Kybernao runs on a node inside your boundary: a rack in a datacenter, a DIN rail in a substation, a pack on a patrol. Every node carries the full platform, so nothing depends on a link to work.
Choose by where the mission lives. The software, the controls and the evidence are identical.
Kybernao Site NODE-RNODE-I
For datacenters, plants and substations with stable power and space. One node can coordinate a fleet of others across a region.
Local terrain graph and evidence store
Passive OT visibility on NODE-I
Coordinates a fleet of site and edge nodes
Federation to peers or Kybernao Cloud, off until you enable it
Kybernao Edge NODE-SNODE-X
For vehicles, vessels, forward teams and any contract where data is forbidden from leaving. The same platform, sized to carry.
Red, Sentinel and Guardian run on the node
Built for denied, degraded and intermittent links
Store-and-forward when a link appears
Air-gapped operation is fully supported
Federation without a center.
Nodes share selected state through FedSpace, peer to peer. Kybernao Cloud can join as one more peer, hosted by us, and it is off by default. No node needs another node, or the cloud, to keep defending its own site.
Selected state only
You choose which data classes a node may share, and with which peers. The rest never leaves.
Store and forward
A node that loses its link queues updates and drains them in order when the link returns.
Sovereign by default
Each node keeps its own keys, ledger and policy. A compromised peer cannot command another node.
When the link goes dark.
Disconnected operation is a normal mode, not a failure state. This is what a node does after the link drops.
T+0sLink lost
The node notes the loss in its ledger and switches federation to queueing. Nothing else changes.
T+0sNothing fails over
Sentinel was already running on the node, watching the routes Red has proven. There is no cloud to lose.
On detectionContainment runs locally
Guardian applies pre-approved containment inside the limits your operators set. No approval is waiting on a link.
Link returnsQueues drain in order
Selected state and audit events forward to peers and your SIEM, signed and in sequence, with nothing lost.
Four form factors.
Each node runs the complete platform. Pick the one that fits the place it will live.
NODE-S
Tactical
Backpack class
Runs on battery or vehicle power for squads and forward teams.
Edge deployments
Battery or vehicle power
NODE-R
Rack
1U or 2U rack unit
For datacenters and enterprise sites, and the coordinator for a fleet of nodes.
Site deployments
Fleet coordination
NODE-I
Industrial
DIN-rail and fanless
Passive by default, for plants, substations and process environments.
Site deployments
Passive OT discovery
NODE-X
Expeditionary
Sealed and shock-rated
For austere sites where power is intermittent and support is days away.
Edge deployments
Harsh environments
From the first node to a fleet.
Most teams start with one site, prove the loop on their own routes, then add nodes one environment at a time.
Day 1Install one node
Rack it or rail it, connect identity and a span port, and start passive discovery.
Week 1See the graph
Your mission engineer walks the first terrain graph and the routes Atlas resolved.
Month 1Prove and contain
Red replays routes in the twin, Guardian containment is approved, and the first retests close findings.
AfterAdd sites and edges
New nodes join the fleet with the same policy, and federation is turned on only where you want it.
Frequently asked questions
Does a node need an internet connection?
No. Every node runs the complete platform locally. A connection is only used for federation, SIEM forwarding and updates, and each of those is optional.
What is Kybernao Cloud?
An optional hosted peer. A site can federate selected state to it the same way it would to another node, for fleet views across regions. It is off by default, and a node never depends on it to make a decision.
How are updates installed on an air-gapped node?
We provide signed update bundles that can be carried in on approved media. The node verifies the signature before it installs anything.
Can we run Kybernao on our own hardware or in our own cloud?
Talk to us about your environment. The NODE form factors are the supported path, and we can review other options with your mission engineer.
How many nodes does one site need?
Most sites start with one. Larger plants add a NODE-I per process area, and a NODE-R can coordinate them all.
What happens to data when we retire a node?
You can purge it on demand. The purge is recorded in the ledger, and the node's keys are revoked so it can no longer join the fleet.
Plan your first node with an engineer.
We will size the hardware, map the network touch points and agree what, if anything, leaves the site.