OhhO Shield
Security for robots that touch the real world.
Security for robots that touch the real world. OhhO Shield gives every robot a hardware identity, encrypts its links, signs its updates, and watches its software bill of materials for vulnerabilities.
- Hardware-rooted device identity
- Mutually-authenticated encrypted links
- Signed OTA / secure boot
- SBOM + CVE monitoring
- Fleet-wide risk posture
What you get
A robot is a computer with wheels and an arm — and an attack surface to match. A compromised robot isn't a data breach; it's a physical-safety incident. OhhO Shield is the security layer for the whole fleet.
Shield gives each robot a cryptographic identity rooted in hardware, establishes mutually-authenticated, encrypted channels for teleop and telemetry, and signs every over-the-air update so a robot only ever runs code you approved.
It continuously inventories every robot's software bill of materials (SBOM), matches it against known CVEs, and surfaces a single risk posture across the fleet — turning security from a one-time audit into a live signal.
Built to do the hard parts for you
Each robot gets a hardware-rooted key and certificate — no shared passwords, no anonymous nodes.
Teleop, telemetry and ROS traffic run over mutually-authenticated, encrypted channels.
Secure boot and signed OTA ensure a robot only runs code with a valid signature.
An automatic software bill-of-materials per robot, continuously checked against vulnerability feeds.
Role-based, audited access to robots and the fleet console, with SSO on enterprise plans.
A live security score per robot and across the fleet, integrated into OhhO Fleet.
How it works
Each robot provisions a hardware-rooted key on first boot.
Shield establishes authenticated channels for all traffic.
OTA bundles are signed; robots verify before applying.
SBOM + CVE scanning feeds a live posture and alerts.
Specifications
- Identity
- Hardware-rooted keys + X.509 certs
- Transport
- Mutually-authenticated TLS / encrypted DDS
- Integrity
- Secure boot + signed OTA
- SBOM
- Per-robot, CVE-matched
- Access
- RBAC + audit log (SSO on Forge)
- Integrates
- OhhO Fleet, OhhO Pilot
Which plan do I need for OhhO Shield?
We recommend the Fleet plan. Any robot reachable over a network should at least be on Builder for encrypted links and signed updates. Fleets in production want Fleet for device identity and CVE monitoring; regulated or enterprise deployments choose Forge for secure boot and SSO.
Common questions
Encryption and verification are designed for embedded targets; the security overhead is negligible next to perception and control.
Yes. Shield layers onto standard ROS 2 / DDS and the ROSBridge transport OhhO Pilot uses.
Works better together
Ready to build with OhhO Shield?
Start free and simulate first — no hardware required. Upgrade when you're ready to deploy.