Signed, then installed
OS updates, Defender payloads and firmware images are all cryptographically verified — Authenticode to a Microsoft publisher, SHA-256 to the repository — before anything touches a host.
Patch & firmware management
Skans keeps an isolated enclave current the way an island demands. The appliance pulls and caches Microsoft updates, stages them through pilot-then-production rings, and Authenticode-verifies every payload to a Microsoft publisher before a single host installs it — while a hash-verified repository does the same for camera and OT firmware. No WSUS, no vendor cloud, nothing of yours leaving the wire.

Change control
WSUS is a dead end on Windows Server 2025 — its catalog sync floods errors and never completes, so Skans doesn't use it. Instead the appliance's own Windows Update Agent pulls and caches updates, and you stage the rollout by ring. Promote a representative host into the pilot ring, approve the update there, watch it, then roll the fleet. Both rings keep Windows Update quiescent, so nothing installs and nothing reboots until you say so.

Visibility
You can't patch what you can't see, and an island can't ask Microsoft what it's short. So Skans scans each Windows host against Microsoft's offline wsusscn2.cab catalog with the Windows Update Agent — no internet required — and lists the exact KBs each host lacks. Open a device's Updates tab to read enclave-wide patch posture without a single endpoint calling home.

Firmware
Cameras, intercoms and controllers don't take Windows updates — they take vendor firmware, and firmware is exactly where a supply-chain attack hides. Skans keeps a vetted, SHA-256-hashed repository per vendor and model, populated offline from a signed bundle so nothing enters the enclave unverified. The box compares each device's live firmware against the vetted baseline and flags what's drifted.

Why it holds
OS updates, Defender payloads and firmware images are all cryptographically verified — Authenticode to a Microsoft publisher, SHA-256 to the repository — before anything touches a host.
The appliance caches everything endpoints need. For a true air-gap, content imports from a signed bundle; the optional, operator-controlled Skans Update Service only pulls signed content down — it never sends your data out.
Windows Update stays quiescent and a human approves each update into each ring. There is deliberately no CVE-to-exact-fix automation making changes behind your back.
A vulnerability finding hands off to the patch-approval flow carrying the fixed-in version — so the path from 'what's wrong' to 'approved and staged' is one lane, not two disconnected tools.
Compliance
Patch and firmware currency isn't a certification; it's an enabler. Skans maps the work you're already doing to the control families an assessor asks about and hands the record over. It supplies the technical evidence — the attestation stays a human process, and the organizational, people and physical controls stay yours.

Talk to us
Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.