physical button is decoupled from the relay, so pressing it signals intent rather than issuing a command.
Credentials. A radio badge carried by the person, and a mobile app for approval workflows and for carrying policy updates and logs to and from offline sites.

How it decides
The Cube establishes three certainties before authorising anything. Any one of them missing means denial.
Detection. The Cube continuously observes its radio environment and knows which enrolled devices and people are nearby. This is an entry condition, not an identity claim.
Identity. A cryptographic challenge answered by a key held in a secure element. Not a number broadcast by a badge, and not something an imitation produces.
Validation. The right person is still not enough. The Cube checks that this action, on this machine, at this time, matches a planned intervention.
Actions. The effector releases or cuts power, verifies the resulting state, and logs it. Unplugging, rewiring or resetting a controlled outlet is itself an event: the zone locks, the incident is recorded with its reason.
Navigating Regulatory Challenges with Ops-Devices Systems
Understanding the Regulatory Context
NIS2 and the Cyber Resilience Act (CRA) make asset inventory, OT risk management and incident evidence mandatory, with heavy penalties. Trust-Buster, the system built on the Ops-Devices platform, turns these obligations into an operated, on-site capability: inventory, access control and a signed audit trail, managed for you. You stay focused on operations and your compliance evidence writes itself.
Ops-Devices: trust, anchored in hardware
Our platform empowers Trust-Buster operations, relying on a physical appliance, the Cube, as a communications & sensors gateway that secures any equipment even if it has never been designed for authentication. It recognizes what and who is actually present, only authorizes actions from an approved set of rules, and acts on its own — on site, even when disconnected from any network. Any attempt at physical bypass is detected, the perimeter locks down, and the incident is logged.
Designed and developed in Europe. Operational sovereignty: no data leaves your site, no third-party cloud, no remote kill-switch, full air-gap operation. Our supply chain is publicly documented.
Who Trust-Buster is for
For industrial operators and critical infrastructure. Factories, energy, water, transport, sites subject to NIS2 and IEC 62443. You operate equipment that was not designed with cybersecurity in mind and cannot simply be replaced. Your supervision teams (SOC) need to extend their visibility and control all the way to the physical boundary — where software tools stop.
For field operators and defense environments. Sites without reliable connectivity, by constraint or by doctrine. You need a trust chain and an action capability that work autonomously, without relying on the cloud, and whose sovereignty is non-negotiable.
More broadly, for anyone who must control “who can activate or use which equipment, where, and when” — and know, without ambiguity, when someone attempts to bypass it.
a picture is worth a thousand words
Secure your future now!
Our key assets

Design strengths
Five decisions, and what each one costs
Every architecture is a trade-off. Here are ours, with the bill attached.
Identity lives in hardware. A badge answers a cryptographic challenge from a secure element certified Common Criteria EAL5+ — a certification carried by the component itself. No shared secret on a server to steal. Cost: a lost badge is revoked, not reset.
The decision is taken on site. No cloud, no server that has to answer for a machine to start. A site cut off for three days runs exactly as designed. Cost: no live dashboard — policy and logs travel by phone.
Enforcement sits outside the machine. Effectors clip onto the power cable. Nothing installed inside, CE marking intact, removable without a trace. Cost: we govern the path to the machine, not what happens inside it.
It fails to denial. Every failure lands de-energised; no breakdown opens an access. Cost: someone who wants to stop your line rather than get into it can jam the band. Better said now than discovered in month three.
Built in Europe, sourcing published — including the decisions we reversed when a supplier changed hands. Cost: a narrower supplier list, and sometimes a slower roadmap.
None of the five is unique alone. We have not found another system that makes all five at once — if you know of one, we would like to see it.
Physical access remains physical access, and no radio monitoring proves the absence of a signal it never saw. What changes is that an attempt stops being invisible.

Proof demo on request
See if you can break it
We will not describe our security to you. We will let you try to break it.
You take the intruder's seat, facing a real machine on a controlled outlet. No script, no briefing, no demo mode. Press the outlet's button, unplug it, plug the machine in elsewhere, rewire it directly, reset the unit, show up without a valid identity, ask for access outside your window.
At each attempt the system reacts in front of you — cut-off, alert, lockdown — then tells you what it saw in your gesture and why it refused. Some attempts will work. We show you those too, and what we are doing about them.
You leave with a signed audit log of your own attempts: your future incident report, written live by a volunteer attacker.
Practical: around 90 minutes, at your site or ours. Bring your most sceptical colleague, and your own tools if you have them. Useful attendees: whoever owns the machines, whoever owns compliance, and whoever will live with the false positives. Nothing is installed on your equipment.
Trust-Buster : See it to believe it
Team

Pascal FLAMAND
Lead
CEO and founder @JANUA - Now Open-IAM - since 2004, a company specializing in IAM (security, access control, identity management) and Open Source.
CEO and Founder @Samarcande since 2023, holding, acting as an investor in real business projects.

Julien HOLTZER
Technical Advisor
Passionate about electronics, embedded devices, research and development, building new hardware and software disrupting solutions.
15+ years of experience in Smart Cities and Smart Buildings, from concepts to implementations.
Frequently Asked Questions
Why Trust-Buster ?
Zero Trust usually stopped at the network. We’re taking it all the way to the power outlet.
Zero Trust — “never trust, always verify” — is the framework every cybersecurity buyer is expected to implement. But it stops at the logical layer: in front of an electrical cabinet, a 2009 PLC, or a wall socket, the paradigm no longer existed.
Our choice is to bridge this gap: we never rely on trust declared on packaging or in a datasheet. Our equipment is built to continuously monitor both users and hardware, providing proof of proper operation or detecting actions that would breach this trust—whether by mistake or design.
How does Trust-Buster prepare businesses for the Cyber Resilience Act?
By design rather than by consulting. The architecture follows IEC 62443-4-2 design principles (design target SL-C 2 - third-party evaluation not yet performed, and we say so), and every authorization, denial and incident produces a signed, time-stamped record, exportable to your SIEM. The signed audit log your NIS2 or CRA auditor will ask for is generated automatically, on site.
What exactly does Trust-Buster deliver?
Trust-Buster deploys an operated security capability built on sovereign hardware (the Ops-Devices platform). It includes the hardware (the Cube and its cutoff satellites) on your site, the support to enroll your equipment and people, to manage access policies signed, audit-ready evidences.
Is Trust-Buster the right fit for my needs?
Trust-Buster addresses critical situations: dangerous equipment, sensitive perimeters, binding compliance obligations, traceability you can defend in front of an auditor.
What is Trust-Buster and where is it based?
Trust-Buster is a services business specializing in cybersecurity and compliance solutions. The company is based in Sophia-Antipolis, France.
Want more technical details about the product ?
Please visit our technical infrastructure platform starting your journey at the public website: