An open-source UEFI firmware implementation that enables virtual machines to boot.
An enterprise confidential computing firmware distribution that enables organisations to verify and control the root of trust for their most sensitive workloads.
Minimize what must be trusted. Verify what was built. Verify what is running.
A reduced firmware profile: up to ~30% less privileged pre-OS code than the corresponding OVMF build.
Pinned source, toolchain and container produce a bit-identical CVMF.fd that anyone can rebuild and compare.
Published expected measurements match against SEV-SNP or TDX attestation evidence from the live VM.
Why not just upstream OVMF?
One architecture, three targets
Conventional x86 VMs — same reduced, reproducible firmware, without memory confidentiality.
Secure Boot enabled, Sylica boot manager; launch state verified through SNP attestation.
UEFI inside the Trust Domain, contributing to its measured initial state.
Where teams use it
Regulated and tenant-isolated workloads with less trust in the operator and hypervisor.
Release keys and credentials only after the firmware measurement checks out.
Source revision, firmware hash and expected measurement as retained evidence.
Auditors inspect the source and rebuild the firmware themselves.
Build twice, fail on differing hashes — unverified firmware never ships.
One firmware layer across AMD and Intel hosts, pinned by hash.
Rebuild it yourself. Compare the hash.
Then talk to us about support, lifecycle and attestation policy.
.png)
