Solution 02 · See
The room stays offline. The map does not.
On-premises network asset discovery for air-gapped and controlled environments. Nothing phones home. Nothing is optional telemetry.
Discovery
-
How hosts are found
ICMP sweep, TCP SYN host discovery, ARP where the segment allows it, then service detection and OS fingerprinting.
-
What is recorded
IP, hostname, MAC, OUI vendor, OS when identifiable, open ports, services, product and version, first seen, last seen, site, status.
| Identity | IP, hostname, MAC, vendor (OUI) |
|---|---|
| Surface | Open ports, running services, product and version when advertised |
| Placement | Site association, first seen / last seen |
| Governance | Pending, active, or quarantined |
Lifecycle
Pending
Newly seen
Discovered, not yet trusted. An operator reviews the record.
Active
Approved
Known device, in inventory, eligible for scheduled scans.
Quarantined
Denied
Rogue or refused. Visible, not trusted, not quietly dropped.
Scanning & change
-
Profiles
Quick, normal, standard, full, or custom: port ranges, OS and service detection, script toggle, speed from slow to aggressive.
-
Schedule
Daily or weekly, scoped to a site, against IP, CIDR, or range. Enable, disable, cancel a run in flight.
-
Alerts
New or removed assets, new or closed ports, baseline drift, OS change, OUI not on the allow-list, scan failed or completed.
-
Operating picture
Counts, pending queue, active alerts, scan history, topology by status, PDF reports, audit log, roles: Admin, Analyst, Viewer.
Accuracy follows the network: firewalls, host response, and whether ports are reachable. This is active scanning, not a passive tap. It does not patch hosts, ship agents, or feed a SIEM — those are later work, not this product.
On-premises
If the network cannot leave the building, neither should the inventory.
Tell us about the environment. We will not send you a cloud dashboard.