Security: UEFI Secure Boot and Secure Start support
Tamper-free updates - components digitally signed and verified
Immutable Silicon Root of Trust
Ability to rollback firmware
FIPS 140-2 validation
Secure erase of NAND/User data
Common Criteria certification
Configurable for PCI DSS compliance
Embedded TPM (Trusted Platform Module) 2.0. Excluded for shipments to China.
Advanced Encryption Standard (AES) and Triple Data Encryption Standard (3DES) on browser
Support for Commercial National Security Algorithms (CNSA)
Secure Recovery - recover critical firmware to a known good state on detection of compromised firmware