Hardware-
Enforced.
Cloud-
Authorized.
Age verification, biometric authentication and telemetry. Built into the hardware, not bolted on. Every device and consumable is cloud-authorized and traceable. Verified, logged and secured at the silicon level.
Hardware-
Gesichert.
Cloud-
Autorisiert.
Altersverifikation, biometrische Authentifizierung und Telemetrie. In die Hardware integriert, nicht nachträglich aufgesetzt. Jedes Gerät und jedes Consumable ist cloudautorisiert und rückverfolgbar. Verifiziert, protokolliert und auf Siliziumebene gesichert.
硬件级安全管控。
云端授权认证。
年龄验证、生物识别认证与遥测内置于硬件,而非后期加装。每台设备和每个耗材均经云端授权且可追溯,在芯片级别完成验证、记录与安全保障。
THE GAP
REGULATORS FACE
DIE LÜCKE
IM SYSTEM
监管体系中的
合规漏洞
Traditional age verification happens at the point of sale, not at device activation. Once a product leaves the store, there is no mechanism to enforce compliance. XEO closes this gap permanently with hardware-level enforcement.
Traditionelle Altersverifikation findet am Point-of-Sale statt, nicht bei der Geräteaktivierung. Sobald ein Produkt das Geschäft verlässt, gibt es keinen Mechanismus zur Durchsetzung der Compliance. XEO schließt diese Lücke dauerhaft durch Hardwaredurchsetzung.
传统年龄验证仅发生在销售环节,而非设备激活时。产品一旦离开商店,便不存在任何合规执行机制。XEO通过硬件级强制执行,永久弥合这一漏洞。

Youth Access
Jugendschutz
未成年人获取
Devices reach minors after purchase with zero enforcement
Geräte gelangen unkontrolliert an Minderjährige
设备在售出后无任何管控即可到达未成年人手中
Device Sharing
Geräteweitergabe
设备转借
Resale and sharing bypass all age checks
Weitergabe umgeht alle Alterskontrollen
转售与共享完全绕过年龄核验
Counterfeits
Fälschungen
假冒伪劣
Refilled & counterfeit PODs contaminate supply chains
Nachgefüllte & gefälschte PODs in der Lieferkette
回灌与假冒烟弹污染供应链
Zero Monitoring
Kein Monitoring
零监控
No post-market monitoring after point of sale
Kein Post-Market-Monitoring nach Verkauf
售后无任何市场监测机制
Age is verified once against an identity document and the result is issued to the device as an authorisation. What sits in the device is the fingerprint check that binds that authorisation to the person who was verified. Hardware-enforced. Cloud-authorized. Fail-safe by design.
Das Alter wird einmal anhand eines Ausweisdokuments geprüft, das Ergebnis geht als Freigabe an das Gerät. Im Gerät sitzt die Fingerabdruckprüfung, die diese Freigabe an die geprüfte Person bindet. Hardwaregesichert. Cloud-autorisiert. Fail-safe by Design.
Age is verified once against an identity document and the result is issued to the device as an authorisation. What sits in the device is the fingerprint check that binds that authorisation to the person who was verified. 硬件级安全管控。云端授权认证。故障安全设计。

Your Fingerprint.
Your Device.
Your Authorization.
The person holding the device is the person who was verified. Authorisation is bound to the enrolled fingerprint and expires: the device re-checks the fingerprint on a configurable schedule, seven days by default, forces a network re-validation every thirty days, and can be made to re-check at any moment from the platform. No phone, no app, no workaround.
Dein Fingerabdruck.
Dein Gerät.
Deine Autorisierung.
Wer das Gerät in der Hand hält, ist die Person, die geprüft wurde. Die Freigabe ist an den hinterlegten Fingerabdruck gebunden und läuft ab: das Gerät prüft den Fingerabdruck nach konfigurierbarem Zeitplan erneut, standardmäßig alle sieben Tage, erzwingt alle dreißig Tage eine Neubestätigung über das Netz und kann jederzeit von der Plattform zu einer erneuten Prüfung veranlasst werden. Kein Telefon, keine App, kein Umweg.
