● LATEST ALERTS
For Regulators · Enforcement Infrastructure · Real-Time Telemetry

Make Compliance Enforceable.
Make Every Device Visible.

XEO gives regulatory agencies hardware-level visibility into ENDS device usage, age verification, and compliance status across the entire product lifecycle. Hash-chained audit trails and cryptographic device authentication. Built into every unit, not retrofitted as software.

Für Regulierungsbehörden · Durchsetzungsinfrastruktur · Echtzeit-Monitoring

Compliance durchsetzbar machen.
Jedes Gerät sichtbar machen.

XEO bietet Regulierungsbehörden hardwareseitige Einsicht in Nutzung, Altersverifikation und Compliance-Status von ENDS-Geräten (elektronische Nikotinabgabesysteme) über den gesamten Produktlebenszyklus. Hashverkettete Prüfprotokolle und kryptografische Geräteauthentifizierung. In jede Einheit integriert.

面向监管机构 · 合规数据基础设施 · 实时监测

让合规可执行。
让每台设备可见。

XEO为监管机构提供覆盖电子烟设备全生命周期的硬件级数据支持能力。审计追踪和加密设备认证,内置于每台设备,而非事后以软件形式加装。

ConfigurablekonfigurierbarConfigurable
Reporting IntervalSendeintervallReporting Interval
Hash-chainedHashverkettetHash-chained
Append-only records, daily signed rootAppend-only, täglich signierte WurzelAppend-only records, daily signed root
2
Regulatory FrameworksRegulatorische Rahmenwerke监管框架
AEAD
End-to-End EncryptionEnde-zu-Ende-Verschlüsselung端到端加密
REAL-TIME TELEMETRY
HASH-CHAINED AUDIT TRAILS
HARDWARE-ENFORCED
FDA PMTA COMPATIBLE
BUILT FOR EU TPD ARTICLE 20
CRYPTOGRAPHIC AUTHENTICATION
POST-MARKET MONITORING
REAL-TIME TELEMETRY
HASH-CHAINED AUDIT TRAILS
HARDWARE-ENFORCED
FDA PMTA COMPATIBLE
BUILT FOR EU TPD ARTICLE 20
CRYPTOGRAPHIC AUTHENTICATION
POST-MARKET MONITORING
Enforcement Gaps

THREE CHALLENGES
XEO SOLVES

Current enforcement mechanisms rely on point-of-sale controls that end the moment a product leaves the store. XEO extends regulatory oversight to the device level.

Durchsetzungslücken

DREI HERAUSFORDERUNGEN
DIE XEO LÖST

Aktuelle Durchsetzungsmechanismen basieren auf Verkaufspunktkontrollen, die enden, sobald ein Produkt das Geschäft verlässt. XEO erweitert die regulatorische Aufsicht auf Geräteebene.

执法漏洞

XEO解决的
三大挑战

当前的执法机制依赖于销售点控制,产品一旦离店便失效。XEO将监管监督延伸到设备层面。

01

Post-Sale Enforcement Void

Age verification at point of sale provides zero enforcement after purchase. Devices freely circulate to underage users through secondary markets, social sharing, and theft. Without device-level controls, regulators have no mechanism to prevent unauthorized use after the initial transaction.

Durchsetzungsvakuum nach dem Verkauf

Altersverifizierung am Verkaufspunkt bietet nach dem Kauf keinerlei Durchsetzung. Geräte gelangen über Sekundärmärkte und soziale Weitergabe frei an minderjährige Nutzer. Ohne Kontrollen auf Geräteebene haben Behörden keinen Mechanismus zur Verhinderung unbefugter Nutzung.

售后执法真空

销售点年龄验证在购买后提供零数据支持能力。设备通过二级市场、社交分享和盗窃自由流向未成年用户。没有设备级控制,监管机构在初始交易后无法阻止未授权使用。

02

Counterfeit Proliferation

Unregulated counterfeit devices represent a growing safety hazard and a direct challenge to regulatory authority. Without cryptographic device authentication, enforcement agencies cannot distinguish legitimate products from dangerous counterfeits at inspection, in the supply chain, or at the border.

