Design & Reuse

Microservice Store Launches "embedded Microservice Runtime", The Foundational Technology Powering a Secure Marketplace for IoT Devices

Jan. 12, 2026 – 

Cambridge, United Kingdom, Microservice Store today announced the embedded Microservice Runtime, a new foundational technology designed to bring a true digital marketplace to life on real embedded hardware. Built for microcontrollers and engineered for real-time performance, the Embedded Runtime enables a secure software supply chain for the edge, where Microservices can be published, discovered, deployed, updated, and monetised, safely and independently in the field, even on the smallest devices.

The Embedded Runtime supports a broad range of architectures, including Arm Cortex-M (Armv6-M, Armv7-M, TrustZone for Armv8-M), RISC-V, and CHERI, and is engineered to operate down to Cortex-M0-class targets. At its core, the Runtime integrates an integrated Micro Hypervisor, an integrated Secure Kernel, and an integrated Security Manager, enabling organisations to deploy isolated, updateable functionality without turning firmware into a monolithic, tightly coupled block.

“This foundation is only the beginning,” said a Bella Nguyen, Director at Microservice Store. “For decades, edge devices have been held back by a 1970s mindset, one giant firmware image, tightly coupled components, and risky updates, but we are breaking that cycle. We are building a modern future on this core technology, where embedded devices evolve safely in the field, component by component, with cloud-style modularity and embedded-grade determinism. Most importantly, we are enabling a marketplace where individuals and inventors can become entrepreneurs, delivering verified microservices that fuel innovation across the embedded ecosystem.”

Turning embedded software into a living marketplace, built by community

Embedded products have traditionally been delivered as single, integrated firmware releases, making every upgrade a full-device event, and making third-party innovation difficult to adopt safely. The Microservice Store Embedded Runtime introduces a new operating model, deployable plug-and-play Microservices delivered as isolated Microcontainers, so device capabilities can evolve continuously in the field, with minimised risk, even for third-party software.

By providing the missing execution layer for a marketplace-driven ecosystem, the Runtime enables:

  • A secure software supply chain for devices, where every Microservice is verifiable, authenticated, HW access policy-controlled, and lifecycle-managed
  • A new embedded “store economy”, where developers, individuals, and specialists can publish reusable functionality and monetise it
  • Faster time-to-market, by assembling products from plug-and-play Microservices rather than rebuilding and revalidating monolithic firmware
  • Lower operational risk, by isolating faults and security violations to the smallest possible component
  • Long-lived products, with safer updates, controlled rollback, and resilience built into the runtime

Architecture built for real-time constraints and proactive security

The Embedded Runtime integrates three tightly coupled layers, each designed specifically for embedded constraints and real-time requirements.

1) integrated Micro Hypervisor

The integrated Micro Hypervisor brings Docker-style containers and cloud microservices to MMU-less microcontrollers. Microservices are turnkey and plug-and-play versions of Microcontainers; isolated, language- and toolchain-independent executables that can be deployed individually.

To preserve real-time determinism, Microcontainers execute as native machine code, avoiding interpreter layers and minimising runtime overhead.

2) integrated Secure Kernel

The platform supports the simultaneous execution of multiple containers, each capable of managing multi-threaded workloads. The integrated Secure Kernel securely schedules both containers and their private sub-threads across the system and provides essential OS services including IPC, mutexes, and semaphores, ensuring robust synchronisation and predictable resource management.

3) integrated Security Manager

The integrated Security Manager provides proactive protection by acting as a dedicated security monitor for the entire device. It is designed to support alignment with global security standards including PSA and SESIP, and to help manufacturers meet regional compliance expectations such as UK PSTI, the EU Cybersecurity Act, and applicable requirements across the US and Asia.

In the event of a security violation or system malfunction, the integrated Security Manager can quarantine the compromised block, log the incident to the vendor, and continues the operations and  initiates system recovery.

Apart from the device level protection, integrated Security manager extends the protection down to the individual component; each Microcontainer and Microservice is treated as an independent virtual environment with its own lifecycle controls, authentication and confidentiality, access policies, and attestation structure.

Availability

The Microservice Store Embedded Runtime is available as part of the Microservice Store platform for evaluation and integration on supported microcontroller targets.

Microservice Store provides public remote test HW Setups/Evaluation kits for developers to test the platform for free using Web Browsers.

About Microservice Store

Microservice Store is building a digital marketplace and secure software supply chain for embedded and IoT devices. The platform enables reusable Microservices to be published, discovered, deployed, updated, and monetised, bringing cloud-style modularity, proactive security, and lifecycle automation to the edge.