● LATEST ALERTS
XEOtech GmbH · Compliance Platform · Knowledge Base

FREQUENTLY ASKED
QUESTIONS

Everything manufacturers, regulators, and distributors need to know about XEO's hardware-enforced compliance platform.

XEOtech GmbH · Compliance-Plattform · Wissensdatenbank

HÄUFIG GESTELLTE
FRAGEN

Alles, was Hersteller, Regulierungsbehörden und Distributoren über die hardwaregestützte Compliance-Plattform von XEO wissen müssen.

XEOtech GmbH · 合规平台 · 知识库

常见问题
解答

制造商、监管机构和分销商需要了解的关于XEO硬件执行合规平台的一切信息。

FAQ
FAQ
常见问题

How does XEO help us maintain PMTA/TPMF compliance across our product portfolio?Wie hilft XEO uns, die PMTA/TPMF-Compliance über unser gesamtes Produktportfolio hinweg aufrechtzuerhalten?XEO如何帮助我们在整个产品组合中保持PMTA/TPMF合规性?

manufacturers +
XEO's hardware compliance technology embeds regulatory checkpoints directly into device firmware, providing documentation that supports FDA PMTA and TPMF submissions. Our system maintains append-only, hash-chained verification records, automates age verification workflows, and generates documentation that supports regulatory submissions and post-market reporting.Die Hardware-Compliance-Technologie von XEO integriert regulatorische Kontrollpunkte direkt in die Gerätefirmware und unterstützt Hersteller bei der Dokumentation für FDA PMTA- und TPMF-Einreichungen. Unser System verwaltet append-only und hashverkettete Verifizierungsaufzeichnungen, automatisiert Altersverifikations-Workflows und erstellt Dokumentation, die regulatorische Einreichungen und Post-Market-Monitoring-Verpflichtungen unterstützt.XEO的硬件合规技术将监管检查点直接嵌入设备固件中,支持每个单位在进入市场前符合FDA PMTA和TPMF要求的文档编制。我们的系统维护验证记录,自动化年龄验证工作流程,并生成支持监管审查的文档,支持监管提交并服务于上市后监测义务。

What is the difference between XEO EMB and EXT-DL, and which should we implement?Was ist der Unterschied zwischen XEO EMB und EXT-DL, und welche sollten wir implementieren?XEO EMB和EXT-DL之间有什么区别,我们应该实施哪一个?

manufacturers +
EMB is for new product lines that integrate at chip level; EXT-DL (External Downlink) is for existing product lines that are not being redesigned. The security architecture is identical.EMB ist für neue Produktlinien, die auf Bauteilebene integrieren; EXT-DL (External Downlink) ist für bestehende Produktlinien, die nicht neu entwickelt werden. Die Sicherheitsarchitektur ist dieselbe.EMB is for new product lines that integrate at chip level; EXT-DL (External Downlink) is for existing product lines that are not being redesigned. The security architecture is identical.

How long is the planned integration schedule for XEO into our manufacturing process?Wie lange ist der geplante Integrationsablauf für XEO in unseren Herstellungsprozess?XEO集成到我们制造流程的计划周期是多长?

manufacturers +
Planned integration schedule: 9 to 12 weeks for a device already in production, subject to the first hardware validation cycle. We provide comprehensive API documentation, dedicated technical support, and integration modules whose certified components carry their own regulatory approvals, supplied with the integration guide that keeps those approvals valid. The finished product is authorised as a whole by its manufacturer. Our integration team works directly with your engineering department to minimize disruption to production schedules.Geplanter Integrationsablauf: 9 bis 12 Wochen für ein Gerät, das bereits in Produktion ist, vorbehaltlich des ersten Hardware-Validierungszyklus. Wir stellen umfassende API-Dokumentation, dedizierte technische Unterstützung und Integrationsmodule bereit, deren zertifizierte Komponenten eigene Zulassungen tragen, geliefert mit dem Integrationsleitfaden, der diese Zulassungen erhält. Das fertige Produkt wird als Ganzes durch seinen Hersteller zugelassen. Unser Integrationsteam arbeitet direkt mit Ihrer Entwicklungsabteilung zusammen, um Störungen in Produktionsabläufen zu minimieren.Planned integration schedule: 9 to 12 weeks for a device already in production, subject to the first hardware validation cycle.我们提供全面的API文档、专项技术支持和集成模块。Integration modules whose certified components carry their own regulatory approvals, supplied with the integration guide that keeps those approvals valid. The finished product is authorised as a whole by its manufacturer.我们的集成团队直接与您的工程部门合作,以最大程度地减少对生产计划的干扰。

