Boot Security Mastery Conference 2026

TrustedServer: From a Verified Image to an Attested Machine
2026-09-24 –, GPN-T Main Room

ExpressVPN introduced TrustedServer in 2019, moving its VPN server fleet to a stateless architecture in which every server starts from a signed, read-only image loaded into RAM, with changes to the running operating system discarded at reboot.
Seven years in production have settled the question of whether RAM-only infrastructure works. The more interesting question now is how much further its trust boundary can extend.
Those security properties — no persistence across reboot, and a fleet that provably runs identical code — rest almost entirely on one thing: the integrity of the boot path that gets the image into RAM. This talk focuses on that path rather than the RAM-only story around it. We are candid about the threat model: what signature verification does and does not buy you, and the classes of attack a stateless design does not eliminate on its own — supply-chain compromise of the image, boot-chain tampering, and physical or DMA-adjacent threats.
We then outline where we want to go next: hardware-rooted verified and measured boot, freshness-bound remote attestation, rollback-resistant policy, and the release of short-lived secrets only to an acceptably attested machine. We have come to pressure-test that direction with the people who work closest to firmware, roots of trust, and platform attestation.

See also: slides (964.7 KB)

Francesco Castellana, Staff Software Engineer, has been with ExpressVPN since 2016. Starting as Operations #1 in the company and moving later to the TrustedServer Engineering team, he helped bringing many of the technologies behind ExpressVPN's servers to production. He is a Chartered Engineer, holds an MBA and a Master's degree in Computer Science.
When he's not tinkering with TrustedServer, you might find him jamming on the (black-and-white) keyboard in some backroom of some bar.

Fediverse: @xfranky@ioc.exchange