A $50 million financing round for Dutch deep-tech company Fortaegis is putting hardware-rooted security at the center of Europe’s effort to protect AI systems, critical infrastructure and future networks from increasingly sophisticated cyber and quantum-era threats.

Illustrative close-up of a semiconductor circuit board representing hardware-rooted cybersecurity and encrypted silicon
Illustrative view of a semiconductor circuit board representing hardware-rooted security and encrypted silicon. Photo: Manuel / Unsplash.

Europe’s race to secure the next generation of computing is moving deeper into the silicon itself. Amsterdam-based Fortaegis has completed a $50 million financing round to accelerate commercialization of a security architecture that uses the unique physical characteristics of semiconductor chips as a foundation for trust, identity and encrypted communication. The company says the funding will help move its technology toward broader commercial deployment from 2027, while expanding work with governments and industrial partners in Europe, the United States and Asia.

The financing, reported on September 14, arrives at a moment when cyber security is being reshaped by two forces that are developing at the same time. Artificial intelligence is creating networks of autonomous machines and software agents that may need to authenticate one another and exchange sensitive data at extremely high speed. At the same time, governments and companies are preparing for a future in which sufficiently capable quantum computers could undermine many of the public-key cryptographic systems that protect digital infrastructure today.

Fortaegis is betting that one part of the answer lies not in adding another layer of software but in changing where trust begins. Its approach is based on tiny, unavoidable variations introduced during semiconductor manufacturing. Those variations make each physical chip slightly different. Fortaegis uses that physical uniqueness as a kind of hardware fingerprint, allowing a device to derive security properties from the silicon itself rather than relying entirely on cryptographic secrets stored elsewhere.

That idea places the company in a broader movement toward hardware-rooted security, where identity and trust are anchored as close as possible to the processor and the physical device. It is a technically attractive concept, but also one that must prove itself against a demanding set of practical tests: reliability, interoperability, certification, side-channel resistance, large-scale manufacturing, compatibility with existing standards and the constantly changing threat environment.

A $50 million bet on secure computing

The latest round gives Fortaegis fresh capital to turn a long research program into a larger commercial platform. According to reporting on the financing, the company is working with roughly 25 companies and government organizations across areas including defense, space, telecommunications and data centers. Investors include Singapore-based Serendipity Capital and the venture arm of Japanese semiconductor equipment group Tokyo Electron, while Dutch research organization TNO has already taken both a strategic and financial role in the company.

For a European deep-tech company, the significance of the round is not only the amount raised. Security hardware sits at the intersection of several industries that governments increasingly treat as strategic: semiconductors, artificial intelligence, defense technology, cloud infrastructure, telecommunications and quantum computing. Europe has spent much of the past decade debating how to reduce dependence on foreign technology while preserving access to global supply chains. A company that can claim a defensible position in trusted computing therefore attracts attention far beyond the conventional cyber security market.

Fortaegis describes its product not simply as an encryption chip but as a “secure compute” architecture. The distinction matters. Traditional cyber security products are often layered onto systems after the underlying hardware and operating environment have already been designed. Fortaegis wants identity, trust and secure data exchange to begin with the physical characteristics of the chip and then extend upward through hardware, software and applications.

In practical terms, that means the company is trying to create a common security foundation for very different computing environments: servers in data centers, ruggedized equipment in military or industrial settings, compact edge devices and eventually embedded silicon integrated directly into other products. If that architecture works as intended, a large network of machines could establish trusted relationships without depending on the same centralized mechanisms used by conventional systems.

This is particularly relevant to the emerging world of distributed AI. A data center running machine-learning workloads may contain thousands of accelerators, servers and network components. An industrial system may combine robots, sensors, digital twins and autonomous agents from several vendors. A defense network may need drones, vehicles, communications nodes and command systems to exchange authenticated information with little tolerance for latency. In all of those environments, the number of machine-to-machine trust relationships can grow rapidly.

