




Zymbit security modules provide multiple layers of physical and digital protection for your digital assets, managed through a simple API.

Zymbit manufacturing tools and services help you transition to volume manufacturing quickly and securely.
| Private / public key pairs | 3 |
| Cryptographic Services | TRNG (NIST SP800-22) ECC NIST P-256 (secp256r1) ECDSA (FIPS186-3) AES-256 (FIPS 197) |
| Tamper Sensors | 2 x Perimeter breach detection circuits Main power monitor |
| Software API | Python, C++, C |
| Physical Format | Plug in mini-hat (pins 1 - 10) |
| Dimensions | 39.0 x 14.0 x 5.3 mm 1.53 x 0.55 x 0.21 Inches |
| Board Connectors |
GPIO: 5x2pin header, 0.1inch Perimeter: 12pin JST 0.8mm receptacle (mates with JST 12SUR-32S) Battery: 2pin JST 0.8mm receptacle (mates with JST 2SUR-32S) |
| Host Interface | Always encrypted channel with ephemeral ECC keys I2C, default address, user changeable GPIO4, user changeable |
| Production mode lock | Software API command |
| Measured system identity & authentication | Standard factors include RPI host, SD card, Zymkey |
| Data encryption & signing applications. | Encrypt root file system with dm-crypt, with LUKS key manager hook Encrypt data blobs with "zblock" function Encrypt data in flight with OpenSSL integration |
| Real time clock | 24-36 month operation, application dependent, 5ppm accuracy. |
| Backup battery | Used for RTC and perimeter circuits Requires JST connected coin cell, RPI 5 RTC battery , or similar, (not included) Recommend |
| Backup battery monitor | Yes |
| Last Gasp battery removal detection | No |
| OEM Custom features | Contact Zymbit |
| Example Cipher Suites | AWS-IOT | TLS_ECDHE_ECDSA_AES256_SHA MS-AZURE | TLS_ECDHE_ECDSA_AES_128_GCM_SHA256_P256 |
| Accessories & related products | Backup battery, perimeter cables |
| Warranty | 18 months |
| Compatibility | Pi Zero, 4, 5 |
| ZYMKEY ZERO plug-on module |
ZYMKEY4 plug-on module |
HSM4 encapsulated module |
|
|---|---|---|---|
|
= Standard feature = OEM feature. Contact sales |
![]() |
![]() |
![]() |
COMPUTE PLATFORM SUPPORT |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Raspberry Pi 4,5, ZERO_2W | |||
| Raspberry Pi CM4,5 | |||
| Nvidia, Intel, Other | KEY STORAGE |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Generate secure key pairs Private key never exposed |
|||
| Secure element, tamper resistant key store | |||
| Private/public key pairs | 3 | 3 | 3 | CRYPTOGRAPHIC PRIMITIVES |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| TRNG (NIST SP800-22) | |||
| ECC NIST P-256 (secp256r1) | |||
| ECDSA (FIPS186-3) | |||
| AES-256 (FIPS 197) | |||
| TAMPER DETECTION SENSORS |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Perimeter breach detection circuits - standard | 2 | 2 | 2 |
| Accelerometer shock & orientation sensor | |||
| Power rail monitor | |||
| SOFTWARE API |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Python | |||
| C++ | |||
| C | |||
| INTERFACES |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Host Communications | I2C, GPIO Always encrypted channel |
I2C, GPIO Always encrypted channel |
I2C, GPIO Always encrypted channel |
| Physical Format | MiniHat | MiniHat | Module |
| Connectors | GPIO: 10pin header Perim: 12pin JST 0.8mm receptacle Battery: 2pin JST 0.8mm receptacle |
GPIO: 10pin header Perim: 5pin microusb |
All: 30pin Hirose DF40HC |
| Production-Mode lock | Software API | Cut Tab |
Software API |
| DEVICE MULTI-FACTOR IDENTITY & AUTHENTICATION |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Host hardware measurement | |||
| Custom authentication factors | DATA ENCRYPTION & SIGNING |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Encrypt root file system with dm-crypt LUKS key manager hook |
|||
| Encrypt data blobs with "zblock" function | |||
| Encrypt data in flight with OpenSSL integration | OTHER FEATURES |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| True Random Number Generator | |||
| Real Time Clock | |||
| Backup battery - for RTC and perimeter circuits | Offboard 2pin JST 0.8mm receptacle |
Onboard | Offboard 30pin Hirose DF40HC |
| Backup battery monitor | |||
| OEM Custom features (min 10K units) | EXAMPLE CIPHER SUITES |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| AWS-IOT | TLS_ECDHE_ECDSA_AES256_SHA | |||
| MS-AZURE | TLS_ECDHE_ECDSA_AES_128_GCM_SHA256_P256 | ACCESSORIES |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Developer Kits | |||
| Custom Integrations | READY TO GET STARTED? |
ZYMKEY ZERO | ZYMKEY4 | HSM4 |
| Learn more> | Learn more > | Learn more > | |
| PRE ORDER | BUY NOW | BUY NOW | |
= standard feature = OEM feature. Contact sales |
|||