Discovery & inventory
Find every camera, controller, PLC and switch by multi-protocol discovery — ONVIF, network scan, industrial — auto-classified by device class and capability tier (A / B / C).
The platform
Skans is a single self-contained appliance that becomes an isolated network's root of trust — the directory and certificate authority it never had — then layers on access control, patching, backup, monitoring, vulnerability assessment and audit-ready compliance evidence. One console runs all of it. It's air-gapped by default and set up by the technician who installs the cameras, not a security team — everything inside, nothing leaving the wire.

The core idea
Most isolated networks share one gap: the cameras, intercoms and controllers on them can't domain-join or enroll themselves, there's no directory or IT team on site, and yet every device is still expected to carry an identity, encryption and access control. Skans becomes the authority the enclave never had — it stands up a directory and a certificate authority on the appliance itself, then issues every device its own X.509 identity from that one CA. Nothing about your enclave lives on anyone else's server.

What's in the appliance
The same appliance that mints identity runs every control built on top of it. One console, air-gapped by default, nothing of yours leaving the wire.
Find every camera, controller, PLC and switch by multi-protocol discovery — ONVIF, network scan, industrial — auto-classified by device class and capability tier (A / B / C).
A built-in CA issues a real X.509 certificate to each device — pushed onto the cameras and controllers that can't enroll themselves, and to Windows, Linux and macOS endpoints through a lightweight agent.
802.1X EAP-TLS admits only trusted, cert-bearing devices through the appliance's native RADIUS; MAB and dynamic VLANs handle limited gear; legacy OT is segmented and gated.
Staged patch rings for Windows without WSUS, an offline missing-KB scan, and a vetted, SHA-256-hashed firmware repository for cameras and IoT — no endpoint ever reaching the internet.
Encrypted, off-box backups of the database, directory system-state, device and network configs, and endpoint data — so nothing irreplaceable lives in one place. Restore is a documented, drilled break-glass procedure.
Push-first, event-driven collection with an always-on alert engine that produces correlated findings bounded by device count — signal that scales with your fleet, not a raw event firehose.
The CVE List and MITRE ATT&CK sync to the box and match your live inventory with a strict version-range gate — CVSS-scored, KEV/EPSS-ranked findings that hand off to patch approval. No cloud scanner in the loop.
Every device login and secret is envelope-encrypted into an SQL vault, each under its own key sealed to the appliance — TPM-backed hardware protection where a TPM is present. Every reveal and copy is audited.
Live NIST 800-171 / CMMC posture by control family, an ISO 27001 crosswalk, and a signed, one-command evidence pack backed by a tamper-evident audit chain — evidence you hand an assessor, never a certification.
The operator sees outcomes — 'cameras encrypted · 2 certs expiring' — never AD, Kerberos or a CLI. Ask or command the appliance in plain language over a correlated, role-based worklist.
Compliance by design
Skans is the enclave's technical control plane and evidence generator. It satisfies the hard technical controls of NIST 800-171 / CMMC Level 2, maps them to control families you can read at a glance, and produces an assessment-ready evidence pack from live state on one command — no hand-collation, and it works air-gapped. It shrinks the boundary an assessor has to look at; it never claims to certify you.

Signal over noise
Monitoring is push-first and event-driven — an agent event, a syslog message, an SNMP trap lands the instant it happens and fires the alert engine. Findings are correlated and bounded by device count, so a 200-device site produces alerts on the order of devices affected, not thousands of raw events. Offline CVE and MITRE ATT&CK intel matches your live inventory on the box itself, with nothing leaving the wire.

How it's built
The whole appliance runs from one role-based console — ask or command it in plain language, or read the triage at a glance: what needs you, where compliance stands, whether last night's backup ran. It's disconnected by default: your identities, keys and data never leave, and a severed WAN changes nothing about your protection. Setup is two or three plain questions and one button; the directory, CA and RADIUS stand up behind it.

Talk to us
Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.