Fälschungsverbreitung

Unregulierte gefälschte Geräte stellen ein wachsendes Sicherheitsrisiko und eine direkte Herausforderung für Regulierungsbehörden dar. Ohne kryptografische Geräteauthentifizierung können Behörden bei Inspektionen legitime Produkte nicht von gefährlichen Fälschungen unterscheiden.

假冒产品泛滥

不受监管的假冒设备代表着日益增长的安全隐患,直接挑战监管权威。没有加密设备认证,执法机构在检查、供应链和边境均无法区分合法产品与危险假冒品。

03

Monitoring Data Deficit

Regulators lack real-time data on device usage patterns, population-level consumption trends, and compliance violations as they occur. Enforcement actions rely on retrospective reporting, complaints, and manual inspections. These tools are insufficient for the scale of the modern ENDS (Electronic Nicotine Delivery Systems) market.

Datenlücke in der Marktaufsicht

Regulierungsbehörden fehlen Echtzeitdaten über Nutzungsmuster, Verbrauchstrends auf Bevölkerungsebene und Complianceverstöße. Durchsetzungsmaßnahmen basieren auf retrospektiver Berichterstattung und manuellen Inspektionen.

市场监管数据缺口

监管机构缺乏关于设备使用模式、人群级消费趋势和违规行为的实时数据。执法行动依赖回顾性报告、投诉和人工检查。这些工具不足以应对现代电子烟(ENDS,电子尼古丁输送系统)市场的规模。

Compliance Proof

VERIFICATION RECORDS
BY DEFAULT

Records are append-only and hash-chained, with a daily signed root that can be verified on request. No manual documentation. No self-reported data. Available on demand.

Compliancenachweis

AB WERK
PRÜFBAR

Datensätze sind append-only und hashverkettet, mit einer täglich signierten Wurzel, die auf Anfrage geprüft werden kann. Keine manuelle Dokumentation. Keine selbstgemeldeten Daten.

合规证明

默认
可供监管审查

Records are append-only and hash-chained, with a daily signed root that can be verified on request. 无需手动文档。无自报数据。按需可用。

  • Device Authentication Logs

    Every activation attempt recorded with timestamp, biometric verification result and, where a jurisdiction requires it, geolocation, written into an append-only log with a daily signed root. Tamper-resistant and hosted on enterprise-grade, security-hardened infrastructure.

    Geräteauthentifizierungsprotokolle

    Jeder Aktivierungsversuch wird mit Zeitstempel, Ergebnis der biometrischen Prüfung und, wo eine Rechtsordnung es verlangt, Standortangabe in einem nur ergänzbaren Protokoll mit täglich signierter Wurzel festgehalten.

    设备认证日志

    每次激活尝试均记录时间戳、地理位置和生物识别验证结果,written into an append-only log with a daily signed root。抗篡改,托管于企业级、安全加固基础设施。

  • Age Verification Audit Trails

    Complete chain-of-verification from initial identity check through biometric re-authentication. Every verification event linked to device ID, and outcome status.

    Altersverifizierungsprüfpfade

    Vollständige Verifizierungskette von der erstmaligen Identitätsprüfung bis zur biometrischen Re-Authentifizierung.

    年龄验证审计追踪

    从初始身份核查到生物识别重新认证的完整验证链。每个验证事件关联设备ID和结果状态。

  • Enforcement Action Records

    Documented record of every compliance intervention: device lockouts, geographic restriction enforcement, authorization revocations, and counterfeit detection events.

    Durchsetzungsmaßnahmenprotokolle

    Dokumentierte Aufzeichnung jeder Complianceintervention: Gerätesperren, geografische Beschränkungen, Autorisierungswiderrufe und Fälschungserkennungen.

    执法行动记录

    每项合规干预的文档记录:设备锁定、地理限制执行、授权撤销和假冒检测事件。

CRYPTOGRAPHIC INTEGRITY

Records are append-only and hash-chained, with a daily signed root that can be verified on request. Any later alteration, backdating or fabrication is detectable.

This means regulatory agencies receive platform-generated records, not self-reported claims from manufacturers.

