Breaking / Platform Security$100M Series C+ announcedAX3080 fits a 25 × 25 mm packageHardware trust meets local AISan Jose, California
Company profile Hardware / AI / Enterprise

The Tiny Computer Guarding the AI Server

Axiado is betting that the safest place to watch an AI server is beneath its operating system. Its security processor combines the machine's keys, management controls and local threat detection in one closely guarded piece of silicon.

There is a second computer hiding inside a modern server. It can turn the machine on, check its temperature, update its firmware and let an administrator reach it from another continent. This baseboard management controller, or BMC, is not the glamorous part of an AI rack. It is closer to a building superintendent with a master key. And because that key opens nearly every door, the controller is also a delicious target.

Axiado Corporation has built its company around a deceptively simple response: if the control layer is already watching the server, make it the server's security guard too. The San Jose semiconductor startup calls its chip a Trusted Control/Compute Unit, or TCU. It combines the BMC with a hardware root of trust, a trusted platform module, cryptographic storage, network controls and dedicated machine-learning engines. Instead of scattering those jobs across separate chips and firmware domains, Axiado pulls them into one hardware-anchored control plane.

That architecture puts Axiado in an unusual patch of the market. It is part cybersecurity company, part systems-management supplier and part fabless chipmaker. It does not sell a familiar dashboard that a security team can install on Tuesday. Its customer must design the processor or a module containing it into a server, switch or telecom platform. The sales cycle is slower, the validation burden is heavier and the potential foothold is much deeper.

One chip, several jobs
BMCRemote control and telemetry
ROOT OF TRUSTVerified boot and identity
TPM + HSMKeys and cryptography
FIREWALLControl-plane traffic
SECURE AIBehavioral detection close to the metal
FORENSICSLow-level evidence and logs
A small neighborhood with one very vigilant block captain. Axiado's TCU folds management, trust and detection into the server's privileged control layer.

Security software can be blinded by the machine it protects

Most enterprise defense lives above the hardware: endpoint agents, operating-system controls, network appliances and cloud monitoring. Those tools remain necessary, but they inherit a structural problem. Once an attacker gains deep control of the host, the malware may tamper with the very sensors meant to expose it. Firmware attacks are worse. They can begin before the operating system loads and persist underneath a clean software reinstall.

A hardware root of trust addresses part of that risk by verifying identity and code during boot. Axiado extends the idea from a checkpoint into a patrol. Its Secure Vault protects cryptographic keys and supports attestation. Its Secure AI engines are designed to observe patterns in platform telemetry, including activity associated with ransomware, network anomalies and some side-channel or supply-chain attacks. Because the monitoring runs in the TCU, separate from the host CPU and its workload, Axiado argues that an intruder has a harder time switching off the alarm.

“The most powerful security camera in the rack may be the computer too small to notice.The architectural wager behind Axiado

The word “AI” needs careful handling here. Axiado is not placing a chatbot beside the motherboard. It uses specialized machine-learning cores and models to classify behavior from low-level signals. That proximity can shorten the distance from observation to mitigation, but it does not repeal the ordinary rules of security. Detection quality depends on the models, the available telemetry, correct platform integration and continuous testing. A chip can create a more defensible vantage point. It cannot promise an invulnerable server.

The AX3080 turns consolidation into a security argument

The company's second-generation AX3080, introduced at Computex in 2025, is the sharpest version of the pitch. In a 25 by 25 millimeter package, Axiado says it integrates the BMC, root of trust, TPM, firewall and hardware security module along with LPDDR4 memory, eMMC storage and SPI flash. Those last integrations matter. Every external component and connection is another interface to protect, validate and power. Pulling memory and storage into the package can reduce exposed seams as well as board complexity.

25×25Millimeter AX3080 package
2017Year Axiado was founded
$185MAcross three publicly announced rounds since 2021

Axiado also packages its processors on secure control modules. The SCM3002 and SCM3003 follow the Open Compute Project's DC-SCM approach, which separates common management and security functions from the host processor module. The newer SCM3080-MT targets accelerated-computing systems including NVIDIA MGX designs. For equipment makers, a module can be easier to qualify across a family of servers than a custom controller on every motherboard.

