The secure space internet infrastructure company 🛰️ Orbital confidential computing and security services

https in orbit
Joined May 2024
Giving an AI agent its own private key is one of the riskiest security decisions you can make right now. A private key allows software to sign transactions for you, and researchers have already tricked AI agents into signing transfers to wallets the researchers controlled. A key management service (KMS) keeps keys locked away and still allows agents to use them, without ever having full access to the key itself. There's 3 critical reasons your agents need a KMS that is actually secure👇 1. A tricked agent can't leak the key if it never has full access to it 2. Limits live at the key level, so when you set a limit like "never send more than $500" the agent cannot bypass this limit 3. Hardware-isolated environments (like TEEs) let you verify where signing happens instead of trusting a server As agents get more capable, a trusted KMS is how you decide what they're actually allowed to do. We see this as critical infrastructure to the future of the space internet. More to share on this soon 👀
1
3
9
494
Post Quantum Cryptography (PQC) is critical infrastructure for space technologies. And this is a much deeper conversation than just preparing for the inevitability of quantum computers breaking classic cryptographic encryption. We need to build adaptable, software-enabled post-quantum migration solutions for spacecrafts that work with data in any capacity. At SpaceComputer, PQC readiness and migration is a top priority amongst our cybersecurity solutions. Subscribe & watch the full video on YouTube: youtu.be/oa4zc0JiwH0
1
3
1
9
625
Post-quantum migration is fundamentally a key management problem. You can’t upgrade key security if you can’t find the keys. A key management service (KMS) centralizes key generation, storage, access control, rotation, and audit, so keys live in one hardened place, like a trusted execution environment (TEE). That's security you need today. Post quantum cryptography (PQC) is security for the future where quantum computers will eventually break public key encryption. These threats are relevant today. Harvest now, decrypt later attacks collect encrypted data today to break it once quantum machines are strong enough. So why do you need both? When every key lives in a KMS and you swap in quantum-resistant algorithms, every key inherits the upgrade. The KMS becomes your layer of cryptographic agility. A KMS also automates the mechanics of generating new keys, re-encrypting data, and key rotation and retirement across your stack. It also absorbs the friction of PQC's larger keys and signatures so your applications stay fast. With quantum computing still on the horizon, and KMS options available from every cloud provider, why is SpaceComputer building a post-quantum agile platform? One simple reason: a satellite launched today must be ready for the next 5-10 years. You can't add hardware in orbit (for obvious reasons), so crypto-agility must be built in before launch. Our KMS will anchor keys in attested TEEs, non-exportable by design: they can be used but never extracted. We're starting with hardened infrastructure on Earth, eventually moving to keys born in orbit inside a satellite-based TEE, with post-quantum readiness currently in development. So we ask you: how are your security keys managed today? And if you could test a KMS built for orbit: would you? Drop a 🙋 below if you'd want early access.