Data is encrypted with AEAD, hosted on enterprise-grade, security-hardened infrastructure, and accessible via role-based regulatory portals.

KRYPTOGRAFISCHE INTEGRITÄT

Datensätze sind append-only und hashverkettet, mit einer täglich signierten Wurzel, die auf Anfrage geprüft werden kann. Nachträgliche Änderungen, Rückdatierungen oder Fälschungen sind erkennbar.

Behörden erhalten von der Plattform erzeugte Datensätze, keine Selbstauskünfte.

Daten werden mit AEAD verschlüsselt, in unternehmenstauglicher, sicherheitsgehärteter Infrastruktur gespeichert und über rollenbasierte Portale zugänglich.

加密完整性

Records are append-only and hash-chained, with a daily signed root that can be verified on request.记录的事后篡改、回溯日期或伪造均可检测。

Regulatory agencies receive platform-generated records, not self-reported claims.

数据采用AEAD加密,存储于企业级、安全加固基础设施,通过角色化监管门户访问。

XEO's hardware-enforced authentication is backed by granted patents, not just architecture claims. EP 4,007,503 · US 12,622,469 · CA 3,190,264 → XEOs hardwaregesicherte Authentifizierung ist durch erteilte Patente abgesichert, nicht nur durch Architekturansprüche. EP 4.007.503 · US 12.622.469 · CA 3.190.264 → XEO的硬件强制认证由已授权专利提供保障,而非仅仅是架构声明。EP 4,007,503 · US 12,622,469 · CA 3,190,264 →
Monitoring Capabilities

DEVICE MONITORING

XEO enables every device to report usage, verification, and telemetry data. Monitor usage patterns, identify anomalies, and support enforcement decisions. All from a centralized monitoring dashboard.

Monitoring-Fähigkeiten

GERÄTE-MONITORING

XEO ermöglicht es jedem Gerät, Nutzungs-, Verifizierungs- und Compliance-Daten zu melden. Nutzungsmuster überwachen, Anomalien identifizieren und Durchsetzungsentscheidungen unterstützen.

监测能力

设备监测

XEO使每台设备能够报告使用、验证和合规数据。监测使用模式、识别异常并支持执法决策,全部来自集中化监测仪表板。

// Real-Time Telemetry

Device Telemetry

Encrypted data streams from every active device. Monitor activation events, usage frequency, session patterns, and consumption metrics across entire device populations in real time. The reporting interval is configurable per deployment, so it can be set to what a jurisdiction requires.

Gerätetelemetrie

Verschlüsselte Datenströme von jedem aktiven Gerät. Überwachen Sie Aktivierungsereignisse, Nutzungshäufigkeit und Verbrauchsmetriken in Echtzeit. Das Sendeintervall ist je Einsatz konfigurierbar und lässt sich auf das einstellen, was ein Rechtsraum verlangt.

设备遥测

每台活跃设备的加密数据流。实时监测整个设备群体的激活事件、使用频率、会话模式和消费指标。

// Geographic Enforcement

Geofenced Compliance Zones

Define geographic boundaries where devices may or may not operate. A fix inside a restricted zone records a violation and raises an alert; suspension is an operator action or a configured rule. Configurable per regulation, per region, per device class.

Geofenced Compliancezonen

Definieren Sie geografische Grenzen, in denen Geräte betrieben werden dürfen. Ein Positionsfix in einer Sperrzone erzeugt einen Verstoß und eine Benachrichtigung; die Sperrung ist eine Bedienhandlung oder eine konfigurierte Regel.

地理围栏合规区域

定义设备可以或不可以运行的地理边界。A fix inside a restricted zone records a violation and raises an alert; suspension is an operator action or a configured rule. 可按法规、地区、设备类别配置。

// Anomaly Detection

Automated Violation Alerts

Rule-based anomaly detection on every frame identifies suspicious usage patterns, repeated authentication failures, unauthorized modification attempts, and activations outside authorized regions. Configurable alert thresholds and escalation workflows.

Automatisierte Verstoßalarme

Regelbasierte Anomalieerkennung auf jedem Frame identifiziert verdächtige Nutzungsmuster, wiederholte Authentifizierungsfehler und Verstöße gegen geografische Beschränkungen.