The physical fingerprint inside every chip

The core principle behind Fortaegis’s technology is familiar to security researchers: semiconductor manufacturing is never perfectly uniform. Even chips produced from the same design and on the same production line contain microscopic differences in their physical and electrical behavior. Those differences are normally treated as manufacturing tolerances. In security engineering, however, they can also be used as a source of device-specific identity.

This family of techniques is commonly associated with physical unclonable functions, or PUFs. A PUF takes advantage of physical variation to produce responses that are extremely difficult to reproduce on another device. Instead of storing a permanent secret in ordinary memory, a system can derive or reconstruct security material from the hardware’s own properties when it is needed.

The attraction is obvious. Stored keys are valuable targets. Attackers can search for them in memory, firmware, databases or poorly protected configuration files. If a device can generate trustworthy cryptographic material from its physical characteristics without keeping the same secret permanently exposed in conventional storage, an attacker’s job can become more difficult.

TNO, the Netherlands Organisation for Applied Scientific Research, has described Fortaegis’s architecture as using a chip’s unique physical fingerprint as the basis for security. TNO says the design is intended to avoid conventional centralized key storage and to establish secure connections without the same public-key exchange mechanisms that are used by many current systems. The research organization entered a strategic partnership with Fortaegis in 2025 and also invested through TNO Ventures.

That support is significant because TNO is not simply a financial investor. It has worked with the company on software foundations, testing methods and evaluation of the communication protocol. The relationship gives Fortaegis access to a research institution with experience in applied cyber security, networking, semiconductor technology and government-linked industrial programs.

Still, hardware uniqueness does not automatically make a security system invulnerable. PUF-based systems must produce consistent results despite temperature changes, voltage fluctuations, aging and manufacturing variation. Designers also have to protect against physical probing, fault injection, side-channel analysis and attempts to model or predict device behavior. The engineering challenge is therefore not merely to show that two chips are physically different, but to turn those differences into a reliable and defensible security primitive under real-world conditions.

Why the quantum question changes the market

Fortaegis has also positioned its architecture as suitable for the quantum era. That is commercially important because the global transition to post-quantum security has moved from a research discussion into an implementation program. In 2024, the US National Institute of Standards and Technology finalized three major post-quantum cryptographic standards: ML-KEM for establishing shared secrets and ML-DSA and SLH-DSA for digital signatures. NIST has urged organizations to begin migrating now rather than waiting for a cryptographically relevant quantum computer to exist.

The underlying risk comes from the fact that a sufficiently powerful quantum computer could break widely used public-key algorithms based on integer factorization and discrete logarithms. Those mathematical problems are extremely difficult for conventional machines at the key sizes used today, but quantum algorithms could change that balance. No machine currently available can break the cryptography protecting modern internet traffic at scale, yet the migration challenge is so large that governments are acting years in advance.

NIST’s transition planning anticipates deprecating and eventually removing quantum-vulnerable algorithms from its standards by 2035, with high-risk systems expected to move earlier. That creates a powerful market incentive for vendors that can reduce the operational cost of the transition or offer complementary ways to establish trust.

It is important, however, to distinguish Fortaegis’s hardware-rooted design from standardized post-quantum cryptography. NIST’s algorithms are publicly specified mathematical constructions that have gone through an international evaluation process and are intended to become interoperable standards. Fortaegis’s architecture is a proprietary platform built around the physical identity of silicon and a broader secure-compute model. Calling a system “quantum-safe” does not by itself mean that it replaces ML-KEM, ML-DSA or other standardized post-quantum mechanisms in every application.

The more realistic possibility is that hardware-rooted identity and standardized post-quantum algorithms will coexist. A chip can provide a trusted physical anchor, while standardized cryptographic protocols protect communication across open networks and between different vendors. In high-assurance environments, multiple layers may be preferable to relying on a single mechanism.