您的指纹。
您的设备。
您的授权。
持有设备的人即为经过验证的人。Authorisation is bound to the enrolled fingerprint and expires: the device re-checks the fingerprint on a configurable schedule, seven days by default, forces a network re-validation every thirty days, and can be made to re-check at any moment from the platform. 无需手机,无需应用。
HOW XEO WORKS
WIE XEO FUNKTIONIERT
XEO 运作机制
Locked by DefaultStandardmäßig gesperrt默认锁定
Every device ships locked. No activation without the full authorization chain being completed.
Jedes Gerät wird gesperrt geliefert. Keine Aktivierung ohne vollständige Autorisierungskette.
每台设备出厂即为锁定状态。未完成完整授权链条,一律无法激活。
Biometric FingerprintBiometrischer Fingerabdruck生物指纹识别
User authenticates directly on-device. One-time registration via PWA. No phone dependency after initial setup.
Nutzer authentifiziert sich direkt am Gerät. Einmalige Registrierung per PWA. Danach kein Smartphone mehr nötig.
用户直接在设备上完成认证。通过 PWA(渐进式网页应用)一次性注册,初始设置后不再依赖手机。
Device ID VerificationGeräte-ID-Verifizierung设备 ID 验证
USB-C ID chip provides a cryptographic device identity bound to the hardware. A copied or transplanted identity fails verification against the registry.
USB-C-ID-Chip liefert eine kryptografische Geräteidentität, gebunden an die Hardware. Eine kopierte oder übertragene Identität scheitert an der Prüfung gegen das Register.
USB-C 身份芯片提供密码学设备身份,与硬件绑定,无法伪造或在设备间转移。
Optional: POD AuthenticationOptional: POD-Authentifizierung可选:烟弹认证
User + device is live today. Tri-factor mode (user + device + POD) is on the roadmap and at prototype stage; it will prevent counterfeit consumables from activating the device.
Nutzer + Gerät ist heute live. Der Trifaktormodus (Nutzer + Gerät + POD) ist Vorhaben im Prototypenstadium; er soll die Aktivierung durch gefälschte Verbrauchsmaterialien verhindern.
User + device is live today. Tri-factor mode (user + device + POD) is on the roadmap and at prototype stage; it will prevent counterfeit consumables from activating the device.
Cloud Issues Authorization TokenDie Cloud stellt das Freigabe-Token ausCloud Issues Authorization Token
The platform verifies every credential and requires the device to prove a hardware identity that cannot be read out, copied or transferred to another device. Only then is an authorization token issued. No token, no activation.
Die Plattform prüft jedes Merkmal und verlangt vom Gerät den Nachweis einer Hardware-Identität, die sich nicht auslesen, kopieren oder auf ein anderes Gerät übertragen lässt. Erst dann wird ein Freigabe-Token ausgestellt. Kein Token, keine Aktivierung.
The platform verifies every credential and requires the device to prove a hardware identity that cannot be read out, copied or transferred to another device. Only then is an authorization token issued. 无授权凭证,则无法激活设备。
Device ActiveGerät aktiv设备激活
Any failure returns the device to its locked state. LTE loss, removal, mismatch.
Bei Ausfall Rückkehr in den gesperrten Zustand. LTE-Verlust, Entfernung, Unstimmigkeit.
任何异常都会让设备回到锁定状态,如 LTE 断连、拆解、不匹配。
TWO WAYS
TO DEPLOY XEO
Both models share identical backend, telemetry, and security architecture. Every device runs the same cloud-authorized compliance stack regardless of form factor. Whether integrated into OEM hardware or deployed as a standalone module, XEO delivers uniform regulatory coverage from a single platform.
ZWEI WEGE
XEO EINZUSETZEN
Beide Modelle teilen identische Backend-, Telemetrie- und Sicherheitsarchitektur. Jedes Gerät nutzt denselben cloud-autorisierten Compliance-Stack unabhängig vom Formfaktor. Ob in OEM-Hardware integriert oder als eigenständiges Modul eingesetzt, XEO liefert einheitliche regulatorische Abdeckung über eine einzige Plattform.