3
5
1
8
418
Post-quantum cryptography changes the math that supports your security without changing how it works on the surface. You'll still have a private key and a public key. The algorithms are migrated within a key management service to withstand quantum computers, not just classical ones. @rezabfil breaks it down in the clip below 👇
1
14
700
If your satellite isn't secure at launch, it can be compromised with as little as a software-defined radio and a few software bugs. "So we have to consider the life cycle and the lifetime of the designs of the respective choices, the respective spacecrafts and make sure that there are solutions for that." That's our mission at at SpaceComputer: building secure satellite computing systems for the long term, starting at the hardware and software level. Catch the full deep dive with on YouTube: youtu.be/mip1p4zy3Ks
2
3
1
7
510
Every spacecraft and ground station in the data chain needs security and end-to-end verifiability. One of the best use cases for this is satellite imaging. Our approach to this is to use cryptographically verify what image came from which satellite. This high-security guarantees help prove the image wasn't tampered with, which is useful for providers and data users alike. Let us know in the comments what other use cases verifiability in orbit could be used for? 🤔
4
3
10
529
For some applications, the most secure place to run a computer is where nobody can reach it. For others physical inaccessibility is the biggest limitation. We spend a lot of time thinking about these kinds of tradeoffs that come with building compute systems in orbit. On Earth, compute is abundant and trust is the hard part. Roughly 55% of data center security incidents come from the inside. In orbit - nobody can access the satellite, and therefore the physical attack surface is ≈0. In orbit, that same isolation means no repairs, radiation-constrained chips, and a power budget where one satellite roughly equals one GPU today. So which one do you build on? It depends on what applications you're building for and the level of in-depth security you need. If physical possession of the hardware is part of your threat model, orbit offers guarantees Earth can't match. If you need fast, large-scale compute, and your threat model is handled by conventional controls, Earth wins on practicality. (For now). So where do you sit on the tradeoffs of physical isolation and capabilities on Earth versus on orbit? Let us know in the comments 👇
2
2
7
402
At SpaceComputer, we look at our open infrastructure the way the internet once looked at Linux. Linux infrastructure is open, auditable, and vendor-neutral. That openness is why it’s the foundation of the internet: hyperscalers, competitors, and governments could all standardize on it, because trusting Linux never meant trusting a vendor. We're doing the same for the space internet. Our infrastructure design, Space Fabric, is built on open verification. We publish our tech stack and system design, and work with hardware partners like Tropic Square also take an open source approach. We incorporate Raspberry Pis into our infrastructure due to their exceptional interoperability across diverse applications. Linux was one of the biggest companies to build backbone level verifiable infrastructure into what it is today. The space internet needs the same foundation, and we're building it. Explore the solutions we offer now: spacecomputer.io/solutions/?…
2
1
1
6
488
The space sector inherited so much of its culture from government bureaus, where information was gatekept. That culture is changing fast, and we're ushering in a new spirit to the space sector. Our choice to build open source infrastructure in orbit is a choice that has left people puzzled. Everything about the space industry incentivizes keeping the tech in a walled garden. 3 reasons companies choose close source: 1. Protect expensive IP 2. National security laws & compliance 3. Control every detail of the system All three concerns come down to the same question: who holds system data, and what happens if that data ends up in the wrong hands. Cryptography changes this calculation by adding verifiability and encryption. For comparative reference: your bank publishes which encryption standards it uses and keeps your keys secret, and the same logic applies in orbit. Satellite-based TEEs and cryptographic attestation lets the customer verify while everything else stays confidential. Being open source is a choice that shapes how we operate: a development process distributed across the world, deliberate decisions about which components we pick for our stack. Head to the full podcast episode on our architecture: youtu.be/mip1p4zy3Ks
1
6
495
This Sunday, August 16th, Co-Founders @semicondurian and @rezabfil are joining @SpaceShow with Dr. David Livingston! We'll be discussing how SpaceComputer is building the secure space internet: satellite-based TEEs, Space Fabric, and why the next generation of spacecraft needs credibly neutral, interoperable infrastructure. The Space Show is live with questions, so show up ready to ask yours! Tune in on Zoom at 2 PM PDT / 5 PM ET: thespaceshow.com/show/16-aug…
1
4
2
15
1,339