Does XEO support TPD (Tobacco Products Directive) compliance for European markets?Unterstützt XEO die TPD-Compliance (Tobacco Products Directive) für europäische Märkte?XEO是否支持欧洲市场的TPD(烟草制品指令)合规性?

regulators +
XEO's architecture is built for EU TPD Article 20. The European platform is in preparation. FDA PMTA evidence is supported today. XEO maintains a Tobacco Product Master File and grants right of reference by Letter of Authorization for the sections it covers; the file is being extended. XEO does not write or file your submission.Die Architektur von XEO ist auf EU TPD Artikel 20 ausgelegt. Die europäische Plattform befindet sich in der Umsetzung. Nachweise für eine FDA-PMTA werden heute unterstützt. XEO unterhält eine Tobacco Product Master File und räumt per Letter of Authorization ein Right of Reference auf die abgedeckten Abschnitte ein; die Datei wird erweitert. XEO schreibt und reicht Ihren Antrag nicht ein.XEO's architecture is built for EU TPD Article 20. The European platform is in preparation. FDA PMTA evidence is supported today. XEO maintains a Tobacco Product Master File and grants right of reference by Letter of Authorization for the sections it covers. XEO does not write or file your submission.

How does XEO's biometric authentication prevent age verification circumvention?Wie verhindert die biometrische Authentifizierung von XEO die Umgehung der Altersverifikation?XEO的生物识别认证如何防止年龄验证规避?

regulators +
XEO implements multi-factor biometric verification combining facial recognition and fingerprint authentication to prevent fraudulent age claims. The system logs all authentication attempts for regulatory review. Age verification runs in the cloud: passport data and facial image are transmitted from the web app to our backend and processed there. Neither is sent to the device; the device receives only an authorisation token bound to its secure element. The fingerprint never leaves the sensor: the template stays inside the fingerprint sensor's secured hardware, no fingerprint image is stored, and not even our own firmware receives it — only the match result. Privacy compliance is preserved, and the authentication log provides a hash-chained audit trail.XEO implementiert Multi-Faktor-Biometrie-Verifikation, die Gesichtserkennung und Fingerabdruckauthentifizierung kombiniert, um betrügerische Altersangaben zu verhindern. Das System protokolliert alle Authentifizierungsversuche zur behördlichen Überprüfung. Die Altersverifikation läuft in der Cloud: Passdaten und Gesichtsbild werden von der Web-App an unser Backend übertragen und dort verarbeitet. An das Gerät geht davon nichts, es erhält ausschließlich ein Autorisierungs-Token, das an sein Secure Element gebunden ist. Der Fingerabdruck verlässt den Sensor nicht: das Template bleibt in der gesicherten Hardware des Fingerabdrucksensors, es wird kein Fingerabdruckbild gespeichert, und nicht einmal unsere eigene Firmware erhält es, sondern nur das Prüfergebnis. Der Datenschutz bleibt gewahrt, und das Authentifizierungsprotokoll liefert einen hashverketteten Nachweis.XEO实施多因素生物识别验证,结合面部识别和指纹认证以防止欺诈性年龄声称。该系统记录所有认证尝试供监管审查。年龄核验在云端执行:护照数据及人脸图像由网页应用上传至后端完成处理。上述两类数据均不会下发至设备;设备仅接收一枚绑定设备安全元件的授权凭证。指纹数据永不离开传感器:指纹模板保存在指纹传感器的安全硬件内部,不保存原始指纹图像;即便是我方自有固件也无法读取模板,仅可获得比对结果。保障隐私合规,同时认证日志可提供留痕审计记录。

What device telemetry does XEO collect, and how is that data secured?Welche Gerätetelemetrie erfasst XEO, und wie werden diese Daten gesichert?XEO收集哪些设备遥测数据,数据如何得到保护?

regulators +
XEO collects usage patterns, activation frequency, and compliance event logs. All are encrypted with AEAD and hosted on enterprise-grade, security-hardened cloud infrastructure. Access is role-based; changes to the system are logged. This enables regulators to verify product usage patterns without exposing personal information.XEO erfasst Nutzungsmuster, Aktivierungshäufigkeit und Compliance-Event-Protokolle. Alle sind mit AEAD verschlüsselt und in unternehmenstauglicher, sicherheitsgehärteter Cloud-Infrastruktur gespeichert. Zugriffe sind rollenbasiert, Änderungen am System werden protokolliert. Behörden können damit Nutzungsmuster von Produkten nachvollziehen, ohne dass personenbezogene Daten offengelegt werden.XEO收集使用模式、激活频率和合规事件日志,全部采用AEAD加密并存储在企业级、安全加固的云基础设施中。数据保留遵循监管最低限度,访问权限基于角色且具有完整的审计日志。

