
Build Compliant.
Ship Globally.
Stay Protected.
XEO gives ENDS manufacturers the hardware-enforced verification infrastructure needed for PMTA approval, TPMF documentation, and global market access. Stop losing revenue to regulatory uncertainty. Integrate once, certify everywhere.
Konform produzieren.
Global ausliefern.
Sicher bleiben.
XEO bietet ENDS-Herstellern die hardwaregesicherte Verifizierungsinfrastruktur für PMTA-Zulassungen, TPMF-Dokumentation und globalen Marktzugang. Schluss mit Umsatzverlusten durch regulatorische Unsicherheit. Einmal integrieren, überall zertifizieren.
WHAT HAPPENS
WITHOUT XEO
Manufacturers shipping non-compliant devices face regulatory action, market exclusion, and financial penalties that far exceed the cost of integration. These are the three critical gaps XEO eliminates.
WAS PASSIERT
OHNE XEO
Hersteller, die nicht-konforme Geräte ausliefern, riskieren behördliche Maßnahmen, Marktausschluss und Geldstrafen, die die Integrationskosten bei weitem übersteigen.
没有XEO
会发生什么
出货不合规设备的制造商面临监管处罚、市场禁入和远超集成成本的罚款。以下是XEO消除的三大关键缺口。
Regulatory Rejection & Market Lockout
Without hardware-level compliance verification, PMTA submissions lack the technical defensibility regulators demand. Products get rejected, markets close, and competitors with compliant devices capture your share. Every month without approval is revenue permanently lost.
Regulatorische Ablehnung & Marktausschluss
Ohne Hardware-Compliance-Verifizierung fehlt PMTA-Anträgen die technische Belastbarkeit, die Regulierungsbehörden verlangen. Produkte werden abgelehnt, Märkte schließen sich, und Wettbewerber mit konformen Geräten übernehmen Ihren Marktanteil.
监管拒绝与市场封锁
缺乏硬件级合规验证,PMTA申请将缺少监管机构要求的技术防御力。产品被拒,市场关闭,拥有合规设备的竞争对手抢占您的份额。每一个未获批的月份都是永久损失的收入。
Counterfeit Exposure & Brand Erosion
Devices without cryptographic authentication are trivially counterfeited. Knockoff products damage your brand reputation, create safety liability, and undermine legitimate distribution channels. You carry the legal risk for products you never manufactured.
Fälschungsrisiko & Markenverfall
Geräte ohne kryptografische Authentifizierung werden problemlos gefälscht. Nachahmerprodukte schädigen Ihren Markenruf, schaffen Sicherheitshaftung und untergraben legitime Vertriebskanäle.
假冒风险与品牌侵蚀
没有加密认证的设备极易被仿制。假冒产品损害品牌声誉,制造安全责任风险,并破坏合法分销渠道。您要为从未生产过的产品承担法律风险。
Post-Market Monitoring Blindspot
Regulators increasingly require continuous monitoring of devices in the field. Without embedded telemetry and verification logging, you cannot demonstrate ongoing safety, respond to adverse events, or fulfill post-market monitoring obligations mandated by FDA and TPD.
Blindstelle bei Post-Market-Monitoring
Regulierungsbehörden verlangen zunehmend kontinuierliches Monitoring von Geräten im Feld. Ohne eingebettete Telemetrie und Complianceprotokollierung können Sie keine laufende Sicherheit nachweisen.
上市后监测盲区
监管机构日益要求对市场中的设备进行持续监测。没有嵌入式遥测和合规日志,您无法证明持续安全性,无法响应不良事件,也无法履行FDA和TPD规定的上市后监测义务。
FROM EVALUATION
TO CERTIFICATION
Four structured phases take your device from initial assessment to market-ready compliance. Each phase has defined deliverables, timelines, and technical milestones.
VON DER BEWERTUNG
ZUR ZERTIFIZIERUNG
Vier strukturierte Phasen bringen Ihr Gerät von der Erstbewertung zur marktfertigen Compliance.
从评估
到认证
四个结构化阶段,将您的设备从初始评估带到市场就绪合规。每个阶段都有明确的交付物、时间表和技术里程碑。
TWO INTEGRATION
ARCHITECTURES
Choose the integration model that matches your device architecture, production timeline, and market strategy. Both deliver full compliance coverage.
ZWEI INTEGRATIONS-
ARCHITEKTUREN
Wählen Sie das Integrationsmodell, das zu Ihrer Gerätearchitektur, Produktionszeitlinie und Marktstrategie passt.
