Foundation Passport
Best for verifiable firmware openness
How it rates
- Firmware source published in a public repository
- Device security or specification page published
- Technical documentation reachable without an account
- No dedicated security or audit disclosure identified at this check
- Terms page not found at the conventional address at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetFirmware source published in a public repository
Vendor repository reachable at this check.
github.com/Foundation-Devices - MetDevice security or specification page published
Security or specification page reachable at this check.
foundation.xyz/passport/ - Not metIndependent security research or audit programme published
No published security research or audit programme identified at this check.
- MetTechnical documentation reachable without an account
Documentation open at this check.
docs.foundation.xyz/ - MetVendor organisation identifiable from the repository
Repository published under the vendor organisation (Foundation Devices).
github.com/Foundation-Devices
- Met
- Met
- Not metLegal or terms page public
Not found at the conventional address at this check.
- Met
- MetPurchase information viewable without an account
No account required to reach the shop at this check.
foundation.xyz/
- Met
- MetFirmware repository is the vendor's own
Repository published by the vendor.
github.com/Foundation-Devices - Met
- MetDocumentation site separate from marketing
Dedicated documentation or support resource published.
docs.foundation.xyz/ - MetSecurity posture stated publicly
Security claims published on a reachable page.
foundation.xyz/passport/
- Met
- MetVendor entity identifiable
Vendor organisation identifiable as Foundation Devices.
github.com/Foundation-Devices - Not metSecurity or disclosure page published
Not identified at this check.
- Not metTerms or legal documentation published
Not found at the conventional address at this check.
- Met
- Met
- Met
- Met
- Met
- Not metLegal documentation reachable
Not found at the conventional address at this check.
A Bitcoin-only air-gapped signer with open hardware and firmware, assembled in the United States, working through QR codes and microSD only.
Our assessment
Foundation Passport Core is a Bitcoin-only air-gapped signer with a keypad and camera. There is no Bluetooth, no Wi-Fi, no NFC, and the USB-C port carries power only — everything in or out goes through a QR code or the microSD slot. Hardware and firmware are both open source, and the device is assembled in the United States.
Air-gapped without qualification
Several devices marketed as air-gapped keep a USB data path available. Passport does not — the physical design removes the option rather than defaulting it off. Combined with open hardware schematics, this is one of the few devices where the isolation claim can be checked rather than taken on trust.
Supply chain as a stated position
US assembly and published hardware designs answer the question most hardware wallet buyers cannot otherwise resolve: who built this, and could something have been added along the way. It does not eliminate supply-chain risk, but it makes the chain shorter and inspectable, which is more than most competitors offer.
It expects you to bring your own wallet
Passport works through PSBTs with Bitcoin Core, Sparrow, Specter, Nunchuk, BlueWallet, Casa, Electrum and BTCPay, alongside its own Envoy app with built-in Tor. That breadth means the device is a signer rather than an ecosystem, and it will outlive any single companion app.
Who it suits
Passport fits Bitcoin-only holders who want open hardware, genuine air-gapping and a Western supply chain, and who are comfortable with QR and microSD workflows. Multi-chain users are in the wrong category — look at Keystone, OneKey or Trezor.
How rivals compare
| Service | Score | Best for | |
|---|---|---|---|
| Trezor | 9.9 | verifiable firmware openness | Read → |
Frequently asked
Does this score mean Foundation Passport is secure?
No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.
Why does firmware openness matter so much here?
It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.
What would raise this score?
Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.