The product family still reflects semiconductor reality: chips, boards, firmware and partner software all have to cooperate. Axiado supports OpenBMC and has worked with AMI around MegaRAC. It also integrated Caliptra, an open-source silicon root-of-trust design promoted through the Open Compute Project. These standards are more than technical decoration. A young supplier asking data-center operators for a privileged seat needs compatibility and external scrutiny to lower the perceived risk.

The same sensors that spot an attack can watch the heat

Axiado has stretched the TCU beyond cybersecurity into power and cooling. Its Dynamic Thermal Management software uses server telemetry and machine learning to adjust cooling behavior in response to workloads. More recent demonstrations add dynamic voltage and frequency scaling, or DVFS. The logic is appealing: a trusted controller already collecting intimate, real-time signals from a server can become a local systems-management brain.

The company has reported cooling-energy reductions of up to 50 percent in its demonstrations. That is a company claim, not a universal operating result; savings will vary with equipment, workload, climate and facility design. Still, the strategic connection is real. AI data centers are constrained not only by chips but by electricity and heat removal. A component that earns its place through security may offer a second budgetary argument to the facilities team.

Where Axiado sits
EDR · SIEM · cloud security
OS · hypervisor · firmware
TCU: trust + management + AI
Most tools watch from above. Axiado takes the basement apartment, close to boot, power, thermals and the management network.

A design-in business, not a download funnel

Axiado's direct audience is the group that builds and operates expensive machines: server OEMs, original design manufacturers, hyperscalers, cloud providers, telecom vendors and large enterprises. Its announced integrations span GIGABYTE, Pegatron, Jabil, Posiflex and Portwell, with demonstrations on systems using NVIDIA, AMD and Intel architectures. Supermicro, VVDN, WNC and AMI have also appeared in its ecosystem. These announcements prove interoperability and engineering collaboration; they should not automatically be counted as high-volume customer contracts.

That distinction reveals the business model. Axiado sells silicon and modules, then works through design wins that can travel into production platforms. Samples, firmware compatibility and joint demonstrations lead toward orders. Pricing and software terms are private. Unlike a software subscription, revenue can arrive in uneven steps tied to qualification and server production, while each accepted design can generate unit sales over a hardware generation.

The alternatives come from several aisles. ASPEED is entrenched in BMC silicon. Server brands offer proprietary management stacks such as iLO and iDRAC. Established vendors sell discrete TPMs, roots of trust and hardware security modules. NVIDIA, AMD Pensando and Intel supply adjacent data-center processors and accelerators. Meanwhile, endpoint and workload-security companies defend from the software layer. Axiado's difference is the bundle: management, cryptographic trust, firewall functions, hardware forensics and local AI in one control-plane system-on-chip.

Consolidation removes interfaces, but it also concentrates responsibility. Buyers must judge the security architecture, firmware lifecycle, model performance, supply continuity and recovery path as one system.

Capital buys time, but infrastructure buyers grant trust slowly

Founded in 2017, Axiado spent years moving from architecture to samples to public integrations. Gopi Reddy Sirineni, a veteran of the semiconductor and networking industries, became chief executive in 2020 and is now identified by the company as founder, president and CEO. The company announced a $25 million Series B in 2021, a $60 million Series C led by Maverick Silicon in December 2024 and a $100 million Series C+ in December 2025. Those three disclosed rounds total $185 million. Supplied company data places total funding at $205 million, suggesting earlier capital not itemized in those announcements.

The 2025 round arrived after the AX3080 launch and a busy sequence of partner demonstrations. In 2026, Axiado expanded in India with a Bengaluru office, continued presenting its thermal and voltage-control work, and publicized awards for enterprise security and zero-trust innovation. Its LinkedIn headcount band is 51 to 200, while supplied data estimates roughly 150 employees. Public recruiting posts describe a culture that moves across AI, firmware, silicon and security, with engineering teams in the United States, India and Taiwan.

For Axiado, the opportunity is being created by the AI boom and complicated by it. More accelerated servers mean more valuable workloads, denser power consumption and a larger management surface. They also mean exacting customers who cannot casually swap a control component after deployment. The company must persuade buyers that an integrated newcomer is safer and more supportable than a collection of familiar incumbents.

If that argument lands, the TCU becomes more than a security accessory. It becomes the part of the server that knows how the whole machine is behaving - from its boot signature to its fan curve - yet remains outside the operating system it is judging. The least visible computer in the rack could become one of its most consequential.

Hardware securityAI infrastructureSemiconductorsData centersEnterprise