That layered approach also helps explain why Fortaegis is targeting defense, critical infrastructure and AI rather than ordinary consumer devices first. These sectors can justify specialized hardware if it reduces latency, strengthens identity or removes vulnerable key-management steps. They are also sectors where customers may be willing to adopt new architectures before they are ubiquitous in mass-market computing.

From autonomous drones to data-center AI

The company’s list of intended applications reveals how much cyber security is changing. One use case is communication between autonomous drones. A drone operating in a contested environment may need to authenticate commands, share sensor data, coordinate with other vehicles and reject spoofed messages, all while connectivity is intermittent and computing resources are constrained. Traditional certificate and key-management systems can be difficult to operate at that speed and scale.

Another target is the data center, where the rapid growth of AI has created vast new flows of sensitive information between accelerators, storage systems and servers. Training a large model can require data to move across many machines, often in parallel. Inference systems may distribute requests across clusters and increasingly across multiple locations. Protecting those flows without introducing major performance penalties is becoming a priority for cloud providers and enterprises.

Fortaegis says its architecture can provide secure communication with substantially lower overhead than conventional cryptographic approaches. Financial Times reporting on the company cited claims of communication speeds as much as 200 times faster than existing cryptographic protocols in some contexts. That figure should be treated as a company performance claim rather than a universal benchmark. Cryptographic speed depends heavily on hardware, network conditions, protocol design, message size and what is being compared.

Even so, the performance question is central. Security systems that add too much latency are often weakened, bypassed or disabled. This is especially true in industrial control, automated trading, telecommunications, robotics and military systems, where milliseconds can matter. A hardware-rooted security layer that operates with minimal delay could therefore solve a real problem if its benefits survive independent testing across realistic workloads.

Telecommunications is another promising market. Modern mobile and fiber networks depend on enormous numbers of devices establishing trusted relationships across distributed infrastructure. The move toward software-defined networks, edge computing and AI-assisted operations increases the number of components that may need strong identity. At the same time, telecom infrastructure is treated by governments as a national-security asset because disruption can affect emergency services, finance, transport and public administration.

Energy networks face similar pressures. As electricity grids become more digital, they depend on sensors, control systems, distributed energy resources and remote maintenance. The more connected the grid becomes, the more important device identity and secure communication become. Hardware-rooted trust cannot eliminate every cyber risk, but it can potentially reduce one class of problem: uncertainty about whether a device is what it claims to be.

The ASML connection raises the stakes

One of the most closely watched parts of Fortaegis’s expansion is a Dutch high-tech research project involving ASML and Eindhoven University of Technology. The project, known as Secure-by-Design Autonomous Cyber Defense in High Tech Systems, began in July 2026 and is scheduled to run until January 2030. Its budgeted cost is just over €1.07 million.

The project aims to develop a distributed trusted execution environment for autonomous AI systems operating across different hardware platforms. ASML contributes systems-engineering expertise, Fortaegis supplies secure-silicon technology and Eindhoven University provides embedded-systems knowledge. The planned work includes hardware-rooted identities and secure communication designed to let AI agents collaborate across heterogeneous computing environments.

The most striking element is the intended pilot inside ASML’s TwinScan systems. ASML’s lithography equipment is among the most complex industrial machinery in the world and sits at the heart of advanced semiconductor production. Testing a security architecture in that environment would provide a demanding demonstration of whether a distributed trust model can operate inside tightly controlled, high-value industrial systems.

The collaboration should not be interpreted as proof that Fortaegis technology has already been adopted across ASML products. The program is explicitly a research and validation project, and the work runs for several years. But it gives Fortaegis an opportunity to test its ideas in an environment where reliability, precision and security requirements are unusually high.

It also reinforces a larger European industrial strategy. The Netherlands occupies an outsized position in the global chip ecosystem because of ASML, NXP, ASM International, research organizations such as TNO and a dense network of specialized suppliers. Fortaegis is trying to build a security layer within that ecosystem rather than compete directly in processor design or lithography.