两种集成
架构方案
选择与您的设备架构、生产时间线和市场策略匹配的集成模式。两者均提供完整合规覆盖。

- Chip-level compliance module (ARM Cortex-M compatible)
- Offline biometric age verification (face + fingerprint)
- Tamper-resistant cryptographic device identity
- AEAD encrypted telemetry with local buffering
- OTA firmware update capability
- <200ms authentication latency
- <3% additional battery consumption
- Chiplevel Compliancemodul (ARM Cortex-M kompatibel)
- Offline biometrische Altersverifizierung
- Manipulationsresistente kryptografische Geräteidentität
- AEAD verschlüsselte Telemetrie
- OTA Firmwareupdatefähigkeit
- <200ms Authentifizierungslatenz
- <3% zusätzlicher Batterieverbrauch
- 芯片级合规模块(ARM Cortex-M兼容)
- 离线生物识别年龄验证(面部+指纹)
- 抗篡改密码学设备身份
- AEAD加密遥测与本地缓冲
- OTA固件更新能力
- <200ms认证延迟
- <3%额外电池消耗

- Plug-in BLE/NFC module (no firmware redesign needed)
- Cloud-based real-time device authorization
- Geographic licensing enforcement
- Remote compliance policy updates
- API-first architecture (REST + WebSocket)
- No changes to the existing production line required
- Compatible with existing MCU platforms
- Plug-in BLE/NFC-Modul (kein Firmwareredesign)
- Cloud-basierte Echtzeitgeräteautorisierung
- Geografische Lizenzdurchsetzung
- Remote Compliance-Policy-Updates
- API-First-Architektur (REST + WebSocket)
- Keine Änderungen an der bestehenden Fertigungslinie erforderlich
- Kompatibel mit bestehenden MCU-Plattformen
- 插入式BLE/NFC模块(无需固件重设计)
- 基于云的实时设备授权
- 区域授权执行
- 远程合规策略更新
- API优先架构(REST + WebSocket)
- 无需改动现有生产线
- 兼容现有MCU平台
WHY ON-DEVICE
NOT ON-PHONE
The FDA's March 2026 draft guidance on Device Access Restrictions (DAR) makes clear: point-of-sale age checks alone are insufficient. The next generation of compliance must be built into the device, not delegated to a smartphone app.
WARUM IM GERÄT
NICHT AM TELEFON
Die FDA-Leitlinie vom März 2026 zu Device Access Restrictions (DAR) stellt klar: Alterskontrollen am Point-of-Sale allein reichen nicht aus. Die nächste Generation der Compliance muss ins Gerät eingebaut sein, nicht an eine Smartphoneapp delegiert.
为什么内置于设备
而非依赖手机
FDA 2026年3月关于设备访问限制(DAR)的指南草案明确指出:仅依靠销售点年龄验证是不够的。下一代合规必须内置于设备,而非委托给智能手机应用。
| CriterionKriterium对比项 | Phone-Based SystemsPhone-Basierte Systeme手机方案 | XEO EMB / EXT-DL |
|---|---|---|
| Biometric LocationBiometriestandort生物识别位置 | On smartphone (consumer hardware)Auf dem Smartphone (Consumer-Hardware)智能手机上(消费级硬件) | On device (hardened compliance module)Im Gerät (gehärtetes Compliancemodul)设备内(加固合规模块) |
| Smartphone Required?Smartphone erforderlich?需要智能手机? | Yes. No phone, no accessJa. Kein Phone, kein Zugang是,无手机则无法使用 | No, fully autonomousNein, vollständig autonom否,完全自主 |
| ConnectivityKonnektivität连接方式 | Bluetooth pairing mandatoryBluetooth-Pairing obligatorisch必须蓝牙配对 | Onboard LTE/WiFi + offline capableOnboard LTE/WiFi + offlinefähig内置LTE/WiFi + 离线能力 |
| Bypass RiskUmgehungsrisiko绕过风险 | Adult verifies on phone, hands device to minorErwachsener verifiziert am Phone, gibt Gerät weiter成人在手机验证后将设备交给未成年人 | Fingerprint is non-transferable, person-boundFingerabdruck ist nicht übertragbar, personengebunden指纹不可转让,绑定个人 |
| Idle BehaviorIdle-Verhalten闲置行为 | Auto-deactivates after 15 min. Re-pair requiredAutodeaktivierung nach 15 Min. Erneutes Pairing nötig15分钟后自动停用,需重新配对 | Continuous on-device auth, instant re-verificationKontinuierliche On-Device-Auth, sofortige Reverifikation持续设备端认证,即时重新验证 |
