Passwords gone dark, then rotated
The factory password is replaced and encrypted into a TPM-protected vault — one login per vendor, never in a config file. Where the driver supports it, Skans rotates camera passwords on a schedule: LAPS for cameras.
Video surveillance & physical security
IP cameras, access control, intercoms and recorders live on islanded networks the cloud can't reach — yet NIST 800-171 and CMMC still demand that every one carry an identity, encryption and evidence. Skans becomes that network's root of trust: an X.509 identity for every device, admission for only the gear you trust, then encryption, monitoring and the audit evidence. One appliance, set up by the integrator who mounts the cameras.

Identity for every device
Skans stands up one certificate authority on the appliance and issues an X.509 leaf to every camera, intercom and recorder on the network. A camera can't domain-join or enroll itself, so a per-vendor driver reaches into the device's own management API, installs the cert, and then confirms the camera is actually serving it on the wire — a real check, not an assumption. It's the enclave's own authority, not a bridge to a vendor cloud.

Network access control
With admission turned on, a camera holding a Skans-issued certificate is let onto its port; a device without one is rejected at the switch and never reaches the segment. Cameras that can't speak 802.1X are admitted by MAC and placed on a restricted camera VLAN, gated from the rest of the estate. Enforcement is a Professional-edition capability — and always a deliberate act, never flipped on automatically.

Beyond the certificate
Identity is the anchor, but a compliant camera network needs its passwords, firmware, telemetry and backups looked after too — offline, on one appliance.
The factory password is replaced and encrypted into a TPM-protected vault — one login per vendor, never in a config file. Where the driver supports it, Skans rotates camera passwords on a schedule: LAPS for cameras.
A vetted, SHA-256-hashed firmware repository flags out-of-date cameras and holds vetted images offline — no internet, no vendor portal. Windows recording servers patch on staged rings without WSUS.
Cameras and NVRs push SNMP traps and syslog to the appliance — tamper, link-down, disk-fail, reboot — correlated into a bounded worklist, not a firehose. Offline CVE + MITRE ATT&CK intel matches known camera vulnerabilities without internet.
Recording servers back up through the agent; network-device configs, the credential vault and the directory/CA system-state are held encrypted off the source machine — so a failed box is rebuildable from media, not from nothing. Restore is a documented, admin-run step.
Run by the install crew
No PKI knowledge, no IT team, no CLI. Point Discover at the camera VLAN, press one button, and every camera Skans can identify and authenticate to is enrolled in a single pass — every lane its driver declares, from identity read and certificate issued to telemetry aimed at the appliance. The console reports outcomes, never certificate chains.

Compliance by design
Skans maps its technical checks to NIST 800-171 and CMMC control families from the start — access control, identification, configuration management, risk assessment, system integrity — with an ISO 27001 crosswalk to all 93 Annex A controls. It's honest alignment you can hand an assessor, not a badge.

Talk to us
Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.