Option-byte configuration, dual-bank firmware layout, and the RDP-level decisions that decide whether your secure boot survives JTAG re-attachment in the field.
Field telemetry across two identical sensor fleets running different RTOSes: watchdog resets, memory fragmentation events, and the developer-time cost of each.
How we wrap peripheral HALs to enable host-side unit testing, what we mock vs simulate, and the CI matrix we run before any firmware tag enters production.
A/B partition layout, rollback timer placement, and the test matrix we use to certify an OTA pipeline against random brown-outs at every stage.
Detection, recovery, and the GPIO-driven bus-clearing routine we ship by default — plus an analysis of which sensor families produce the most hangs.