| Post-Market SurveillancePost-Market-Monitoring上市后监测 | Not included, access control onlyNicht enthalten, nur Zugangskontrolle不包含,仅访问控制 | Full telemetry + automated FDA reportingVolle Telemetrie + automatisiertes FDA-Reporting完整遥测 + 自动化FDA报告 |
| FDA DAR ComplianceFDA DAR-KonformitätFDA DAR合规 | Biometric ✓ Geofencing ✓ Continuous ✗Biometrie ✓ Geofencing ✓ Kontinuierlich ✗生物识别 ✓ 地理围栏 ✓ 持续验证 ✗ | Biometric ✓ Geofencing ✓ Continuous ✓Biometrie ✓ Geofencing ✓ Kontinuierlich ✓生物识别 ✓ 地理围栏 ✓ 持续验证 ✓ |
| Counterfeit DetectionFälschungserkennung假冒检测 | Product authentication via appProduktauthentifizierung via App通过应用进行产品认证 | Cryptographic POD ID + real-time telemetryKryptografische POD-ID + Echtzeittelemetrie加密烟弹ID + 实时遥测 |
| Product-Side IntegrationProduktseitige Integration产品侧集成 | Some architectures require additional BLE electronics on the device or battery sideManche Architekturen benötigen zusätzliche BLE-Elektronik geräte- oder batterieseitig部分架构需在设备或电池侧增加额外 BLE 电子元件 | Reusable intelligence sits in the Digital Lighter, designed to minimize product-side electronicsWiederverwendbare Intelligenz im Digital Lighter, auf minimale produktseitige Elektronik ausgelegt可复用智能置于数字打火机中,旨在减少产品侧电子元件 |
No Smartphone Dependency
Phone-based systems create a new dependency that excludes users without smartphones. XEO eliminates it. Every verified user interacts directly with the device.
Keine Smartphoneabhängigkeit
Phone-basierte Systeme schaffen eine neue Abhängigkeit. XEO eliminiert sie. Jeder verifizierte Nutzer interagiert direkt mit dem Gerät.
无需智能手机
手机方案增加了新的依赖。XEO消除了这一问题。每位验证用户直接与设备交互,无论是否拥有智能手机。
Non-Transferable Identity
Phone-based biometrics verify the phone holder, not the device user. An adult can unlock and hand the device to a minor. XEO's on-device fingerprint binds verification to the person holding the device at every use.
Nicht übertragbare Identität
Phone-basierte Biometrie verifiziert den Smartphonebesitzer, nicht den Gerätenutzer. XEO's On-Device-Fingerprint bindet die Verifikation an die Person, die das Gerät bei jeder Nutzung hält.
不可转让身份
手机生物识别验证的是手机持有者,而非设备使用者。XEO的设备端指纹传感器将验证绑定到每次使用时持有设备的人。
Beyond Access Control
Phone-based systems only lock and unlock. XEO is a full compliance platform, generating continuous post-market monitoring data, adverse event detection, and regulatory-ready reports.
Über Zugangskontrolle hinaus
Phone-basierte Systeme sperren und entsperren. XEO ist eine vollständige Complianceplattform, mit Post-Market-Monitoring-Daten, Adverseeventerkennung und Berichten für die behördliche Prüfung.
超越访问控制
手机方案只负责锁定和解锁。XEO是完整的合规平台,生成持续的上市后监测数据、不良事件检测和可供监管审查的报告。
WHAT FDA NOW
WEIGHS FOR FLAVORS
The FDA's March 2026 draft guidance opens, for the first time. A formal pathway for flavored ENDS (Electronic Nicotine Delivery Systems) PMTAs. But approval requires Device Access Restrictions that go far beyond point-of-sale checks. XEO supplies the device level restrictions FDA now weighs in applications for flavored ENDS.
WAS DIE FDA BEI
AROMEN BEWERTET
Der FDA-Leitlinienentwurf vom März 2026 eröffnet erstmals einen formalen Weg für PMTAs zu aromatisierten ENDS (elektronische Nikotinabgabesysteme). Aber die Zulassung erfordert Device Access Restrictions, die weit über Point-of-Sale-Kontrollen hinausgehen. XEO liefert die geräteseitigen Zugangsbeschränkungen, die die FDA bei Anträgen für Aroma-ENDS inzwischen in die Bewertung einbezieht.