As the space internet emerges, so do its applications. Onboard AI processing of Earth observation (EO) data. Satellites connecting directly to your phone. Today, connectivity inside a single constellation is possible, but between different vendors, they don't link. Connectivity across services is a goal at this stage. Reaching it will be critical to offer secure services from orbit the same as we do on Earth. Here's how a secure system would complete a user's request: A query enters through an API for analyzed EO data. A ground station finds an available satellite, books the contact window, and translates the request into a signed task. The EO satellite captures the imagery, then passes the data to a compute satellite. Onboard AI would extract the answer inside a trusted execution environment (TEE), with attestation verifying what code ran. Only the results are downlinked back through the ground station to the user. This connectivity and interoperability is what will make the space internet comparable to Earth internet. As more spacecraft and active satellites head into orbit, we need applications that connect securely end to end across satellites, ground stations, and everything in between. Where do you think in this process will have the biggest challenges with reaching Earth-level capacities? 🛰️
3
4
1
16
996
By not considering security now, you are sending obsolete infrastructure to space. Space compute is accelerating, and as @semicondurian says, the signal for robust secure compute in space is highlighted by 2 space trends: 1. more complex compute systems 2. more cyber warfare @rezabfil: "Use AI as an example. When a general user wants to interact with the infrastructure, it opens the attack vector massively. You make to make sure systems are built with this in mind. It wasn't like this in the past...the barrier to entry was high, and you needed to be a state-level attacker to access the domain...now it's a matter of a software-defined radio and a couple of bugs to access it." As barrier to entry lowers, more infra moves to space, and we must look for solutions for the threats that will arise in the future, especially for the missions flying for 2030 and beyond. Tune into the rest of the conversation with Frontier Pod host @ideacasino on building secure multi-purpose space infrastructure: youtu.be/mip1p4zy3Ks
1
3
12
722
After 6 months it's finally time... the next episode of the Frontier Pod is live! 🚀 We had none other than @rezabfil on to discuss how to build space internet infrastructure, and SpaceComputer's most recent architecture development: Space Fabric. On this episode we dive into what it takes to build for a future with orbital compute and multi-purpose satellites applications, instead of siloed, single purpose satellites. Subscribe and watch the full episode on YouTube: youtu.be/mip1p4zy3Ks
2
4
2
14
596
What is one of the strongest binding elements for connectivity between layers of internet infrastructure in space? Operations. Similar to enterprises, without interoperability, the operational capabilities between service layers remain siloed. It limits usability and decreases the output of what you can get in terms of services. We're working to eliminate that for the space internet. As we discussed previously, there are six layers to space internet infrastructure (what we're working to build). Those are: 1. ground stations 2. communications 3. compute 4. data 5. analytics 6. security Operations tie everything together. We're connecting each layer using Orbitport: our secure gateway for orbital services. Orbitport handles the operations that satellite infrastructure demands. ✅ Scheduling and prioritizing satellite passes. ✅ Buffering batched data in short contact windows. ✅ Routing data from ground stations into one processing pipeline. ✅ Verifying signatures so data integrity holds from satellite to consumer. ✅ All services accessible through one API. What this means for space operators is they can all use a new provider or payload without changing your stack or code. That's operations across different layers of space internet infrastructure, handled in one place. Learn how the architecture works in our docs: docs.spacecomputer.io/docs/c…
1
3
1
11
428
Interoperability and connectivity are the two things stopping space internet infrastructure from scaling to meet space services needs on Earth. We're building within each of these layers to solve to solve that blockage. Here's how the different layers of the stack work, and how we can start connecting each of them: blog.spacecomputer.io/6-laye…
How many layers of the space internet tech stack do you think have emerged? We see six. Ground stations move data between Earth and orbit. The comms layer carries it between satellites. The computing layer processes it where it's generated. More compute is moving to space in the next decade. The data layer stores and routes it. More data is moving to space with compute and increase in satellite usage globally. The analytics layer turns it into intelligence, processed via the compute layer. And the security protects all processes from bad actors. Connectivity gets most of the attention when you say 'space internet.' A functioning space internet, similar to Earth internet infrastructure, needs every layer operating together. Today, each of these layers is being built by teams working on different stacks, that may or may not be interoperable. That's why adaptability matters as much as capability. Infrastructure for the space internet has to plug into each layer, whichever stack it lives in. We built Space Fabric to integrate vertically across the stack, with security and post-launch adaptability in mind Drop a follow to see how all these layers interoperate! 👀
1
1
8
489
Replying to @rezabfil
@rezabfil presenting our Space Fabric architecture paper Currently at Science of Blockchain Conference – at Stanford, CA
2
2
14
404