Overview
The official USB separates user-visible product content from protected product-managed runtime material:Boot boundary
Product-managed boot material for Enigm Link Boot OS.
Visible app boundary
User-visible Enigm Link volume with desktop apps and official device trust material.
Boot OS boundary
Product-managed runtime material for the bootable Enigm Link environment.
Visible Content Model
The visible USB content should remain simple and predictable:macOS: shows only the macOS app.Windows: shows only the Windows executable.Linux: shows only the Linux executable.
Official Device Trust Material
Enigm Link uses official device trust material to validate the USB and support lifecycle operations. Official trust material supports:- Device validation.
- Update eligibility.
- Controlled update workflows.
- Product lifecycle state.
- Enigm Command registration for eligible deployments.
Closed Product Model
Enigm Link is delivered as a closed official USB product. Users and customers should not:- Repartition the USB.
- Format the visible volume.
- Replace Boot OS material manually.
- Rebuild the device from public files.
- Modify official trust material.
- Treat internal files as user-managed configuration.
Security Boundaries
The visible app boundary and Boot OS boundaries have different responsibilities.- The visible app boundary stores platform apps and official device trust material.
- Boot OS boundaries support boot and isolated runtime behavior.
- Boot OS updates must preserve visible app content and official USB identity.
- App updates must preserve official trust material and avoid leaving incomplete visible folders.