Here's what we can show about how the identity core works, and why each property matters — without exposing the parts that would help someone attack it.
Most digital identity — API keys, certificates, model credentials — is data. Data can be copied, extracted, or replayed by anything that reaches it. UBIQS roots identity in a physical property of the silicon itself: something that exists because of how the chip was made, not something written into it afterward. There is no master key sitting in memory or flash waiting to be found. Nothing is stored to steal.
Most authentication schemes require both sides to hold something matching — a password, a certificate, an enrollment record. UBIQS verifies identity from a public reference alone: no per-device secret is held by whoever is checking, and no enrollment record has to exist anywhere in advance. A device can prove it's real the moment it's built, without either side trusting a stored value.
The last decade of major security failures — firmware exploits, credential theft, supply-chain compromise — happened in the software and firmware layer, because that's where identity has always lived. UBIQS moves the root of trust off that plane entirely, onto the physical device itself. A compromised operating system, application, or even firmware cannot forge, export, or replay this identity, because there is nothing stored there to take.
An invasive attempt to extract or probe the identity-deriving structure doesn't yield a clean copy. The attack disturbs the very physical property being read, so the attempt corrupts the thing it's trying to steal rather than exposing it. There's no clean extraction path — only a failed one. Combined with there being no stored secret to begin with, this is what makes the identity unclonable: not hardened against copying, but structurally unavailable to copy.
An AI agent's authority is only as strong as the identity behind it. If that identity lives in software, it inherits every attack that lives in software — an agent can be impersonated as easily as a credential can be copied. Anchoring agent identity in physical hardware means an agent's actions can be traced back to a specific, non-forgeable device — a foundation that credentials, tokens, and model weights alone can't provide.
The specific physical mechanism behind identity derivation isn't published here — for the same reason a lock manufacturer doesn't publish the exact tolerances of its pins. The properties above are what matter for evaluating the system; the implementation details are exactly what would help someone attack it. What's on this page is what we stand behind publicly. Deeper technical review is available under NDA for design partners and investors.