Skip to main content
The official Enigm Link USB is the sealed physical distribution and identity boundary for Enigm Link. It is delivered by Enigm as a prepared device and is not intended to be installed, formatted, rebuilt, or provisioned by end users. The USB contains the platform apps, official device trust material, and Boot OS material required for supported workflows. Public documentation describes the device model and trust boundaries; it does not provide manufacturing, provisioning, internal storage details, or installation instructions.

Overview

The official USB separates user-visible product content from protected product-managed runtime material:

Boot boundary

Product-managed boot material for Enigm Link Boot OS.

Visible app boundary

User-visible Enigm Link volume with desktop apps and official device trust material.

Boot OS boundary

Product-managed runtime material for the bootable Enigm Link environment.
The visible app boundary is critical. It contains the desktop apps, official device trust material, and user-facing platform folders. Boot OS update workflows must preserve this boundary on the official USB.

Visible Content Model

The visible USB content should remain simple and predictable:
  • macOS: shows only the macOS app.
  • Windows: shows only the Windows executable.
  • Linux: shows only the Linux executable.
Auxiliary files, staging data, update backups, autorun files, and internal metadata are hidden or cleaned within host-platform constraints. Users should not need to inspect or modify internal files.

Official Device Trust Material

Enigm Link uses official device trust material to validate the USB and support lifecycle operations. Official trust material supports:
  • Device validation.
  • Update eligibility.
  • Controlled update workflows.
  • Product lifecycle state.
  • Enigm Command registration for eligible deployments.
Official trust material must be preserved during app updates and Boot OS updates. Update workflows must not treat the visible app boundary as disposable storage.

Closed Product Model

Enigm Link is delivered as a closed official USB product. Users and customers should not:
  • Repartition the USB.
  • Format the visible volume.
  • Replace Boot OS material manually.
  • Rebuild the device from public files.
  • Modify official trust material.
  • Treat internal files as user-managed configuration.
Supported lifecycle actions are performed through Enigm Link itself and governed through Enigm Command. This keeps official device identity, update eligibility, and protected-state behavior tied to Enigm’s product lifecycle controls.

Security Boundaries

The visible app boundary and Boot OS boundaries have different responsibilities.
  • The visible app boundary stores platform apps and official device trust material.
  • Boot OS boundaries support boot and isolated runtime behavior.
  • Boot OS updates must preserve visible app content and official USB identity.
  • App updates must preserve official trust material and avoid leaving incomplete visible folders.
See Platform Limitations.