XEO的
两种部署方式
两种型号共享相同的后端、遥测和安全架构。每台设备运行相同的云授权合规堆栈,与产品形态无关。无论集成到OEM硬件中还是作为独立模块部署,XEO都通过单一平台提供统一的监管覆盖。
External DownlinkExternal DownlinkExternal Downlink

Cloud-connected authorization layer via lightweight module. EXT-DL integrates with your existing product controller through a lightweight interface. The heater is enabled only with a valid authorisation, and the rest of your firmware stays untouched.
Cloud-verbundene Autorisierungsschicht über Leichtgewichtmodul. EXT-DL integriert sich über eine schlanke Schnittstelle in den vorhandenen Produktcontroller. Der Heizer wird nur mit gültiger Autorisierung freigegeben, die übrige Firmware bleibt unberührt.
通过轻量级模块实现云端连接授权层。EXT-DL integrates with your existing product controller through a lightweight interface. The heater is enabled only with a valid authorisation, and the rest of your firmware stays untouched.
- Integrates with your existing product controller, the rest of your firmware stays untouched
- Cloud-based real-time device authorization
- Geofenced compliance monitoring with violation alerts
- Compliance rules updated on the platform, with no firmware release
- API-first architecture (REST + Server-Sent Events)
- No changes to your existing production line; EXT-DL units arrive provisioned
- Compatible with existing MCU platforms
- 18 x 55 mm plus a 6 mm plug, USB-C powered, no internal battery
- LTE and Wi-Fi, cloud sync hourly by default, configurable from 10 minutes to 24 hours, forced network re-validation every 30 days
- Set-up runs through a web application served from the platform, with no app installation
- Estimated data volume under 5 MB per device per month, not yet measured on final hardware
- Integriert sich in Ihren vorhandenen Produktcontroller, der Rest Ihrer Firmware bleibt unberührt
- Cloudbasierte Geräteautorisierung in Echtzeit
- Geofencing-gestützte Compliance-Überwachung mit Verstoßmeldung
- Compliance-Regeln werden auf der Plattform geändert, ohne Firmware-Auslieferung
- API-First-Architektur (REST und Server-Sent Events)
- Keine Änderung an Ihrer bestehenden Fertigungslinie, EXT-DL-Einheiten kommen vorkonfiguriert
- Kompatibel mit vorhandenen MCU-Plattformen
- 18 × 55 mm zuzüglich 6 mm Stecker, Versorgung über USB-C, kein interner Akku
- LTE und WLAN, Abgleich mit der Cloud standardmäßig stündlich, konfigurierbar von 10 Minuten bis 24 Stunden, erzwungene Neubestätigung über das Netz alle 30 Tage
- Einrichtung über eine Webanwendung von der Plattform, ohne App-Installation
- Geschätztes Datenvolumen unter 5 MB je Gerät und Monat, nicht auf finaler Hardware gemessen
- 集成到您现有的产品控制器,其余固件保持不变
- Cloud-based 实时设备授权
- Geofenced 合规监控,含违规告警
- 合规规则在平台上更新,无需发布固件
- API-first 架构(REST + Server-Sent Events)
- 无需改动您现有的生产线;EXT-DL 单元出厂即已预配置
- 兼容现有 MCU 平台
- 18 × 55 mm 另加 6 mm 插头,USB-C 供电,无内置电池
- LTE 与 Wi-Fi,默认每小时与云同步,可配置为 10 分钟至 24 小时,每 30 天强制一次网络重新验证
- 通过平台提供的 web application 完成设置,无需安装 App
- 估计数据量低于每台设备每月 5 MB,尚未在最终硬件上实测
Designed to minimize incremental product-side integration. XEO EXT-DL keeps the reusable intelligence in the EXT-DL instead of duplicating it inside every compatible disposable. Keep the disposable architecture simple. Put the reusable intelligence in the reusable interface.
Darauf ausgelegt, den zusätzlichen produktseitigen Integrationsaufwand zu minimieren. XEO EXT-DL hält die wiederverwendbare Intelligenz im EXT-DL, statt sie in jedem kompatiblen Einwegprodukt zu duplizieren. Die Einweg-Architektur bleibt einfach, die wiederverwendbare Intelligenz sitzt in der wiederverwendbaren Schnittstelle.
