Video surveillance & physical security

Every camera gets an identity. Nothing leaves the wire.

IP cameras, access control, intercoms and recorders live on islanded networks the cloud can't reach — yet NIST 800-171 and CMMC still demand that every one carry an identity, encryption and evidence. Skans becomes that network's root of trust: an X.509 identity for every device, admission for only the gear you trust, then encryption, monitoring and the audit evidence. One appliance, set up by the integrator who mounts the cameras.

Skans console · Devices
The Skans device inventory filtered to cameras — each with a certificate issued by the enclave CA, its capability tier, and its enrollment lane (ONVIF / vendor driver / agent).

Identity for every device

A certificate on every camera — from a CA you own.

Skans stands up one certificate authority on the appliance and issues an X.509 leaf to every camera, intercom and recorder on the network. A camera can't domain-join or enroll itself, so a per-vendor driver reaches into the device's own management API, installs the cert, and then confirms the camera is actually serving it on the wire — a real check, not an assumption. It's the enclave's own authority, not a bridge to a vendor cloud.

  • Driver-pushed certs — the driver issues, installs and binds the leaf, then verifies the camera is serving the new certificate serial before it reports success.
  • Proven on real hardware — Axis, Hanwha and Bosch cameras and 2N intercoms are validated on physical devices, alongside a hardware-proven generic ONVIF driver for ONVIF-conformant cameras.
  • Extensible to any vendor — the signed, versioned driver pack covers 100+ vendors, including Uniview, Dahua, Hikvision, i-PRO, Avigilon, LenelS2 and Mercury; new vendors ship in the pack without upgrading the appliance.
  • Renewal runs itself — expiries are tracked and re-issued before they lapse; the operator sees "2 certs expiring — auto-renewing," never a certificate chain.
Skans console · Devices
The Skans device inventory — cameras with certificate status, capability tier, and enrollment lane, each traceable to the enclave's own CA.

Network access control

Only the cameras you trust reach the wire.

With admission turned on, a camera holding a Skans-issued certificate is let onto its port; a device without one is rejected at the switch and never reaches the segment. Cameras that can't speak 802.1X are admitted by MAC and placed on a restricted camera VLAN, gated from the rest of the estate. Enforcement is a Professional-edition capability — and always a deliberate act, never flipped on automatically.

  • 802.1X EAP-TLS — identity-gated admission over the appliance's native Windows NPS (RADIUS); a camera swapped for a rogue device fails authentication and gets no address.
  • MAB + dynamic VLANs — limited cameras are admitted by MAC and placed on the right segment by RADIUS-assigned VLAN.
  • Legacy segmented and gated — an old recorder that can't hold a cert gets a segment, an allow-list and monitoring instead of open access.
  • Staged, never sprung — turning admission on can black out a camera fleet the instant it hits live ports, so Skans keeps it a separate, opt-in step you stage first, then enforce.
Skans console · NOC
The Skans NOC wall — fleet health, devices by capability tier, certificates, and a RADIUS / NPS Serving tile showing admission is live.

Beyond the certificate

The rest of the posture, handled by the same box.

Identity is the anchor, but a compliant camera network needs its passwords, firmware, telemetry and backups looked after too — offline, on one appliance.

Passwords gone dark, then rotated

The factory password is replaced and encrypted into a TPM-protected vault — one login per vendor, never in a config file. Where the driver supports it, Skans rotates camera passwords on a schedule: LAPS for cameras.

Firmware & patch, offline

A vetted, SHA-256-hashed firmware repository flags out-of-date cameras and holds vetted images offline — no internet, no vendor portal. Windows recording servers patch on staged rings without WSUS.

Tamper & health in view

Cameras and NVRs push SNMP traps and syslog to the appliance — tamper, link-down, disk-fail, reboot — correlated into a bounded worklist, not a firehose. Offline CVE + MITRE ATT&CK intel matches known camera vulnerabilities without internet.

Backups held off the box

Recording servers back up through the agent; network-device configs, the credential vault and the directory/CA system-state are held encrypted off the source machine — so a failed box is rebuildable from media, not from nothing. Restore is a documented, admin-run step.

Run by the install crew

Set up by the technician who mounts the cameras.

No PKI knowledge, no IT team, no CLI. Point Discover at the camera VLAN, press one button, and every camera Skans can identify and authenticate to is enrolled in a single pass — every lane its driver declares, from identity read and certificate issued to telemetry aimed at the appliance. The console reports outcomes, never certificate chains.

  • Scan a subnet, secure everything — one button runs scan → identify → secure across the range, with a per-device lane scoreboard for what ran.
  • One credential per vendor — a site has one camera password, not two hundred; store it once and the sweep never stops to ask again.
  • Proof, not guesswork — an ONVIF string only hints which driver to try; the vendor is confirmed by a driver actually talking the device's protocol. Anything it can't confirm is reported and skipped, never faked.
  • Read-only by default — the automatic pass only reads or adds a telemetry destination; it never rotates a password or enforces NAC, so it can't take a camera off the network.
Skans console · Home
The Skans console home — an ask-or-command bar over a correlated worklist of what needs attention, where compliance stands, and whether last night's backup ran.

Compliance by design

The evidence an assessor asks for — already in place.

Skans maps its technical checks to NIST 800-171 and CMMC control families from the start — access control, identification, configuration management, risk assessment, system integrity — with an ISO 27001 crosswalk to all 93 Annex A controls. It's honest alignment you can hand an assessor, not a badge.

  • Posture by control family — a live view of where the camera estate stands against AC, IA, CM, RA and SC, updated as devices run.
  • Evidence you hand over — a signed, per-control evidence pack built from live state, with a tamper-evident manifest and a responsibility matrix; the evidence-pack export is a Professional capability.
  • Honest scope — Skans supplies the technical evidence; organizational, people and physical controls stay yours, with any gaps tracked in a POA&M. Your ISMS gets certified — never a product.
  • Nothing leaves the wire — evidence is generated and proven offline; the one optional egress, the operator-controlled Skans Update Service, only pulls signed content in and never sends your data out.
Skans console · Compliance
The Skans compliance view — a NIST 800-171 posture ring and per-control-family cards for AC, AU, CM, CP, IA, RA and SC.

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.