Early stage · working with energy-hardware design partners

Firmware you can trust, all the way to the field.

Embrium is secure, auditable update infrastructure built for energy hardware — solar inverters, BMS packs, EV chargers, and smart meters — so a bad release never means a fire, a fault, or a fleet of bricked devices.

The problem

In energy hardware, a firmware update is a promise you can't take back.

Most inverters, BMS packs, and chargers in the field today were updated with none of the safeguards their manufacturer would insist on for anything else that touches live power.

// no verification

Anyone can be the source.

Without signed releases, a BMS or inverter can't tell a legitimate firmware update from one that was intercepted or spoofed on the way to it.

// no rollback

Failure is physical, not just digital.

A bad update to a battery pack or inverter isn't just downtime — it's a safety event. No crash-safe recovery path means a software problem becomes a field incident.

// no record

Nothing is provable.

When something breaks in the field, there's no tamper-evident answer to what shipped, when, to which device, or who approved it — the exact record a grid-code or safety audit will ask for.

What Embrium is today

Four guarantees, built into every release.

Not a dashboard bolted on top of your existing pipeline — the foundation your energy hardware's update pipeline runs on.

01

Signed releases

Every update is cryptographically signed before it leaves your infrastructure, and verified on-device before it's ever installed on a live inverter, BMS, or charger.

02

Staged rollouts

Ship to 1% of your fleet before you ship to all of it. Catch a bad release while it's an incident, not a recall across thousands of deployed units.

03

Crash-safe rollback

If power drops mid-update, the device recovers to a known-good state on its own — no truck roll, no manual recovery, no field visit to a rooftop or substation.

04

Tamper-evident audit trail

A hash-chained record of every update, every device, every outcome — the safety and compliance record you can hand to an auditor, a DISCOM, or a customer.

How it works

Every release moves through the same five checkpoints.

No step is optional, and no device installs anything it can't verify for itself.

01

Build

Firmware compiled and packaged

02

Sign

Signed against your key hierarchy

03

Distribute

Staged out across the fleet

04

Verify

Checked on-device before install

05

Confirm

Recorded, or rolled back automatically

Where this is going

OTA is the foundation. Not the ceiling.

Every layer we build is meant to carry more weight later — the same trust foundation, extended further into how an energy-hardware fleet is run.

TODAY

Secure OTA for energy-hardware fleets

Signed, staged, recoverable, and provable updates for solar inverters, BMS packs, and EV chargers — the part of the lifecycle that fails silently until it doesn't.

NEXT

Fleet health, provisioning & compliance

The same trusted channel used to update a device is the natural one to monitor it, provision it, and generate the audit trail a grid-code or safety review needs.

EVENTUALLY

The default infrastructure layer for energy hardware

A single, trusted foundation an energy-hardware manufacturer runs their entire fleet's lifecycle on — from first boot to last update.

Who it's for

Built for energy-hardware manufacturers, not managed by them.

If your devices carry live power and stay in the field for years, this is infrastructure you'll eventually need — built now, instead of assembled under pressure after an incident.

Solar & inverter manufacturers

Firmware that respects grid-code compliance windows, with rollouts that won't take a fleet of inverters offline at once.

BMS & battery storage

Update-safety gating tied to real device state, so a firmware push never lands outside a safe charge or thermal window.

EV charging infrastructure

Update a thousand chargers in a week with no visible impact on drivers — and a full record of what shipped, when.

Get early access

Join the waitlist.

We're onboarding a small number of energy-hardware teams first. Add your details and we'll reach out when there's room for your fleet.

Why join now

Early partners help shape the roadmap and get priority access as we open up capacity.

→ Priority onboarding when a slot opens
→ Direct input into the product roadmap
→ First access to fleet health & provisioning

We're early — and looking for the right first energy-hardware partners.

Embrium isn't generally available yet. We're working closely with a small number of solar, storage, and EV-charging hardware teams building the real thing with us.