自动违规警报

Rule-based anomaly detection on every frame 识别可疑使用模式、反复认证失败、未授权修改尝试和地理限制违规。可配置警报阈值和升级工作流。

// Counterfeit Detection

Cryptographic Device Verification

Every XEO device carries a unique cryptographic identity, checked against the registry each time an authorisation is issued. Counterfeit and refilled pods are identified from usage patterns and reported. Cryptographic pod authentication — in development.

Kryptografische Geräteverifizierung

Jedes XEO-Gerät trägt eine eindeutige kryptografische Identität, die bei jeder Freigabe gegen das Register geprüft wird. Gefälschte und nachgefüllte Pods werden anhand von Nutzungsmustern erkannt und gemeldet. Kryptografische Pod-Authentifizierung — in Entwicklung.

加密设备验证

Every XEO device carries a unique cryptographic identity, checked against the registry each time an authorisation is issued. Counterfeit and refilled pods are identified from usage patterns and reported. Cryptographic pod authentication — in development.

Framework Compatibility

BUILT FOR YOUR
REGULATORY REGIME

XEO's architecture is designed to support multiple regulatory frameworks simultaneously. A single infrastructure layer provides jurisdiction-specific age rules and device authentication, with one regulatory report set on top.

Frameworkkompatibilität

FÜR IHR REGULIERUNGS-
REGIME ENTWICKELT

XEOs Architektur unterstützt mehrere Regulierungsrahmenwerke gleichzeitig. Eine einzige Infrastrukturschicht liefert rechtsraumspezifische Altersregeln und Geräteauthentifizierung, darüber einen einheitlichen regulatorischen Berichtssatz.

框架兼容性

为您的
监管体系构建

XEO的架构设计为同时支持多个监管框架。A single infrastructure layer provides jurisdiction-specific age rules and device authentication, with one regulatory report set on top.

🇺🇸
FDA PMTA
United States

Device-level evidence for a Premarket Tobacco Product Application: access-restriction documentation, age-verification records and post-market monitoring data. Periodic report data feed under 21 CFR 1114.41 and adverse-event packages on a 15-day clock. Tamper-evident verification records supporting the applicant's submission.

XEO maintains a Tobacco Product Master File with the FDA and grants manufacturers right of reference by Letter of Authorization, limited to the sections named in that letter. A master file is a confidential submission that the FDA does not review on its own; its existence is not a finding about its contents. The applicant remains the manufacturer and responsible party of record.

FDA PMTA
Vereinigte Staaten

Geräteseitige Nachweise für eine Premarket Tobacco Product Application: Dokumentation der Zugangsbeschränkungen, Aufzeichnungen der Altersverifikation und Daten der Marktüberwachung. Periodischer Berichtsdatenstrom nach 21 CFR 1114.41 und Pakete zu unerwünschten Ereignissen mit 15-Tage-Frist. Manipulationserkennende Verifizierungsdatensätze zur Unterstützung der Einreichung des Antragstellers.

XEO unterhält eine Tobacco Product Master File bei der FDA und räumt Herstellern per Letter of Authorization ein Right of Reference ein, begrenzt auf die in diesem Schreiben benannten Abschnitte. Eine Master File ist eine vertrauliche Einreichung, die die FDA nicht eigenständig prüft; ihr Bestehen ist keine Aussage über ihren Inhalt. Antragsteller und verantwortlicher Hersteller bleibt der Lizenznehmer.

FDA PMTA
美国

Device-level evidence for a Premarket Tobacco Product Application: access-restriction documentation, age-verification records and post-market monitoring data.

XEO maintains a Tobacco Product Master File with the FDA and grants right of reference by Letter of Authorization. A master file is not reviewed by the FDA on its own. The applicant remains the responsible manufacturer.

🇪🇺
EU TPD Article 20
European Union

Tobacco Products Directive requirements — European platform in preparation. Device and component description for the manufacturer's Article 20 notification. Usage aggregates by region and device type. A usage-weighted HPHC exposure model, which is not laboratory emissions data.