How do we leverage XEO's counterfeiting prevention technology across our distribution network?Wie können wir die Fälschungsschutztechnologie von XEO über unser Vertriebsnetz hinweg nutzen?我们如何在分销网络中利用XEO的防伪技术?

distributors +
XEO embeds cryptographic device identification and cryptographically verified serial numbers into hardware. Each device generates unique authentication tokens that validate legitimacy against our tamper-resistant verification registry, protecting your brand reputation.XEO integriert kryptografische Gerätekennung und kryptografisch verifizierte Seriennummern in die Hardware. Jedes Gerät generiert eindeutige Authentifizierungs-Token, die die Legitimität gegen unser manipulationsresistentes Verifikationsregister validieren und Ihren Markenruf schützen.XEO在硬件中嵌入密码设备标识和密码学验证的序列号。每个设备生成唯一的认证令牌,根据我们的抗篡改验证注册表验证真实性,保护您的品牌声誉。

What is XEO's pricing model, and how does it scale with our distribution volume?Wie lautet das Preismodell von XEO, und wie skaliert es mit unserem Vertriebsvolumen?XEO的定价模式是什么,它如何随分销量扩展?

distributors +
XEO licensing combines a per-device licence with a cloud authorization subscription. Terms depend on volume, integration scope and target region. Planned integration schedule: 9 to 12 weeks for a device already in production, subject to the first hardware validation cycle. We quote on request.Die XEO-Lizenzierung kombiniert eine Lizenz je Gerät mit einem Abonnement für die Cloud-Autorisierung. Die Konditionen richten sich nach Volumen, Integrationsumfang und Zielregion. Geplanter Integrationsablauf: 9 bis 12 Wochen für ein Gerät, das bereits in Produktion ist, vorbehaltlich des ersten Hardware-Validierungszyklus. Angebot auf Anfrage.XEO的授权模式由每台设备许可与云授权订阅组成。具体条件取决于数量、集成范围和目标区域。Planned integration schedule: 9 to 12 weeks for a device already in production, subject to the first hardware validation cycle.报价请垂询。

How does XEO's cloud authorization system prevent unauthorized device activation?Wie verhindert das Cloud-Autorisierungssystem von XEO nicht autorisierte Geräteaktivierungen?XEO的云授权系统如何防止未授权设备激活?

distributors +
XEO's cloud authorization maintains real-time verification of device legitimacy, geographic licensing restrictions, and age verification status. Devices fail to activate if they lack current authorization credentials or are flagged as counterfeit. Operation inside a restricted zone is recorded as a compliance violation and raises an alert; suspension is then an operator action or a configured rule. An operator runs the recall batch; the platform revokes authorization over the air for every device and logs delivery and acknowledgement per device.Das Cloud-Autorisierungssystem von XEO führt Echtzeitverifikation der Gerätelegitimität, geografischer Lizenzierungsbeschränkungen und Status der Altersverifikation durch. Geräte aktivieren nicht, wenn ihnen gültige Freigabedaten fehlen oder sie als Fälschung markiert sind. Betrieb innerhalb einer gesperrten Zone wird als Compliance-Verstoß protokolliert und löst eine Meldung aus; die Sperrung ist dann eine Maßnahme des Betreibers oder eine konfigurierte Regel. Den Rückruf startet der Betreiber; die Plattform entzieht die Freigabe für jedes Gerät über das Netz und protokolliert Zustellung und Bestätigung je Gerät.XEO的云授权系统维护设备合法性、地理许可限制和年龄验证状态的实时验证。如果设备缺乏当前授权凭证或被标记为假冒,则设备无法激活。Operation inside a restricted zone is recorded as a compliance violation and raises an alert. An operator runs the recall batch; the platform revokes authorization over the air and logs delivery and acknowledgement per device.

Can we implement hardware-based age verification, or is software-only sufficient for compliance?Können wir Hardware-gestützte Altersverifikation implementieren, oder ist nur Software ausreichend für Compliance?我们可以实施基于硬件的年龄验证,还是仅有软件就足以合规?