FDA如何评估
调味产品
FDA 2026年3月的指南草案首次为调味电子烟(ENDS,电子尼古丁传输系统)PMTA开辟了正式途径。但审批要求设备访问限制远超销售点检查。XEO提供设备级访问限制,FDA在调味ENDS申报的评估中已将其纳入考量。
FDA FLAVOR RISK FRAMEWORK
FDA FLAVOR-RISIKO-FRAMEWORK
FDA口味风险框架
XEO does not replace a PMTA. XEO supplies one building block and the evidence for it.
- Tobacco Product Master File (TPMF) reference
- Letter of Authorization
- Documentation of the device level access restrictions
- Post-market monitoring data
- Toxicology
- Emissions data
- Clinical evidence
- The PMTA submission itself
XEO ersetzt keine PMTA. XEO liefert einen Baustein und die Belege dafür.
- TPMF-Referenz (Tobacco Product Master File)
- Letter of Authorization
- Dokumentation der geräteseitigen Zugangsbeschränkungen
- Post-Market-Monitoring-Daten
- Toxikologie
- Emissionsdaten
- Klinische Evidenz
- Die PMTA-Einreichung selbst
XEO不替代PMTA。XEO提供其中一个组成部分及其证明文件。
- 烟草产品主档案(TPMF)参考
- 授权书(LOA)
- 设备级访问限制的文档
- 上市后监测数据
- 毒理学
- 排放数据
- 临床证据
- PMTA申报本身
THE HIDDEN COST
AFTER APPROVAL
Getting a PMTA approved is just the beginning. The FDA requires continuous post-market reporting for the entire lifetime of every Marketing Granted Order. Periodic reports, adverse event documentation, sales tracking, and risk profile updates. For most manufacturers, this means permanent compliance headcount and external consultants. XEO automates it.
DIE VERSTECKTEN KOSTEN
NACH DER ZULASSUNG
Eine PMTA-Zulassung ist erst der Anfang. Die FDA verlangt kontinuierliche Post-Market-Berichterstattung für die gesamte Lebensdauer jeder Marketing Granted Order. Periodische Berichte, Adverseeventdokumentation, Verkaufstracking und Risikoprofilupdates. Für die meisten Hersteller bedeutet das permanentes Compliancepersonal und externe Berater. XEO automatisiert das.
审批后的
隐性成本
获得PMTA批准仅仅是开始。FDA要求在每项营销授权令的整个生命周期内持续进行上市后报告,包括定期报告、不良事件文档、销售追踪和风险概况更新。对大多数制造商而言,这意味着永久性的合规团队和外部顾问。XEO将其自动化。
FREQUENTLY ASKED
QUESTIONS
HÄUFIG GESTELLTE
FRAGEN
常见
问题
What is the difference between XEO EMB and EXT-DL integration?Was ist der Unterschied zwischen XEO EMB und EXT-DL?XEO EMB和EXT-DL集成有什么区别?
+How long does the full integration process take?Wie lange dauert der gesamte Integrationsprozess?完整集成流程需要多长时间?
+What regulatory documentation does XEO generate for submissions?Welche regulatorische Dokumentation erstellt XEO für Anträge?XEO为申报生成哪些监管文档?
+Does integrating XEO EXT-DL require changes to our production line?Erfordert die Integration von XEO EXT-DL Änderungen an unserer Fertigungslinie?集成 XEO EXT-DL 是否需要改动我们的生产线?
+Does XEO support multi-market compliance from a single integration?Unterstützt XEO Multimarktcompliance aus einer einzigen Integration?XEO是否支持一次集成实现多市场合规?
+What is XEO's pricing model for manufacturers?Wie sieht das Preismodell von XEO für Hersteller aus?XEO面向制造商的定价模式是什么?
+READY TO BUILD
COMPLIANT?
Request a free technical evaluation of your device architecture. Our engineering team will deliver a compatibility report, integration roadmap, and cost estimate within two weeks.
BEREIT FÜR
COMPLIANCE?
Fordern Sie eine kostenlose technische Bewertung Ihrer Gerätearchitektur an. Unser Engineeringteam liefert innerhalb von zwei Wochen einen Kompatibilitätsbericht.
准备好
合规生产?
申请免费技术评估。我们的工程团队将在两周内提供兼容性报告、集成路线图和成本估算。