EU TPD Artikel 20
Europäische Union

Anforderungen der Tabakproduktrichtlinie — europäische Plattform in Vorbereitung. Geräte- und Komponentenbeschreibung für die Meldung des Herstellers nach Artikel 20. Nutzungsaggregate nach Region und Gerätetyp. Ein nutzungsgewichtetes HPHC-Expositionsmodell, das keine Labormessung von Emissionen ist.

EU TPD 第20条
欧盟

Tobacco Products Directive requirements — European platform in preparation. Device and component description for the manufacturer's Article 20 notification. Usage aggregates by region and device type. A usage-weighted HPHC exposure model, which is not laboratory emissions data.

Regulatory References: FDA PMTA Guidance · EU TPD — Electronic Cigarettes · EU Track & Trace · GDPR Regulatorische Referenzen: FDA PMTA Guidance · EU TPD — E-Zigaretten · EU Track & Trace · DSGVO 监管参考资料: FDA PMTA指南 · EU TPD — 电子烟 · EU追踪追溯 · GDPR
REQUEST PMTA TECHNICAL REVIEWPMTA-PRÜFUNG ANFRAGEN申请 PMTA 技术评审
Data Access

REGULATORY
REPORTING TOOLS

Purpose-built data access infrastructure for regulatory agencies. Role-based permissions, real-time dashboards, and export for regulatory review.

Datenzugang

REGULATORISCHE
REPORTING-TOOLS

Zweckgebaute Datenzugangsinfrastruktur für Regulierungsbehörden. Rollenbasierte Berechtigungen, Echtzeitdashboards und Export für die behördliche Prüfung.

数据访问

监管
报告工具

为监管机构专门构建的数据访问基础设施。角色化权限、实时仪表板。

Regulatory Access Portal

Dedicated web portal for authorized regulatory personnel: built and available for evaluation, not yet in productive use with an authority. Role-based access controls and multi-factor authentication. Every state-changing action is recorded with actor, resource and timestamp in an append-only log, hash-chained with a daily signed root. Every data export is logged.

Role-Based Access

Regulatorisches Zugangsportal

Dediziertes Webportal für autorisiertes Regulierungspersonal: gebaut und zur Evaluierung verfügbar, aber noch nicht produktiv bei einer Behörde im Einsatz. Rollenbasierte Zugriffskontrollen und Multi-Faktor-Authentifizierung. Jede zustandsändernde Handlung wird mit Akteur, Ressource und Zeitstempel in einem nur ergänzbaren Protokoll festgehalten, hashverkettet, mit täglich signierter Wurzel. Jeder Datenexport wird protokolliert.

Rollenbasierter Zugang

监管访问门户

为授权监管人员提供的专用网络门户。角色化访问控制、多因素认证。每一次 state-changing 操作均以 actor、resource 和时间戳记录于 append-only 日志,hash-chained,每日一个 signed root。每一次数据导出均被记录。

角色化访问

Real-Time Dashboards

Live verification metrics across device populations. Configurable views for age verification rates, geographic compliance, counterfeit detection, and enforcement action tracking.

Live Monitoring

Echtzeitdashboards

Live-Compliance-Metriken über Gerätepopulationen. Konfigurierbare Ansichten für Altersverifizierungsraten, geografische Compliance und Fälschungserkennung.

Live-Monitoring

实时仪表板

跨设备群体的实时合规指标。可配置视图涵盖年龄验证率、地理合规、假冒检测和执法行动跟踪。

实时监测

Reporting

Thirteen regulatory reports: device lifecycle, usage and post-market surveillance aggregates, geographic compliance, counterfeit and supply chain, safety and anomalies, compliance violations, recall and action log, adverse events, HPHC exposure, sales reconciliation, youth access, age verification, and the periodic FDA data feed. Each exports as CSV, JSON or XLSX, and can be delivered automatically on a daily, weekly or monthly schedule. Regulatory packages are issued as signed PDF with a per-file checksum manifest.