regulators +
While software age verification is functional, XEO recommends hardware-based authentication for maximum regulatory defensibility. Hardware biometric verification creates append-only, hash-chained verification records designed for regulatory acceptance, whereas software-only systems remain vulnerable to circumvention. We recommend hardware-based solutions to support your own PMTA submission and for high-risk markets; software can supplement in lower-risk jurisdictions.Während Software-Altersverifikation funktional ist, empfiehlt XEO Hardware-gestützte Authentifizierung für maximale behördliche Verteidigbarkeit. Hardware-Biometrie-Verifikation erstellt append-only und hashverkettete Verifizierungsdatensätze für die behördliche Akzeptanz, während reine Software-Systeme anfällig für Umgehung bleiben. Wir empfehlen Hardware-gestützte Lösungen für Unterstützung Ihrer eigenen PMTA-Einreichung und risikoreiche Märkte; Software kann in weniger risikoreichen Regionen ergänzend wirken.虽然软件年龄验证是可行的,但XEO建议采用硬件认证以获得最大的监管防御性。硬件生物识别验证创建合规记录,为监管审查而设计,而仅软件系统仍然容易受到规避。我们建议在支持贵司自有 PMTA 提交和高风险市场中采用硬件解决方案;软件可在较低风险司法管辖区补充。

How does XEO integration affect device battery life and performance?Wie beeinflusst die XEO-Integration die Akkulaufzeit und Leistung unseres Geräts?XEO集成如何影响设备电池寿命和性能?

manufacturers +
XEO's embedded compliance module has a design target of under 3 % additional battery consumption through optimized cryptographic algorithms; that figure has not yet been measured on final hardware. The design target for authentication is under 200 ms; that figure has not yet been measured on final hardware. Telemetry collection runs asynchronously without affecting user experience.Das eingebettete Compliance-Modul von XEO hat durch optimierte kryptografische Algorithmen ein Designziel von unter 3 % zusätzlichem Batterieverbrauch; dieser Wert ist auf finaler Hardware noch nicht gemessen. Das Designziel für die Authentifizierung liegt unter 200 ms; dieser Wert ist auf finaler Hardware noch nicht gemessen. Die Telemetrieerfassung läuft asynchron ohne Auswirkungen auf das Benutzererlebnis.XEO的嵌入式合规模块通过优化密码算法,Design target: under 3 % additional battery consumption, not yet measured on final hardware.The design target for authentication is under 200 ms; that figure has not yet been measured on final hardware. 遥测收集异步运行,不影响用户体验。

What regulatory documentation does XEO provide for submission to government agencies?Welche behördliche Dokumentation stellt XEO für die Einreichung bei Behörden bereit?XEO为提交给政府机构提供哪些监管文档?

regulators +
XEO provides the device-level material a submission cites: technical architecture description, access-restriction documentation, age-verification aggregates, device telemetry audit trails and post-market monitoring data. XEO does not write or file the submission.XEO stellt das geräteseitige Material bereit, das eine Einreichung zitiert: Beschreibung der technischen Architektur, Dokumentation der Zugangsbeschränkungen, Aggregate der Altersverifikation, Telemetrie-Protokolle und Daten der Marktüberwachung. XEO schreibt und reicht den Antrag nicht ein.XEO provides the device-level material a submission cites: technical architecture description, access-restriction documentation, age-verification aggregates, device telemetry audit trails and post-market monitoring data. XEO does not write or file the submission.

Is XEO's core technology patent-protected?Ist die Kerntechnologie von XEO patentrechtlich geschützt?XEO的核心技术是否受专利保护?

manufacturers +
Yes. The cryptographic device-cartridge pairing at the core of XEO's hardware authentication is protected by a granted patent family: EP 4,007,503 B1 (Europe, validated in the UK and Switzerland, granted 2024), US 12,622,469 B2 (USA, granted May 2026), and CA 3,190,264 C (Canada, granted January 2026). Further applications are pending in additional jurisdictions. This gives manufacturers and distributors a defensible, granted patent family rather than an easily replicated software layer.Ja. Die kryptografische Gerätekartuschenkopplung im Kern der XEO-Hardware-Authentifizierung ist durch eine erteilte Patentfamilie geschützt: EP 4.007.503 B1 (Europa, validiert in UK und der Schweiz, erteilt 2024), US 12.622.469 B2 (USA, erteilt Mai 2026) und CA 3.190.264 C (Kanada, erteilt Januar 2026). Weitere Anmeldungen sind in zusätzlichen Jurisdiktionen anhängig. Das gibt Herstellern und Vertriebspartnern eine belastbare, erteilte Patentfamilie statt einer leicht nachbaubaren Softwareschicht.是的。XEO硬件认证核心的密码学设备-烟弹配对技术受已授权专利家族保护:EP 4,007,503 B1(欧洲,已在英国和瑞士生效,2024年授权)、US 12,622,469 B2(美国,2026年5月授权)以及CA 3,190,264 C(加拿大,2026年1月授权)。其他司法管辖区的申请仍在审理中。这为制造商和分销商提供了已授权专利家族,而非容易被复制的软件层。