One root of trust
Your CA, your identities, your keys — issued and rotated on-box for every building system, never parked on a vendor cloud.
Building automation & facilities
HVAC, lighting, elevators, metering and the BMS head-ends from Siemens Desigo, Honeywell, Johnson Controls Metasys and Tridium Niagara run on islanded networks a trades integrator stood up — no directory, no security team, no internet. Skans becomes that enclave's root of trust: an identity for every controller that can hold one, segmentation and read-only monitoring for the gear that can't, and the compliance evidence to prove it. One appliance, set up by the technician who commissions the building.

Identity for every controller
Skans stands up an on-premises certificate authority the enclave owns, then issues an X.509 identity to every controller, head-end and field panel that can hold one. Per-vendor drivers push and bind the certificate onto gear that can't domain-join or enroll itself — Siemens Desigo, Honeywell, Johnson Controls Metasys, Tridium Niagara, Distech Controls, Belimo and the S7 controllers behind them. OPC UA servers get spec-correct application-instance certificates instead of the permanent, hand-made self-signed ones they usually ship with.

Meet the plant where it is
Mixed-vintage estates are the norm in a building — a new Desigo head-end beside a decade-old BACnet MS/TP trunk and a raw-Modbus meter. Skans sorts every device into a capability tier and applies the strongest control it can support: full identity where possible, a driver-pushed cert and a dynamic VLAN where the device is limited, and segmentation with a security gateway where it's legacy. That's NIST 800-82 compensating controls, not a rip-and-replace.

Why facilities teams pick Skans
Islanded by design, commissioned by trades, audited like IT. Skans fits that reality instead of fighting it.
Your CA, your identities, your keys — issued and rotated on-box for every building system, never parked on a vendor cloud.
Legacy controllers are segmented, allow-listed and read only. Identity probes ask 'who are you, are you running?' — they never write to the device.
Disconnected out of the box. Threat feeds, firmware and patches sync offline; a severed WAN changes nothing about your protection.
The Setup Wizard is a few plain questions and one button. The operator sees outcomes — 'controllers encrypted · 2 certs expiring' — never PKI internals.
Patch, firmware & backup
Air-gapped estates fall behind because there's no clean way to get signed content in. Skans keeps a vetted, hash-verified firmware repository for controllers and IoT gear, and staged patch rings for the Windows head-ends and workstations that run the BMS — no internet, no WSUS. Configs, secrets and firmware are versioned and held off the source machine, so a bricked panel or a bad commissioning change is recoverable.

Evidence, not badges
Skans maps its technical controls to NIST 800-171 and CMMC control families from the start, with an ISO 27001 crosswalk and read-only OT guidance from NIST 800-82 for the gear that can't be hardened directly. It hands the assessor a signed, per-control evidence pack — not a compliance badge, and never a claim that a product made you compliant.

Talk to us
Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.