Login
User Agreement & LicensingPrivacy Policy
FIPS 140-3
Common Criteria EAL5+

Products

  • ProvenHSM
  • ProvenBox
  • Native Security Applications
  • Software Developer Kit (SDK)
  • ProvenCore OS and TEE
  • ProvenVisor

Use Cases

  • Data Protection
  • PQC Migration
  • Key Management & Cloud KMS
  • Confidential Computing
  • Finance Innovation
  • Digital Signature (eIDAS 1.0)
  • Wallet & Identity (eIDAS 2.0)
  • Multi-Party Computation (MPC)
  • Enterprise PKI
  • Strengthening HPC Platforms

Resources

  • Blog and Whitepapers
  • Security and Certifications
  • Integrations

Company

  • Careers
  • About
All customer stories

Eviden (BullSequana SH) — High-performance computing

Strengthening HPC Platform Integrity with ProvenCore

Metal Processor
Bull Logo

Company

Eviden (BullSequana SH)

HQ

Les Clayes-sous-Bois, France

Industry

High-performance computing

Focus

Secure boot, firmware integrity, BMC hardening

Products used

  • ProvenCore
The question we could never answer with code review alone was what happens on the next controller generation. Formal verification turned that into a property we carry forward, rather than an argument we have to rebuild every time the hardware moves.
Full nameJob title

Key outcome

A Formally Verified Root of Trust for Mission-Critical Workloads

The management controller is the one component that outlives every other piece of firmware on a supercomputing node — and the one an attacker most wants. Moving its trust decisions into a formally verified kernel makes platform integrity a property of the design rather than of the review process.

More customer stories

Digital Cloud
OVH Cloud Logo

Cloud infrastructure

Running Sovereign Key Management on Certified Infrastructure

Digital Lock
Orange Logo

Telecommunications

Securing Secure Element Provisioning at Carrier Scale

The challenge

Stringent Assurance Requirements Across Evolving Hardware

Hardening a controller by review scales with the size of the codebase, and the codebase kept growing. Each new controller generation reopened questions the previous review had already answered, because nothing in the architecture prevented untrusted code from reaching the parts that mattered.

What was needed was a boundary that held by construction across hardware revisions, rather than an audit repeated per generation.

The solution

ProvenCore as the Security Foundation

ProvenCore isolates the security-critical elements of the BMC from untrusted code paths, so the verified secure-boot chain and firmware integrity checks run in a minimal, mathematically proven environment rather than alongside the full OpenBMC stack.

The results

Measurable Gains Across Platform Generations

The isolation boundary now carries forward unchanged from one hardware revision to the next, so each generation inherits the previous evaluation instead of restarting it. Signed updates and anti-rollback protection sit inside that boundary rather than beside it.

The practical gain is schedule: security sign-off stopped being the step that decided when a platform generation could ship.

Security sign-off used to be the step that decided when a platform generation could ship. It is not any more.
— Full name, Eviden (BullSequana SH)
Next storyOVHcloud
Digital Processor
Renault Logo

Automotive

Hardening Connected Vehicle Gateways and OTA Updates

Explore ProvenHSM
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo