Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › Security & Zero-Trust
Security & Zero-Trust

Supply-Chain Security for Hardware and Software

Components, firmware, and dependencies are verified for provenance before they enter the plant, because a tampered part defeats every runtime control downstream.

STRATEGY / SLOW ▲ ▼ MICROSECOND REAL-TIMEL7Ecosystem & Strategytelemetry ▲ control ▼open ▸L6Experience & Visualizationtelemetry ▲ control ▼open ▸L5Applications & Copilotstelemetry ▲ control ▼open ▸L4Orchestrationtelemetry ▲ control ▼open ▸L3Twin Modeling & AItelemetry ▲ control ▼open ▸L2Data Fabrictelemetry ▲ control ▼open ▸L1Control Planetelemetry ▲ control ▼open ▸L0Foundationtelemetry ▲ control ▼open ▸PHYSICAL S.M.A.R.T. GENERATOR PLANTBREEDER · HYPERION1R0 1.2 m · A 2.5 · 16.84 T · δ −0.30BURNER · TANDEM MIRROR2317 T throat · 26.49 T plug · fₙ 5.44% · DEC1 center stack + plasma · 2 high-field plug · 3 expander → direct converterCOLOR GRAMMAR strategy AI-workflow infra/data models reactor/DECLINE SEMANTICStelemetry (µs)controlKRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORMASTER BLUEPRINTSHEET 01REV. 2026-08L0-L7 · 2 MACHINES
The AI-Native S.M.A.R.T. Generator Master Blueprint — eight layers (L0→L7), one control stack, wired to both machines. Telemetry rises in microseconds; control descends the same path.

The trust starts before install

Runtime security assumes the hardware and software are what they claim to be. If an FPGA arrives with a subverted boot ROM, or a dependency ships with a backdoor, downstream secure boot and attestation are anchored to a lie. Kronos treats the supply chain as part of the attack surface: it verifies provenance of hardware, firmware, and software before they reach the OT environment.

Controls across the chain

Anchoring the root of trust in-house

Because field secure boot depends on fused keys, those keys are provisioned by Kronos during a controlled manufacturing step rather than trusting factory defaults. This means a compromised vendor cannot pre-load a key it controls into a device destined for the reactor. The provisioning ceremony itself is under separation of duties.

Honest residual

Deep hardware implants (malicious silicon) are the hardest supply-chain threat and cannot be fully excluded by inspection alone; Kronos mitigates with trusted sourcing, attestation, and behavioral monitoring, and accepts a residual risk that is documented in the threat model. Design status: SBOM, signing, and provisioning workflows are implemented for the toolchain and twin; hardware inspection and vendor programs are defined for the FOAK procurement, which begins ahead of Q2 2027 construction.

Content reviewed August 2026 · design-and-simulation stage