Skip to main content

Highly secure access to data and applications, secured by smartcard

ECOS SecureBootStick FX

The ECOS SecureBootStick FX allows companies to admit the use of private and third-party PCs in compliance with the highest security requirements. Compared to conventional solutions, administration effort and costs are significantly reduced while user satisfaction is increased.

The ECOS SecureBootStick FX offers numerous security features cast in hardware. It also features an integrated smartcard and an integrated keypad allowing direct PIN entry on the stick. All encryptions and processes are secured by smartcard. Hhis ensures highly secure remote access for your applications.

"Totally easy to use!"

  1. Connect boot stick to PC or Mac
  2. Power on PC or Mac
  3. ECOS Secure Linux starts automatically. The local hard disk is deactivated.
  4. When stick flashes: enter PIN
  5. Connect to your working environment
  6. Log in as usual & go!"

- Sebastian Hülle, Sales Assistant -

10 good reasons for the ECOS SecureBootStick FX

Protected and encapsulated working environment

100% separation of professional / private use

All software on the stick

Strong multi-factor authentication via smartcard

Integrated firewall

Central management & remote update

Fast roll-out, even for large quantities

Data safe for the storage of documents

Smartcard forwarding

Low investment costs

hochgestreckte Hand tippt mit Zeigefinger auf gelben Button mit Aufschrift Demo

Free trial

Take your time and try our free DEMO KIT!

Deckblatt der Broschüre zum Secure Boot Stick von ECOS

Security to the X-treme

Are you interested in the ECOS SecureBootStick? brochure?

Read brochure
Ein gelbes Fragezeichen vor vielen dunkelgrauen Fragezeichen

Any questions?

Use our contact form and we will get in touch with you as soon as possible.

Contact form
Technichal data of the ECOS SecureBootStick FX


  • RDP client, Citrix Workspace app (formerly Citrix Receiver), VMware Horizon via RDP, PCoIP, BLAST, Firefox, Chromium, VNC Viewer, VPN client for IPsec
  • Citrix HDX RealTime Media Engine to optimize audio and video transmission for Skype for Business and Microsoft Teams
  • Microsoft RemoteFX for optimizing audio quality with RDP

Supported destination systems

  • Microsoft RDSH, WTS 2000 and later, RDS, RD sharing, Citrix Virtual Apps & Desktops, VMware Horizon or web server


  • Connection to default gateway via IPsec, OpenVPN or HTTPS
  • Additional VPN clients: Cisco AnyConnect, Juniper, F5 (additional licenses may be required)


  • Profiles for access to different applications/servers on user, group or role level
  • Use of local resources after release (external USB storage devices, local printers)
  • Rights assignment for external devices bound to manufacturer ID or serial number of the device
  • Remote update of all applications and firmware


  • Integrated smartcard reader for cards in ID-000 format
  • Drivers for all popular 64-bit PCs, Macs and tablets with x86 architecture
  • UEFI Secure Boot support
  • Keyboard drivers for more than 90 languages and countries
  • Multi-monitor support
  • Connection by LAN, WLAN, UMTS, LTE incl. browser for login to hotspot
  • Software in German and English (pre-configurable)

Data safe

  • 2 GB, usable for storing documents (not for VS-NfD), (larger storage capacities on request)
  • Hardware encryption with AES-256, secured by smartcard plus PIN
  • Installation-free use as USB drive in Windows, Linux and macOS

Additional features

  • Signing, encryption or Windows smartcard logon with PC/SC forwarding
  • Forwarding of external USB and LAN devices, e.g. for the connection of an IP telephone
  • Automatic reconnection after disconnection or connection change

Multi-factor authentication

  • Software certificate, tied to stick’s hardware ID and smartcard
  • Integrated numeric keypad for PIN entry on the stick


  • Write-protected and signed partitions for bootloader and kernel
  • Encryption by hardware of all security-relevant partitions
  • Signed read-only partition for firmware and applications
  • Writeable partition for storage of user parameters
  • Hardened ECOS Secure Linux operating system
  • Digitally signed bootloader, firmware and applications validated in chain of trust
  • All processes secured by smartcard, e.g. Easy Enrollment, sign-on to gateway, stick update
  • Integrated firewall protecting against attacks over the same network and blocking ping requests
  • Encryption of RAM content except for the executable program code
  • VM start detection to prevent use in virtual environment
  • Fingerprinting of the guest computer incl. peripherals
  • Instant logout on stick disconnection
  • Secured updating process for firmware and applications with verification of integrity and correct update server

Connection, dimensions and scope of delivery

  • USB-A | C | micro - 28 x 85 x 13 mm – 68 g
  • ECOS SecureBootStick FX and carrying strap, 2 connection cables for USB A and C