Protocol data arrives
CTAP and management fields are bounded and parsed before they reach the display.
Open hardware · lab prototype
csiPass puts the site, operation, and account on its own display. The companion can configure the key. Only the glass and physical Confirm can approve it.
One trust surface
A compromised host can draw a convincing window. It cannot silently replace the relying-party identity shown by firmware or manufacture a fresh physical gesture after the request arrives.
CTAP and management fields are bounded and parsed before they reach the display.
Site, operation, and account are rendered by autonomous firmware, not mirrored from the host.
Success appears only after the cryptographic or protected management operation succeeds.
Optional companion
The local Go companion inventories passkeys and site-held records, enrols HOTP accounts, adjusts display preferences, and manages PIN/UV policy. Protected writes wait for the device.
Built for review
The firmware owns CTAPHID, CTAP2, CTAP1/U2F, Client PIN, credential management, encrypted records, local browsing, and the 172×320 trusted UI. The implementation is intentionally inspectable.
Current boundary
Registration, sign-in, management, and HOTP work in development builds. Release hardening and independent review still matter more than another feature checkbox.
Secure Boot v2, flash encryption, rollback-controlled signed recovery and update, production attestation/VID/PID, interoperability work, and certification are not complete. Use disposable test accounts only.
Track progressContact