旨在最大限度减少产品侧的额外集成工作。XEO EXT-DL 将可复用的智能保留在 EXT-DL 中,而非在每个兼容的一次性产品中重复部署。保持一次性产品架构简单,将可复用的智能置于可复用的接口中。
On DeviceOn Device设备端

Direct firmware-level integration for maximum security. Ideal for new product lines and manufacturers seeking hardware-level compliance control.
Direkte Firmware-Integration für maximale Sicherheit. Ideal für neue Produktlinien und Hersteller mit höchsten Sicherheitsanforderungen.
直接固件级集成,提供最高安全性。适用于新产品线和寻求硬件级合规控制的制造商。
- Self-contained compliance module that integrates with your existing product controller
- Biometric age verification: identity check in the cloud, fingerprint verification on the device
- Tamper-resistant cryptographic device identity
- AEAD encrypted telemetry with local buffering
- Over-the-air firmware updates for Wi-Fi connected units
- Design target: authentication under 200 ms, not yet measured on final hardware
- Design target: under 3 % additional battery consumption, not yet measured on final hardware
- Eigenständiges Compliance-Modul, das sich in Ihren vorhandenen Produktcontroller integriert
- Biometrische Altersverifikation: Identitätsprüfung in der Cloud, Fingerabdruckprüfung auf dem Gerät
- Manipulationsresistente kryptografische Geräteidentität
- AEAD-verschlüsselte Telemetrie mit lokaler Zwischenspeicherung
- Firmware-Updates aus der Ferne für Geräte mit WLAN-Verbindung
- Designziel: Authentifizierung unter 200 ms, nicht auf finaler Hardware gemessen
- Designziel: unter 3 % zusätzlicher Batterieverbrauch, nicht auf finaler Hardware gemessen
- 独立 compliance 模块,可集成到您现有的产品控制器
- Biometric 年龄验证:身份核验在云端,指纹验证在设备端
- Tamper-resistant 加密设备身份
- AEAD 加密遥测,带本地缓冲
- Over-the-air 固件更新,适用于已连接 Wi-Fi 的设备
- Design target:认证低于 200 ms,尚未在最终硬件上实测
- Design target:额外电池消耗低于 3 %,尚未在最终硬件上实测
Designed in at the architecture stage. XEO EMB puts identity, authentication and authorization into the product itself, with control over hardware, firmware and cloud from the first design review. The compliance layer is part of the platform, not an addition to it.
Von der Architekturebene an eingeplant. XEO EMB verankert Identität, Authentifizierung und Autorisierung im Produkt selbst, mit Kontrolle über Hardware, Firmware und Cloud ab dem ersten Design-Review. Die Compliance-Schicht ist Teil der Plattform, keine Ergänzung dazu.
在架构阶段即设计融入。XEO EMB 将身份、认证与授权植入产品本身,从首次设计评审起即掌控硬件、固件与云端。合规层是平台的组成部分,而非附加项。

Every Device.
Every Metric.
Live.
Encrypted data streams from every active device. Ingested and visualized in real time. The reporting interval is configurable per deployment, so it can be set to what a jurisdiction requires. Usage patterns, verification events, geographic compliance, puff-level analytics, and anomaly detection. Configurable alerts flag compliance deviations or unauthorized activations instantly. All telemetry is formatted for regulatory review and exportable for regulatory submissions. Turn post-market data into operational intelligence and supporting regulatory evidence.
Jedes Gerät.
Jede Metrik.
Live.
Verschlüsselte Datenströme von jedem aktiven Gerät. In Echtzeit erfasst und visualisiert. Das Sendeintervall ist je Einsatz konfigurierbar und lässt sich auf das einstellen, was ein Rechtsraum verlangt. Nutzungsmuster, Verifizierungsereignisse, geografischer Compliancestatus, Zuglevelanalytik und Anomalieerkennung. Konfigurierbare Alerts melden Complianceabweichungen oder unautorisierte Aktivierungen sofort. Alle Telemetriedaten sind auditfähig und exportierbar. Aus Post-Market-Daten werden operative Erkenntnisse und Nachweise, die Ihre regulatorische Dokumentation stützen.
THE PLATFORM
ADVANTAGE
DER PLATTFORM-
VORTEIL
平台
优势

Patented.