Export

Berichte

Dreizehn regulatorische Berichte: Gerätelebenszyklus, Nutzungs- und Marktüberwachungsaggregate, geografische Compliance, Fälschung und Lieferkette, Sicherheit und Anomalien, Compliance-Verstöße, Rückruf- und Maßnahmenprotokoll, unerwünschte Ereignisse, HPHC-Exposition, Absatzabgleich, Jugendzugang, Altersverifikation und der periodische FDA-Datenstrom. Jeder Bericht wird als CSV, JSON oder XLSX exportiert und kann täglich, wöchentlich oder monatlich automatisch zugestellt werden. Regulatorische Pakete werden als signiertes PDF mit Prüfsummenverzeichnis je Datei ausgegeben.

Export

Reporting

Thirteen regulatory reports: device lifecycle, usage and post-market surveillance aggregates, geographic compliance, counterfeit and supply chain, safety and anomalies, compliance violations, recall and action log, adverse events, HPHC exposure, sales reconciliation, youth access, age verification, and the periodic FDA data feed. Each exports as CSV, JSON or XLSX, and can be delivered automatically on a daily, weekly or monthly schedule. Regulatory packages are issued as signed PDF with a per-file checksum manifest.

Export

Population Analytics

Aggregate usage statistics by region and device type. Identify consumption trends and market patterns to inform evidence-based policy decisions.

Aggregates only

Populationsanalysen

Aggregierte Nutzungsstatistiken nach Region und Gerätetyp. Verbrauchstrends und Marktmuster für evidenzbasierte Politikentscheidungen identifizieren.

Aggregates only

人群分析

跨人口统计、地理和设备类型的汇总使用统计。识别消费趋势、高风险人群和市场模式,为循证政策决策提供依据。

Aggregates only

Licensee API Access

Read-only regulator portal behind multi-factor authentication. Since 1.9.1, licensee API keys give machine access to the licence holder's own data packages. No programmatic access to the verification database, no customs integration.

REST API

Licensee-API-Zugang

Lesendes Behördenportal hinter Mehrfaktor-Authentifizierung. Seit 1.9.1 geben Licensee-API-Schlüssel maschinellen Zugriff auf die eigenen Datenpakete des Inhabers. Kein programmatischer Zugriff auf die Verifizierungsdatenbank, keine Zollanbindung.

REST API

Licensee API Access

Read-only regulator portal behind multi-factor authentication. Since 1.9.1, licensee API keys give machine access to the licence holder's own data packages. No programmatic access to the verification database, no customs integration.

REST API

Incident Response

Real-time alert system for critical compliance events. Configurable escalation workflows, immediate device lockout capability, and coordinated response tools for multi-agency enforcement operations.

Real-Time Alerts

Incident Response

Echtzeitalarmsystem für kritische Complianceereignisse. Konfigurierbare Eskalationsworkflows, sofortige Gerätesperrung und koordinierte Response-Tools.

Echtzeitalarme

事件响应

关键合规事件的实时警报系统。可配置升级工作流、即时设备锁定能力和多机构执法操作的协调响应工具。

实时警报
Regulator FAQ

FREQUENTLY ASKED
QUESTIONS

Behörden-FAQ

HÄUFIG GESTELLTE
FRAGEN

监管机构常见问题

常见
问题

How does XEO enable real-time monitoring of devices in the field?Wie ermöglicht XEO Echtzeit-Monitoring von Geräten im Feld?XEO如何实现对市场中设备的实时监测?

+
XEO embeds encrypted telemetry modules directly into device hardware. These modules report usage patterns and activation events to a central compliance dashboard; the reporting interval is configurable, and devices can enter sleep mode between transmissions. Incoming data is processed and displayed in real time. Geographic data can be collected where a jurisdiction requires it and is switchable in software, as required by the FDA. Age verification is not part of the telemetry: the authorisation is issued in the cloud and sent to the device as a token.XEO bettet verschlüsselte Telemetriemodule direkt in die Gerätehardware ein. Diese Module berichten Nutzungsmuster und Aktivierungsereignisse an ein zentrales Compliancedashboard. Das Sendeintervall ist konfigurierbar, zwischen den Übertragungen kann das Gerät in den Schlafmodus wechseln. Eingehende Daten werden in Echtzeit verarbeitet und dargestellt. Standortdaten können erhoben werden, wo ein Rechtsraum es verlangt; sie sind per Software zuschaltbar und für die FDA vorgeschrieben. Die Altersverifikation ist nicht Teil der Telemetrie: die Freigabe entsteht in der Cloud und geht als Token an das Gerät.XEO将加密遥测模块直接嵌入设备硬件。这些模块持续向集中化合规仪表板报告使用模式、激活事件和地理数据。监管机构可以接收异常行为和授权范围外激活事件的实时提醒。

What regulatory documentation does XEO provide?Welche Dokumentation für die behördliche Prüfung bietet XEO?XEO提供哪些支持监管审查的文档?

