The platform

Every control your isolated network needs — in one air-gapped appliance.

Skans is a single self-contained appliance that becomes an isolated network's root of trust — the directory and certificate authority it never had — then layers on access control, patching, backup, monitoring, vulnerability assessment and audit-ready compliance evidence. One console runs all of it. It's air-gapped by default and set up by the technician who installs the cameras, not a security team — everything inside, nothing leaving the wire.

Skans console · NOC
The Skans NOC wall — metric tiles for fleet health, open incidents, compliance percentage, certificates issued, devices by capability tier, open vulnerabilities, events in the on-box store, ATT&CK detections, RADIUS/NPS serving and the search engine, all from one appliance.

The core idea

One box becomes the root of trust the network never had.

Most isolated networks share one gap: the cameras, intercoms and controllers on them can't domain-join or enroll themselves, there's no directory or IT team on site, and yet every device is still expected to carry an identity, encryption and access control. Skans becomes the authority the enclave never had — it stands up a directory and a certificate authority on the appliance itself, then issues every device its own X.509 identity from that one CA. Nothing about your enclave lives on anyone else's server.

  • One CA per enclave — a single root of trust, with the private signing key TPM-protected on the box by default (a FIPS-140-3 HSM is an optional override, not the shipped default).
  • Four enrollment lanes, chosen automatically — Windows auto-enroll via AD CS + GPO, SCEP for standalone devices, a vendor-driver push for cameras and IoT that can't enroll themselves, and protocol-native issuance for OPC UA (GDS Push) and BACnet/SC.
  • Proven across leading camera & IoT brands — Axis, Hanwha, Bosch, 2N, Uniview, ONVIF, Redfish and UniFi are hardware-validated end to end, and the signed driver pack is extensible to any vendor.
  • Capability tiers, honestly applied — full identity where a device can hold a cert, a driver-pushed cert where it's limited, segmentation and a gateway where it's legacy. When a device genuinely can't take a certificate, the driver says so instead of faking it.
Skans console · Devices
The Skans device inventory — cameras, switches and firewalls with their onboarding lane, certificate status, capability tier and reachability, all kept current automatically.

What's in the appliance

Everything the enclave needs — in one box.

The same appliance that mints identity runs every control built on top of it. One console, air-gapped by default, nothing of yours leaving the wire.

Discovery & inventory

Find every camera, controller, PLC and switch by multi-protocol discovery — ONVIF, network scan, industrial — auto-classified by device class and capability tier (A / B / C).

Identity for every device

A built-in CA issues a real X.509 certificate to each device — pushed onto the cameras and controllers that can't enroll themselves, and to Windows, Linux and macOS endpoints through a lightweight agent.

Network access control

802.1X EAP-TLS admits only trusted, cert-bearing devices through the appliance's native RADIUS; MAB and dynamic VLANs handle limited gear; legacy OT is segmented and gated.

Patch & firmware

Staged patch rings for Windows without WSUS, an offline missing-KB scan, and a vetted, SHA-256-hashed firmware repository for cameras and IoT — no endpoint ever reaching the internet.

Backup & recovery

Encrypted, off-box backups of the database, directory system-state, device and network configs, and endpoint data — so nothing irreplaceable lives in one place. Restore is a documented, drilled break-glass procedure.

Continuous monitoring

Push-first, event-driven collection with an always-on alert engine that produces correlated findings bounded by device count — signal that scales with your fleet, not a raw event firehose.

Vulnerability management

The CVE List and MITRE ATT&CK sync to the box and match your live inventory with a strict version-range gate — CVSS-scored, KEV/EPSS-ranked findings that hand off to patch approval. No cloud scanner in the loop.

Credential vault

Every device login and secret is envelope-encrypted into an SQL vault, each under its own key sealed to the appliance — TPM-backed hardware protection where a TPM is present. Every reveal and copy is audited.

Compliance evidence

Live NIST 800-171 / CMMC posture by control family, an ISO 27001 crosswalk, and a signed, one-command evidence pack backed by a tamper-evident audit chain — evidence you hand an assessor, never a certification.