A global supply chain behind a sovereignty story

The company’s growth also illustrates the limits of simple slogans about technological sovereignty. Fortaegis is Dutch, but its hardware strategy remains tied to a global semiconductor supply chain. Earlier reporting on the company said its chips are manufactured by Taiwan Semiconductor Manufacturing Company, while Dutch group Prodrive Technologies handles assembly and integration in Eindhoven.

That arrangement is typical of modern chip companies. Designing a specialized security architecture does not mean building a semiconductor fabrication plant. Leading-edge foundries cost tens of billions of dollars and require expertise that only a small number of companies possess. For a European start-up, using TSMC while keeping design, integration and key parts of the engineering stack in Europe can be a rational compromise.

But it also means that “sovereign” technology is rarely completely sovereign. Components, design tools, manufacturing equipment, packaging and materials cross multiple borders. The strategic question is often not whether a country can control every step, but whether it owns enough of the intellectual property and production knowledge to avoid a single point of geopolitical dependence.

Fortaegis’s investor base reflects the same international logic. Serendipity Capital is based in Singapore and invests heavily in quantum and security technologies. Tokyo Electron is one of Japan’s most important semiconductor equipment companies, and its venture arm invested in Fortaegis in 2025. TNO brings Dutch institutional support, while the company says it is working with partners in the United States, Europe, Singapore and Japan.

That network may be a commercial advantage. Security products are notoriously difficult to sell internationally if customers fear dependence on a foreign supplier they do not trust. A company that can show relationships across allied industrial ecosystems may find it easier to enter sensitive markets. Conversely, it will also face export controls, procurement rules and national-security reviews as its technology becomes more relevant to defense and critical infrastructure.

Europe’s cyber-security problem is becoming a hardware problem

For years, much of enterprise cyber security focused on software: antivirus tools, firewalls, identity platforms, endpoint agents and cloud monitoring. Those systems remain essential, but the expansion of AI and connected infrastructure is pushing security deeper into the hardware stack. The reason is simple: software cannot reliably verify the integrity of the underlying machine if the hardware foundation itself is compromised or impersonated.

Trusted platform modules, secure enclaves, hardware security modules and device-rooted credentials are all part of the same broad shift. Fortaegis is attempting to go further by making the intrinsic physical properties of silicon central to identity and communication across an entire compute architecture.

Europe has reasons to be interested. The continent has strong industrial and research capabilities but has struggled to produce technology companies of the scale of American cloud providers or Asian semiconductor manufacturers. Cyber security offers a different route to strategic relevance because trust can become a layer embedded across products made by other companies.

The European Union’s Cyber Resilience Act, new rules around digital identity, stricter supply-chain requirements and growing defense spending all increase demand for demonstrable security. At the same time, Europe’s industrial base is becoming more connected, automated and AI-driven. Those trends reward vendors that can prove security claims in measurable ways rather than simply promise protection.

That last point is crucial. Security technology is full of ambitious labels: unhackable, quantum-proof, zero-trust, military-grade and secure by design. None of them should be treated as guarantees. Every system has assumptions, dependencies and attack surfaces. The decisive question for Fortaegis will be whether independent testing, customer deployments and standards work show that its architecture provides meaningful advantages under realistic conditions.

The challenge of proving security rather than branding it

Hardware security has one uncomfortable characteristic: weaknesses can be expensive to fix after deployment. A software vulnerability can sometimes be patched remotely within days. A flaw embedded in silicon may require firmware mitigations, replacement hardware or a redesign of the next chip generation. That raises the stakes for validation before large-scale adoption.

Fortaegis will therefore need evidence in several areas. The first is repeatability. A chip fingerprint must remain stable enough to support authentication over the lifetime of a device. The second is uniqueness. Different devices must be distinguishable with extremely low collision risk. The third is resilience against attackers who can observe, probe or manipulate the hardware.