+
XEO generates verification records: device authentication logs, age verification audit trails, and post-market monitoring data. All records are cryptographically signed and timestamped, and are formatted for regulatory review.XEO erzeugt Verifizierungsdatensätze: Geräteauthentifizierungsprotokolle, Altersverifizierungsprüfpfade und Post-Market-Monitoring-Daten. Alle Datensätze sind kryptografisch signiert und mit Zeitstempel versehen und für die behördliche Prüfung formatiert.XEO生成验证记录,包括设备认证日志、年龄验证审计追踪和上市后监测数据。所有记录均加密签名、带时间戳,格式化为可直接用于监管审查和执法程序。

Can regulators access XEO data directly?Können Behörden direkt auf XEO-Daten zugreifen?监管机构能否直接访问XEO数据?

+
A dedicated regulatory access portal with role-based permissions is built and available for evaluation; it is not yet in productive use with an authority. It provides dashboards and reports. Reports export in machine-readable formats for ingestion into an agency's own systems. A direct system-to-system integration would be a bespoke project. Changes to the system are logged.Ein dediziertes Zugangsportal mit rollenbasierten Berechtigungen ist gebaut und steht zur Evaluierung bereit; im produktiven Einsatz bei einer Behörde ist es noch nicht. Es bietet Dashboards und Berichte. Berichte werden in maschinenlesbaren Formaten exportiert und können in die Systeme einer Behörde eingelesen werden. Eine direkte Kopplung beider Systeme wäre ein Einzelprojekt. Änderungen am System werden protokolliert.可以。XEO提供专用监管访问门户,具有角色化权限、实时仪表板和自动化报告。监管机构可查询设备群体、审查合规指标并接收可配置警报。所有访问均记录且符合GDPR。Reports export in machine-readable formats for ingestion into an agency's own systems. A direct system-to-system integration would be a bespoke project.

How does XEO handle data privacy and GDPR compliance?Wie handhabt XEO Datenschutz und DSGVO-Compliance?XEO如何处理数据隐私和GDPR合规?

+
Age verification runs in the cloud: passport data and facial image are transmitted from the web app to our backend and processed there, and are never sent to the device. The fingerprint never leaves the sensor: the template stays inside the fingerprint sensor's secured hardware, no fingerprint image is stored, and not even our own firmware receives it — only the match result. It is deleted on factory reset or remotely. Telemetry carries no personal data in the payload. Because the platform holds the link between a device and its verified owner, the link that makes a recall reachable, telemetry is pseudonymous rather than anonymous. Regulators and manufacturers receive aggregates only. Retention follows the deployment region: telemetry is kept four years in the US configuration, matching the FDA record-keeping period, and two years in the EU configuration, with location data kept ninety days. Access is role-based; changes to the system are logged. Infrastructure is enterprise-grade and security-hardened.Die Altersverifikation läuft in der Cloud: Passdaten und Gesichtsbild werden von der Web-App an unser Backend übertragen und dort verarbeitet, an das Gerät gehen sie nicht. Der Fingerabdruck verlässt den Sensor nicht: das Template bleibt in der gesicherten Hardware des Fingerabdrucksensors, es wird kein Fingerabdruckbild gespeichert, und nicht einmal unsere eigene Firmware erhält es, sondern nur das Prüfergebnis. Es wird beim Werksreset oder aus der Ferne gelöscht. Die Telemetrie enthält in ihren Nutzdaten keine personenbezogenen Daten. Da die Plattform die Verknüpfung zwischen Gerät und verifiziertem Besitzer hält, also genau die Verknüpfung, über die ein Rückruf den Besitzer erreicht, ist die Telemetrie pseudonym und nicht anonym. Behörden und Hersteller erhalten ausschließlich Aggregate. Die Aufbewahrung richtet sich nach der Region des Einsatzes: Telemetrie wird in der US-Konfiguration vier Jahre vorgehalten, passend zur Aufbewahrungsfrist der FDA, in der EU-Konfiguration zwei Jahre, Standortdaten neunzig Tage. Zugriffe sind rollenbasiert, Änderungen am System werden protokolliert. Die Infrastruktur ist unternehmenstauglich und sicherheitsgehärtet.年龄核验在云端执行:护照数据及人脸图像由网页应用上传至后端完成处理,且绝不会下发至设备。指纹数据永不离开传感器:指纹模板保存在指纹传感器的安全硬件内部,不存储原始指纹图像;即便是我方自有固件也无法读取模板,仅可获得比对结果。恢复出厂设置或远程操作均可将该模板清除。Telemetry carries no personal data in the payload. Because the platform holds the link between a device and its verified owner, the link that makes a recall reachable, telemetry is pseudonymous rather than anonymous. Regulators and manufacturers receive aggregates only. Retention follows the deployment region: telemetry is kept four years in the US configuration, matching the FDA record-keeping period, and two years in the EU configuration, with location data kept ninety days. 基于角色的访问配合完整审计日志。XEO在企业级、安全加固基础设施上保持GDPR和CCPA合规。