Encrypted.
Tamper-Resistant.
Every XEO device carries a unique cryptographic identity burned into the silicon at manufacture. All telemetry is encrypted and authenticated on the device itself, with a key unique to that device. Every authorisation is bound to the individual device: before a token is issued or renewed, the device must prove a hardware identity that cannot be cloned or transferred. Records are append-only and hash-chained, with a daily signed root that can be verified on request. Any later alteration, backdating or fabrication is detectable.
Patentiert.
Verschlüsselt.
Manipulationsresistent.
Jedes XEO-Gerät trägt eine einzigartige kryptografische Identität, die bei der Fertigung in den Chip eingebrannt wird. Die gesamte Telemetrie wird auf dem Gerät selbst verschlüsselt und authentifiziert, mit einem Schlüssel, der nur für dieses Gerät gilt. Jede Freigabe ist an das einzelne Gerät gebunden: bevor ein Token ausgestellt oder erneuert wird, muss das Gerät eine Hardware-Identität nachweisen, die sich nicht klonen und nicht übertragen lässt. Datensätze sind append-only und hashverkettet, mit einer täglich signierten Wurzel, die auf Anfrage geprüft werden kann. Jede spätere Änderung, Rückdatierung oder Fälschung ist erkennbar.
专利保护。
全程加密。
抗篡改。
每台XEO设备在制造时即将唯一加密身份写入芯片。All telemetry is encrypted and authenticated on the device itself, with a key unique to that device. Every authorisation is bound to the individual device: before a token is issued or renewed, the device must prove a hardware identity that cannot be cloned or transferred. Records are append-only and hash-chained, with a daily signed root that can be verified on request. Any later alteration, backdating or fabrication is detectable.
FULL-STACK IN-HOUSE
FULL-STACK INHOUSE
全栈自主研发
From proof of concept to mass production. Hardware, firmware, cloud and apps. Compliance architecture designed, built and owned by XEO. XEO — satisfaction! engineered in Germany.
Vom Proof of Concept zur Massenproduktion. Hardware, Firmware, Cloud und Apps. Compliance-Architektur von XEO entworfen, gebaut und im Eigentum von XEO. XEO — satisfaction! engineered in Germany.
从概念验证到量产,涵盖硬件、固件、云端和应用。Compliance architecture designed, built and owned by XEO.XEO — satisfaction! engineered in Germany.

From Concept
To Mass Production.
In-House.
Silicon partnerships, custom chip architecture, embedded firmware, cloud infrastructure, and consumer apps. Compliance architecture designed, built and owned by XEO in Germany. Manufacturing partners in China and Taiwan. XEO — satisfaction! engineered in Germany.
Vom Konzept
Zur Massenproduktion.
Inhouse.
Siliziumpartnerschaften, eigene Chiparchitektur, Embeddedfirmware, Cloudinfrastruktur und Consumerapps. Compliance-Architektur, von XEO in Deutschland entwickelt, gebaut und gehalten. Fertigungspartner in China und Taiwan. XEO — satisfaction! engineered in Germany.
WHERE XEO
STANDS TODAY
September 2026. The platform runs: device authorisation, age verification, telemetry, the append-only audit log and the regulator portal. Devices are in engineering validation, and firmware for the current board has not yet run on final production hardware. Performance figures on this site are design targets unless stated otherwise, and capabilities still in development are marked as such.
WO XEO
HEUTE STEHT
Stand September 2026. Die Plattform läuft: Geräteautorisierung, Altersverifikation, Telemetrie, das append-only Audit-Log und das Behördenportal. Die Geräte sind in der technischen Validierung, und die Firmware der aktuellen Platine ist noch nicht auf finaler Serienhardware gelaufen. Leistungsangaben auf dieser Seite sind Designziele, sofern nicht anders vermerkt, und Fähigkeiten in Entwicklung sind entsprechend gekennzeichnet.
WHERE XEO
STANDS TODAY
September 2026. The platform runs: device authorisation, age verification, telemetry, the append-only audit log and the regulator portal. Devices are in engineering validation, and firmware for the current board has not yet run on final production hardware. Performance figures on this site are design targets unless stated otherwise, and capabilities still in development are marked as such.