One console

The operator sees outcomes — 'cameras encrypted · 2 certs expiring' — never AD, Kerberos or a CLI. Ask or command the appliance in plain language over a correlated, role-based worklist.

Compliance by design

The evidence an assessor asks for — already in place.

Skans is the enclave's technical control plane and evidence generator. It satisfies the hard technical controls of NIST 800-171 / CMMC Level 2, maps them to control families you can read at a glance, and produces an assessment-ready evidence pack from live state on one command — no hand-collation, and it works air-gapped. It shrinks the boundary an assessor has to look at; it never claims to certify you.

  • Posture by control family — AC, AU, CM, CP, IA, RA and SC, each backed by what the appliance actually measured. A control Skans hasn't verified reads Not Verified — never turned green because a policy should have applied.
  • One-command evidence pack — SSP control status, a live POA&M of gaps, a Skans-technical-vs-customer-organizational responsibility matrix, the asset inventory, the audit log, and a signed manifest.
  • ISO 27001 crosswalk — the same measured checks map to all 93 Annex A controls of ISO/IEC 27001:2022 via NIST's published OLIR mapping; it's your ISMS that gets certified, never a product.
  • Cryptographically tamper-evident — an append-only, hash-linked, signed audit chain detects after-the-fact change. It's tamper-evident, not WORM, and organizational, people and physical controls stay yours.
Skans console · Compliance
The Skans compliance view — a NIST security-posture ring at 67% with per-control-family cards for AC, AU, CM, CP, IA, RA and SC.

Signal over noise

Detection is the appliance's judgment. Where it lands is yours.

Monitoring is push-first and event-driven — an agent event, a syslog message, an SNMP trap lands the instant it happens and fires the alert engine. Findings are correlated and bounded by device count, so a 200-device site produces alerts on the order of devices affected, not thousands of raw events. Offline CVE and MITRE ATT&CK intel matches your live inventory on the box itself, with nothing leaving the wire.

  • Correlated, deduplicated findings — a site-wide outage collapses into a handful of alerts; transient laptops get a 24-hour offline grace so a van of sleeping machines doesn't read as an incident.
  • Offline vulnerability assessment — the CVE List and ATT&CK sync to the appliance and match live inventory with a strict version-range gate; a patched host shows zero findings, and KEV/EPSS rank what's actually exploited.
  • Rules, routing and recorded exceptions — tune rules from the console; a suppression on a compliance-tagged rule demands a written justification and is logged as an explicit risk acceptance, so a silenced control is never an invisible gap.
  • Honest scope — this is push-first collection plus correlation and known-CVE assessment, not a full IDS/EDR, SIEM or NVR. Pair Skans with a dedicated IDS/EDR for complete NIST Detect coverage.
Skans console · Alerting
The Skans alerting view — alert rules listed by name, type, severity, cooldown and routing.

How it's built

One console. Air-gapped by default. Run by the tech who hung the cameras.

The whole appliance runs from one role-based console — ask or command it in plain language, or read the triage at a glance: what needs you, where compliance stands, whether last night's backup ran. It's disconnected by default: your identities, keys and data never leave, and a severed WAN changes nothing about your protection. Setup is two or three plain questions and one button; the directory, CA and RADIUS stand up behind it.

  • Air-gap-first — the one optional egress is the operator-controlled Skans Update Service, and it only pulls signed content down. It never sends your data out, and it's off unless you switch it on.
  • You own the keys — your certificate authority, your identities, your data, on your box. Skans is proprietary, closed-source Windows software; Community Edition is free and runs uncapped in production — independence, not source access.
  • Set up by the install tech — the Setup Wizard hides AD, Kerberos and the CLI; the operator sees outcomes, never certificate chains. The endpoint agent is Authenticode-signed and deploys over GPO — no hand-carried double-click MSI yet.
  • One box, sized for a site — a single self-contained Windows Server appliance today; distributed Core + Edge and high availability are a design-stage Enterprise tier, not shipping yet.
Skans console · Home
The Skans console home — an ask-or-command bar over a correlated worklist of what needs attention, compliance posture, and backup status.

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.