Which regulatory frameworks does XEO currently support?Welche regulatorischen Rahmenwerke unterstützt XEO derzeit?XEO目前支持哪些监管框架?

+
XEO supports FDA PMTA and TPMF (United States). The platform provides a periodic report data feed under 21 CFR 1114.41, adverse event data packages on a 15-day clock from awareness, recall effectiveness evidence, and a reporting calendar per licensee, as data packages in JSON, CSV and PDF.XEO unterstützt FDA PMTA und TPMF (USA).XEO支持FDA PMTA和TPMF(美国)。The platform provides a periodic report data feed under 21 CFR 1114.41, adverse event data packages on a 15-day clock from awareness, recall effectiveness evidence, and a reporting calendar per licensee, as data packages in JSON, CSV and PDF.

How does XEO help identify and combat counterfeit devices?Wie hilft XEO bei der Identifizierung und Bekämpfung von Fälschungen?XEO如何帮助识别和打击假冒设备?

+
Every XEO device carries a cryptographic identity that is verified against a tamper-resistant verification registry. The platform records firmware distribution to each licensee in a tamper-evident ledger, and reconciles device activations against the manufacturer's own imported sales data by territory, channel and distributor.Jedes XEO-Gerät trägt eine kryptografische Identität, die gegen ein manipulationsresistentes Verifikationsregister verifiziert wird. Die Plattform protokolliert die Firmware-Auslieferung an jeden Lizenznehmer in einem manipulationserkennenden Register und gleicht Geräteaktivierungen mit den vom Hersteller selbst eingespielten Absatzdaten nach Gebiet, Kanal und Distributor ab.每台XEO设备携带通过抗篡改验证注册表验证的加密身份。The platform records firmware distribution to each licensee in a tamper-evident ledger, and reconciles device activations against the manufacturer's own imported sales data by territory, channel and distributor.
Request a Briefing

READY TO
SEE IT IN ACTION?

Schedule a confidential regulatory briefing with our compliance team. We will demonstrate monitoring capabilities, verification documentation, and framework-specific oversight tools tailored to your jurisdiction.

Briefing anfordern

BEREIT ES
IN AKTION ZU SEHEN?

Vereinbaren Sie ein vertrauliches regulatorisches Briefing mit unserem Complianceteam. Wir demonstrieren Monitoring, Auditdokumentation und jurisdiktionsspezifische Durchsetzungstools.

申请简报

准备好
亲眼见证?

与我们的合规团队预约保密监管简报。我们将演示监测能力、监管文档和针对您司法管辖区定制的监管支持工具。

Request Regulatory Briefing →Regulatorisches Briefing anfordern →申请监管简报 →