Zero Trust starts at the factory, not the firewall.

Software-level Zero Trust gets most of the attention. Hardware-level trust — who built the board, and where — is the part most conversations skip.

Most cybersecurity conversations focus on protecting networks and software from attack, and treat the physical hardware underneath as a solved problem. It rarely is. Hardware-level security is easy to overlook precisely because it does not show up in a dashboard.

Who controls the production line

The first question worth asking a supplier is where manufacturing actually happens, and who controls that process. A vertically integrated manufacturer, with full control over its own board production, can make guarantees about tampering that a manufacturer several supply-chain layers removed from its own factory cannot.

Jurisdiction matters alongside vertical integration. Manufacturers based in countries with high security standards and stable export-control regimes are a materially different risk profile than supply chains that pass through jurisdictions where tampering with firmware, or embedding tracking hardware, is a documented concern for defence and municipal operators alike.

Fujitsu, and why component-level customisation matters

kHouse works closely with Fujitsu, a NATO-friendly manufacturer with its own factories in Japan and the EU building its own motherboards, running at 99.997% availability. Their laptops and desktops can be specified down to component level — cameras, USB ports, and other attack surfaces removed outright rather than merely disabled in software, where they could in principle be re-enabled.

A policy that trusts every request still has to trust the board the request runs on.

None of this replaces the software-level Zero Trust work. It is the layer underneath it — the one that makes "verify everything" a claim you can actually stand behind, instead of a policy document describing a network you are still trusting on faith.