Product
eMCP
vHSM
Garnet
Dyneemes
Buckypaper
Sylica
Nitride
Vault
SYLICA · CONFIDENTIAL VIRTUAL MACHINE FIRMWARE

An open-source UEFI firmware implementation that enables virtual machines to boot.

An enterprise confidential computing firmware distribution that enables organisations to verify and control the root of trust for their most sensitive workloads.

Up to ~30% less firmware code than OVMF
Bit-identical rebuilds from published source
Deterministic measurements for SEV-SNP and TDX
Signed releases · SBOM · enterprise lifecycle

Minimize what must be trusted. Verify what was built. Verify what is running.

Minimize what must be trusted

A reduced firmware profile: up to ~30% less privileged pre-OS code than the corresponding OVMF build.

SMALLER ATTACK SURFACE · SMALLER TCB
01
Verify what was built

Pinned source, toolchain and container produce a bit-identical CVMF.fd that anyone can rebuild and compare.

SOURCE → BINARY, INDEPENDENTLY VERIFIED
02
Verify what is running

Published expected measurements match against SEV-SNP or TDX attestation evidence from the live VM.

ATTESTATION → POLICY → KEY RELEASE
03

Why not just upstream OVMF?

REQUIREMENT
OVMF
SYLICA
Trusted computing base
General-purpose firmware, broad functionality
Reduced footprint, confidential computing only
Reproducible builds
Not a primary design goal
First-class: pinned toolchain and environment
Measurements
Available, not an enterprise trust anchor
Deterministic, release-controlled
Supply chain
Depends on distributor
Signed releases, SBOM, provenance
Lifecycle
Community / distribution dependent
Enterprise LTS with CVE response

One architecture, three targets

sylica-x86
NO CONFIDENTIAL COMPUTING

Conventional x86 VMs — same reduced, reproducible firmware, without memory confidentiality.

sylica-sev-oss
AMD SEV-SNP

Secure Boot enabled, Sylica boot manager; launch state verified through SNP attestation.

sylica-tdx-oss
INTEL TDX

UEFI inside the Trust Domain, contributing to its measured initial state.

Where teams use it

01
Confidential cloud workloads

Regulated and tenant-isolated workloads with less trust in the operator and hypervisor.

02
Attestation before secrets

Release keys and credentials only after the firmware measurement checks out.

03
Auditable infrastructure

Source revision, firmware hash and expected measurement as retained evidence.

04
Independent audits

Auditors inspect the source and rebuild the firmware themselves.

05
CI/CD verification

Build twice, fail on differing hashes — unverified firmware never ships.

06
Fleet standardization

One firmware layer across AMD and Intel hosts, pinned by hash.

Get started

Rebuild it yourself. Compare the hash.

Then talk to us about support, lifecycle and attestation policy.

Certifications & security
Certified ISO/IEC 27001
IT Security made in Germany — TeleTrusT