Secure Element
Infineon SLC39x
Form Factor
USB-A / USB-C
FIDO2 Protocol
CTAP 2.3 target
Certification Path
FIPS 140-3 L2 target
DISCRETE TOKEN ARCHITECTURE
Why a discrete bridge, not integrated USB?
Custodia Pro™ separates the USB interface from the secure element by design. The secure element communicates over ISO 7816, while a discrete USB-to-ISO 7816 bridge handles host protocol translation.
This keeps the secure-element boundary cleaner, reduces integration risk, and gives OEMs more control over certification, lifecycle management, and long-term platform ownership.


OEM Programme
Custodia™ Pro packages secure-element hardware, Javelin™ OS, applet support, and certification planning into an OEM-ready white-label platform.

White-Label Programme
White-label token platform under your control
Standard security keys leave OEMs and system integrators with limited control over firmware, applet extensibility, lifecycle policy, and long-term roadmap ownership. Custodia™ Pro closes that gap.
Full Industrial Design Ownership
Custom housing geometry — shape, size, form factor
Surface color, material, tactile texture
Laser marking, lanyards, bespoke packaging
No jNet branding unless you choose it
Sovereign Trust Ownership
ISD key ownership transfers to the partner
jNet cannot inspect partner-controlled code
Partner controls full post-issuance lifecycle
SCP02, SCP03, SCP11a/b/c key management
OEM Programme Deliverables
Full GP Security Domain hierarchy documentation
SCP11-provisioned root keys
Sample CPM policy set
JavaCard Eclipse IDE Plug-in
Joint Engineering Engagement for custom SSD / applet co-development
Partner Hardware Matrix
Four SKUs. One platform
All SKUs share the same Javelin™ OS foundation and GP Security Domain architecture. Silicon and OS version determine PQC and biometric capability.
PLATFORM SPECIFICATIONS
Parameter
Specification
Form factor
USB Type-A, USB Type-C (optional dual connector)
Secure element
Infineon SLC39x (EAL6+ silicon, FIPS 140-3 Level 2 target)
SE ↔ USB bridge
Discrete USB-to-ISO 7816 bridge IC (contact interface to SE)
JavaCard OS
Javelin™ OS v3.0.5 / v3.2
GlobalPlatform
GP 2.4 with Amendment A, B, C, F
FIDO2 protocol
CTAP 2.3 (certification target Q2 2026)
FIDO transport
USB HID (CTAPHID), NFC (optional variant)
PIV / NIST
SP 800-73-5, FIPS 201-3, up to 25 key slots
OpenPGP
OpenPGP 3.4 — sign, decrypt, authenticate
Crypto wallet
BIP32/44, ECDSA, EdDSA, Schnorr, Keccak-256
OATH
TOTP / HOTP — RFC 6238/4226, up to 32 credentials
Key storage
RSA 2048/4096, ECC P-256/P-384/P-521, secp256k1, Ed25519
PIN policy
Configurable PIN length 4–16 digits, PUK, retry counters, policy-controlled reset flows
Preloaded applets
FIDO2, PIV, OpenPGP, Crypto Wallet, OATH (TOTP / HOTP)
Security
Secure Boot, SCP03, Domain Firewall, CPM Policy Engine
Certifications (target)
FIPS 140-3 Level 2 (Q1 2027), CC EAL6+ (achieved), FIDO2 CTAP 2.3 (Q2 2026)
Operating temperature
-25 °C to +70 °C
Made in
EU / Global supply chain
Partner Hardware Matrix
Four SKUs. One platform
All SKUs share the same Javelin™ OS foundation and GP Security Domain architecture. Silicon and OS version determine PQC and biometric capability.
Pro C NFC
Platform Overview
Pro C NFC is the reference platform for secure USB-C and NFC deployments. It combines Javelin™ OS with the Infineon SLC39 secure element and provides a production-ready foundation for enterprise authentication, digital identity and secure access applications.
PLATFORM SPECIFICATIONS
Silicon
SLC39
Interface
USB-C + NFC
Javelin OS
JavaCard v3.2 /
GlobalPlatform v2.3.1
PQC
—
Fingerprint
—
FIDO
CTAP 2.3
FIPS 140-3
L3 target Q1 2027
FIDO Certification
Q2 2026
Status
Ref HW Available
