




Zymbit security modules provide multiple layers of physical and digital protection for your digital assets, managed through a simple API.

Zymbit manufacturing tools and services help you transition to volume manufacturing quickly and securely.
| Private / public key pairs | 3 | 
| Cryptographic Services | TRNG  (NIST SP800-22)  ECC NIST P-256 (secp256r1) ECDSA (FIPS186-3) AES-256 (FIPS 197)  | 
	
| Tamper Sensors | 2 x Perimeter breach detection circuits Main power monitor  | 
	
| Software API | Python, C++, C | 
| Physical Format | Plug in mini-hat (pins 1 - 10) | 
| Dimensions | 39.0 x 14.0 x 5.3 mm  1.53 x 0.55 x 0.21 Inches  | 
	
| Board Connectors | 
               GPIO: 5x2pin header, 0.1inch   Perimeter: 12pin JST 0.8mm receptacle (mates with JST 12SUR-32S) Battery: 2pin JST 0.8mm receptacle (mates with JST 2SUR-32S)  | 
	
| Host Interface | Always encrypted channel with ephemeral ECC keys I2C, default address, user changeable GPIO4, user changeable  | 
	
| Production mode lock | Software API command | 
| Measured system identity & authentication | Standard factors include RPI host, SD card, Zymkey | 
| Data encryption & signing applications. | Encrypt root file system with dm-crypt, with LUKS key manager hook  Encrypt data blobs with "zblock" function Encrypt data in flight with OpenSSL integration  | 
	
| Real time clock | 24-36 month operation, application dependent, 5ppm accuracy. | 
| Backup battery | Used for RTC and perimeter circuits  Requires JST connected coin cell, RPI 5 RTC battery , or similar, (not included) Recommend  | 
	
| Backup battery monitor | Yes | 
| Last Gasp battery removal detection | No | 
| OEM Custom features | Contact Zymbit | 
| Example Cipher Suites | AWS-IOT | TLS_ECDHE_ECDSA_AES256_SHA  MS-AZURE | TLS_ECDHE_ECDSA_AES_128_GCM_SHA256_P256  | 
	
| Accessories & related products | Backup battery, perimeter cables | 
| Warranty | 18 months | 
| Compatibility | Pi Zero, 4, 5 | 
| ZYMKEY ZERO plug-on module  | 
		ZYMKEY4 plug-on module  | 
		HSM4 encapsulated module  | 
	|
|---|---|---|---|
| 				
                                  = Standard feature  = OEM feature. Contact sales  | 
		![]()  | 
     	![]()  | 
		![]()  | 
	
	 COMPUTE PLATFORM SUPPORT  | 
		ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Raspberry Pi 4,5, ZERO_2W | |||
| Raspberry Pi CM4,5 | |||
| Nvidia, Intel, Other |  KEY STORAGE | 
  	         ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Generate secure key pairs  Private key never exposed  | 
		|||
| Secure element, tamper resistant key store | |||
| Private/public key pairs | 3 | 3 | 3 |  CRYPTOGRAPHIC PRIMITIVES | 
	        ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| TRNG (NIST SP800-22) | |||
| ECC NIST P-256 (secp256r1) | |||
| ECDSA (FIPS186-3) | |||
| AES-256 (FIPS 197) | |||
| TAMPER DETECTION SENSORS | 
                 ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Perimeter breach detection circuits - standard | 2 | 2 | 2 | 
| Accelerometer shock & orientation sensor | |||
| Power rail monitor | |||
| SOFTWARE API | 
                 ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Python | |||
| C++ | |||
| C | |||
| INTERFACES | 
                 ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Host Communications | I2C, GPIO  Always encrypted channel  | 
		I2C, GPIO  Always encrypted channel  | 
		I2C, GPIO  Always encrypted channel  | 
	
| Physical Format | MiniHat | MiniHat | Module | 
| Connectors | GPIO: 10pin header Perim: 12pin JST 0.8mm receptacle Battery: 2pin JST 0.8mm receptacle  | 
		GPIO: 10pin header  Perim: 5pin microusb  | 
		All: 30pin Hirose DF40HC | 
	
| Production-Mode lock | Software API | Cut Tab | 
		Software API | 
| DEVICE MULTI-FACTOR IDENTITY  & AUTHENTICATION  | 
                 ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Host hardware measurement | |||
| Custom authentication factors |  DATA ENCRYPTION & SIGNING | 
		ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
|  Encrypt root file system with dm-crypt  LUKS key manager hook  | 
		|||
| Encrypt data blobs with "zblock" function | |||
| Encrypt data in flight with OpenSSL integration |  OTHER FEATURES | 
		ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| True Random Number Generator | |||
| Real Time Clock | |||
| Backup battery - for RTC and perimeter circuits | Offboard  2pin JST 0.8mm receptacle  | 
		Onboard | Offboard  30pin Hirose DF40HC  | 
	
| Backup battery monitor | |||
| OEM Custom features (min 10K units) |  EXAMPLE CIPHER SUITES | 
	ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| AWS-IOT | TLS_ECDHE_ECDSA_AES256_SHA | |||
| MS-AZURE | TLS_ECDHE_ECDSA_AES_128_GCM_SHA256_P256 |  ACCESSORIES | 
                 ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Developer Kits | |||
| Custom Integrations |  READY TO GET STARTED? | 
	
                 ZYMKEY ZERO | ZYMKEY4 | HSM4 | 
| Learn more> | Learn more > | Learn more > | |
| PRE ORDER | BUY NOW | BUY NOW | |
= standard feature = OEM feature. Contact sales  | 
   
	|||