The fourth challenge is interoperability. Large companies do not want a security architecture that works only inside one vendor’s closed ecosystem. They need it to connect with existing identity systems, network protocols, key-management infrastructure and post-quantum standards. That is especially true in telecom, cloud and industrial environments where equipment from many vendors must operate together for years.

The fifth is certification. Government and defense customers often require formal evaluation against security standards before purchasing technology at scale. Claims of resistance to quantum attacks or physical compromise will eventually need to be translated into clearly defined threat models, test procedures and assurance levels.

TNO’s involvement may help with that process because independent evaluation is more persuasive than vendor testing alone. But a research partnership is not the same as universal certification. The technology will still need broader scrutiny as deployments grow.

Why AI makes machine identity more urgent

The rise of autonomous AI agents may ultimately be the most important commercial driver. Today, most digital identity systems are designed around people, applications and relatively static servers. AI agents introduce entities that can create tasks, call tools, communicate with other agents and make decisions at machine speed. That creates a new security problem: how does one autonomous system know that another is genuine, authorized and operating on trusted hardware?

Software credentials can answer part of that question, but credentials can be stolen, copied or misconfigured. Hardware-rooted identity provides another signal. If an agent’s identity is bound to a specific physical device or secure execution environment, impersonation becomes more difficult.

The idea becomes more powerful when combined with confidential computing and trusted execution environments. An organization may eventually want proof not only that it is communicating with the correct machine, but that the machine is running approved code inside a protected environment and that sensitive data is not exposed elsewhere in the system.

This is the logic behind the ASML, Fortaegis and Eindhoven University project. The goal is not simply encryption between two computers. It is a distributed trust layer for autonomous AI systems operating across different platforms. If such a model can be made interoperable and fast, it could become relevant to factories, transport networks, defense systems and data centers.

It could also become relevant to the broader debate about AI governance. Rules for artificial intelligence often focus on model behavior, data privacy and human oversight. As agents gain more operational autonomy, hardware identity and secure execution may become part of how organizations prove that an AI system is running in an authorized environment.

A competitive field, not an empty market

Fortaegis is not entering an empty market. Major chipmakers already integrate security features into processors. Cloud providers are expanding confidential-computing services. Specialist vendors sell hardware security modules, secure elements and trusted execution technologies. Post-quantum cryptography is being implemented across network protocols and enterprise products.

The company’s opportunity is therefore not simply to prove that hardware-rooted security works. It must show that its particular architecture is faster, easier to manage or more resilient than alternatives, and that those advantages are significant enough to justify integration into complex systems.

Its strongest argument may be convergence. Instead of treating device identity, secure communication, post-quantum readiness and distributed AI as separate security problems, Fortaegis wants to address them through one silicon-rooted platform. Customers may find that attractive if it simplifies infrastructure. They may reject it if it creates a new proprietary dependency.

That tension is common in enterprise technology. Integrated platforms can reduce operational complexity but increase vendor lock-in. Open standards can improve interoperability but may be slower to evolve. The companies that succeed often find a way to combine proprietary innovation with enough standards compatibility to make customers comfortable.

What the new funding does — and does not — prove

The $50 million round is evidence that sophisticated investors and industrial partners see commercial potential in Fortaegis. It is not evidence that the architecture has already become a new security standard. Funding validates investor appetite, not cryptographic strength.

That distinction matters because cyber security markets can move quickly from excitement to disappointment. Technologies that look elegant in laboratory demonstrations often encounter difficult integration problems in production. Performance claims can change when systems are tested at scale. Hardware that works in controlled conditions may behave differently under temperature, power or electromagnetic stress.

Fortaegis appears to be addressing those risks by working with applied-research institutions and industrial partners before attempting mass deployment. TNO provides validation and research support. Prodrive contributes European assembly and integration. The ASML project offers a path to testing in complex industrial equipment. International investors and customers expose the architecture to different requirements.

