Hardware-backed security

Security rooted
in hardware.

SupportTPM gives Windows software a device-bound security foundation using TPM 2.0—without requiring each software vendor to build and operate its own TPM integration.

First used in SupportRMM, our remote monitoring and management platform for Windows.

First used in SupportRMMRead about the reference implementation

Hardware-Backed Identity

Each installation is enrolled against a real TPM 2.0 device and receives a hardware-bound identity.

Hardware Enrollment

Trust is granted only after the platform proves possession of TPM-protected keys.

Protected Operations

Applications request scoped cryptographic capabilities through a local agent instead of integrating raw TPM APIs.

Hardware identityTPM-backed enrollment and a unique installation identity.
Protected operationsBind selected keys and application flows to the hardware root of trust.
Managed lifecycleEnrollment, binding, renewal, revocation and audited re-enrollment.
Simple integrationA local service hides TPM complexity behind a small application interface.

SupportTPM is hardware-backed by design. Security software can build on.

One local security layer

From TPM complexity to a usable application capability.

Windows exposes powerful TPM primitives, but integrating them safely requires device enrollment, key lifecycle logic, IPC, cloud coordination and recovery rules. SupportTPM centralizes that work in one managed platform.

No software fallback. The protected path requires a real TPM 2.0 device.
Local daily operation. Applications continue using enrolled capabilities without a permanent cloud dependency.
Scoped capabilities. A product requests only the operation or key context it has been designed to use.
The local protection path
Your softwareRequests a named protected capability.
SupportTPM AgentApplies product policy and manages the local security context.
TPM 2.0Hardware root for the non-exportable key hierarchy.
The managed service is used for enrollment, binding, lifecycle actions and audit. Normal protected operations remain local after enrollment.
How it works

A controlled lifecycle, not a single licence check.

SupportTPM turns hardware trust into a sequence of operational controls that a software product can actually use.

01 — Enroll

Establish the hardware identity

The agent proves control of TPM-protected keys and receives a unique installation identity.

02 — Bind

Authorize the product deployment

The enrolled installation is associated with the software deployment and its allowed capability policy.

03 — Request

Ask for a scoped capability

The application requests the specific local capability required by a database, signing or internal security flow.

04 — Operate

Make the feature depend on hardware

The protected workflow works only when the correct TPM-backed installation can reproduce the required capability.

SupportRMM
Remote Monitoring & Management

The first production reference implementation.

SupportRMM uses SupportTPM to make core data flows depend on a TPM-derived application capability instead of a simple Boolean licence result.

DB
Volatile database protectionMonitoring history and runtime telemetry are encrypted with a device-bound capability.
OFF
Offline-capable operationNormal monitoring and decryption continue locally after the installation is enrolled.
Safe hardware transitionWhen the hardware-derived key changes, non-critical volatile data is reset and rebuilt automatically.
Validated in a real product

Not a dashboard mockup. A running integration.

SupportTPM is being validated inside SupportRMM before third-party integration is opened. This provides real operational feedback across Windows systems, different TPM hardware and daily application workloads.

Active on real Windows installations and a production SupportRMM server.
Tested across multiple TPM 2.0 implementations on Windows 10 and Windows 11.
Visit SupportRMM
Application possibilities

One hardware root, multiple protection models.

The first implementation protects volatile application data. The same platform can support other product-specific security workflows as each lifecycle and recovery model is introduced.

Protected application state

Encrypt internal state or database fields so normal software operation depends on the enrolled device.

Reference implementation

Hardware-bound licensing

Replace a single patchable licence flag with application functions that require a valid hardware-backed capability.

Platform direction

Local file protection

Protect selected configuration or content with device-bound encryption and an explicitly designed recovery policy.

Future capability

Device-bound removable data

Encrypted removable content can be restricted to an authorized machine when the product defines durable recovery requirements.

Future capability

Signing and origin proof

Use hardware-backed signing contexts for scripts, commands or product-specific records.

Product-specific

Zero-trust device access

Authorize application or network operations based on an enrolled hardware identity rather than a copyable local secret.

Future integration

Current platform status

TPM agent and installer: operational on multiple Windows 10 and Windows 11 systems.
Hardware enrollment and binding: working through the managed cloud service.
SupportRMM integration: running as the first reference implementation.
Third-party SDK and vendor dashboard: not publicly available yet.
Durable-data recovery: introduced only when a dedicated recovery and redundancy model is ready.
About SupportTPM

A managed platform, currently Windows-first.

SupportTPM is being developed as a managed security service operated by SupportTPM. Software vendors integrate the application-facing layer; the platform manages enrollment, binding, lifecycle controls and audit.

The MVP is Windows-first because the reference implementation and current agent use Windows services, TPM 2.0 and local Named Pipe communication. This does not define the final platform as Windows-only.

Read the public technology notes

SupportTPM is being proven before it is sold.

The current site documents the technology and its first real implementation. Commercial access, pricing and third-party onboarding will follow only after the platform is consolidated.