The next stage will be harder. Commercialization requires repeatable manufacturing, customer support, developer tools, integration documentation, certification and a convincing economic case. A security system can be technically impressive and still fail if deployment is too difficult or expensive.

The target of broader commercialization from 2027 gives the company little room for purely conceptual work. Customers will increasingly expect measurable evidence: latency under specific workloads, resilience under attack, failure rates across large device populations and compatibility with modern post-quantum protocols.

The migration clock is already running

The urgency surrounding post-quantum security is not based on the assumption that a cryptographically relevant quantum computer will appear tomorrow. It comes from the lifespan of sensitive information and infrastructure. Intelligence records, industrial designs, medical data and strategic communications may need to remain confidential for many years. Attackers can collect encrypted traffic now and retain it in the hope that future computing systems will make decryption possible later. This “harvest now, decrypt later” problem means the effective deadline for protecting long-lived data can arrive well before the quantum machine itself.

Infrastructure replacement cycles make the timing even more difficult. Telecom equipment, industrial controllers, military platforms and data-center hardware can remain in service for a decade or longer. If equipment installed in 2027 still depends on mechanisms that are difficult to upgrade in the 2030s, operators may inherit an expensive security problem. That is one reason governments are pushing cryptographic agility: systems should be designed so algorithms and trust mechanisms can be replaced without rebuilding the entire platform.

A silicon-rooted architecture therefore has to solve two apparently competing problems. It must make identity harder to copy, while remaining flexible enough to coexist with changing cryptographic standards. A device that is physically unique but locked permanently to obsolete protocols would not be future-proof. The long-term value comes from combining a durable hardware trust anchor with software and protocol layers that can evolve.

For European customers, this also intersects with regulation. Critical-infrastructure operators are under pressure to demonstrate stronger supply-chain security, incident resilience and risk management. Manufacturers face new obligations under the Cyber Resilience Act, while financial, telecom and public-sector organizations are tightening requirements for third-party technology. Hardware security will increasingly be evaluated not only by engineers but by auditors, regulators and procurement teams asking for evidence that protections can be maintained throughout a product’s life.

That could favor Fortaegis if its platform reduces the complexity of managing trust across large device fleets. It could also expose weaknesses quickly if the technology requires proprietary tools that customers cannot independently assess. In security markets, transparency and auditability often become commercial features in their own right.

A European technology story with global consequences

The broader importance of Fortaegis lies in what it says about the direction of computing. The boundaries between cyber security, semiconductors, artificial intelligence and geopolitics are disappearing. A chip is no longer only a processor. It can be an identity anchor, a policy enforcement point and a component of national critical infrastructure.

That change favors countries with strong semiconductor ecosystems, but it also creates openings for smaller companies with specialized intellectual property. Europe does not need to manufacture every advanced processor to remain strategically relevant. It can build technologies that sit inside the trusted layer of systems designed elsewhere.

The Netherlands is particularly well placed for that strategy because it already occupies a critical position in semiconductor equipment. If Dutch companies can add secure silicon, trusted-compute architecture and industrial cyber security to that position, the country could strengthen its role in the parts of the technology stack where governments are increasingly reluctant to rely on unknown suppliers.

For Fortaegis, the opportunity is large but the burden of proof is equally large. The company is asking customers to rethink where digital trust begins. Instead of starting with certificates, software credentials or centralized key stores, it starts with microscopic differences created when silicon is manufactured.

That is an elegant idea. Whether it becomes an industry-changing platform will depend on how well the engineering survives contact with real networks, real attackers and real procurement rules.

For now, the new financing gives the company the resources to find out. It also sends a broader message: in the AI and quantum era, Europe’s next cyber-security battleground may not be the cloud, the firewall or the endpoint. It may be the chip itself.

Trending

Discover more from The Tower Post

Subscribe now to keep reading and get access to the full archive.

Continue reading