Prove every route. Keep every key.

Control where Kybernao runs, what it may touch, who can authorize an action, how every step is audited, and what, if anything, leaves your boundary.

Runs under the rules you already enforce.

Kybernao connects to your identity provider, writes every action to a ledger on the node, keeps your data inside the boundary, and ships with the documents your review teams need.

APPROVED SCOPEMAPPED TERRAIN

Sign-in and roles

Connect Kybernao to Entra ID or Okta with SAML 2.0 or OIDC. SCIM keeps operators in sync, while roles decide who can view the graph, approve a containment plan, or raise an execution level.

Data residency

The graph, findings, telemetry and models stay on the node unless you allow otherwise. Federation is store-and-forward, scoped to the classes you enable, and reversible with a purge.

Signed ledger

Every run, finding, approval, containment action and login is written to the node first, then streamed to Splunk, Microsoft Sentinel, Elastic or ServiceNow when a link exists.

Legal and vendor review

Request an MSA, DPA, security questionnaire response, or an architecture session on data flow. A named engineer stays with the deployment rather than a ticket queue.

Decide where the node lives.

Run it at the site with optional federation, or fully isolated with no reach-back at all.

Site NODE-RNODE-I

The full platform inside your datacenter, plant, or substation. It operates alone and federates only on the schedule and scope you set.

  • Local cyber-physical graph and data lake
  • Passive industrial and OT visibility on NODE-I
  • Coordination point for a fleet of sites
  • Optional federation, off by default
Isolated (no reach-back)NODE-SNODE-X

The same platform for remote sites, vessels and vehicles, and for contracts where data is forbidden from leaving at all.

  • Red, Sentinel and Guardian run entirely on the node
  • Store-and-forward through degraded links
  • No cloud call in the path of any decision
  • Air-gapped is a supported configuration

Map, test, and defend on one runtime.

Four engines share a single graph, so a finding is a route with a consequence rather than a row in a scanner export, and every node exposes it through a local API.

01 · Atlas

Map the terrain

Identity, cloud, network, controllers and the physical functions they drive resolve into one graph built from your own configuration.

02 · Red and Range

Prove it safely

Validation walks up three execution levels, and nothing reaches a live process until an authorized operator raises the level for a named action.

03 · Sentinel and Guardian

Detect, contain, retest

Detections come from routes that were actually validated. Containment is pre-authorized and a finding closes only when its route fails.

Local API

Findings, assets, plans and audit events from a node API that keeps working when the WAN does not.

Scoped keys and tokens

Automation uses scoped API keys. People use tokens from your identity provider, so a role change there takes effect here.

Your tools

Route validated findings into ServiceNow or Jira, and pull runs and audit events into the dashboards your team maintains.

Every action has an owner and a limit.

Governance is built into the node rather than bolted on. Each control writes its own audit record, and the record stays on site whether or not a link exists.

APPROVED SCOPE SITE BOUNDARY IDENTITYCLOUDNETWORKOT BOUNDARYPROCESS MAPPED REACHABLE ON A VALIDATED ROUTE EMPTY CELLS ARE OUT OF SCOPE
One cell per asset · five lanes · one route proven end to endScope and boundary are yours to set, not ours to assume

Execution levels

Observe reasons over configuration and sends nothing. Twin runs full adversary emulation against a model of your site. Live requires the security owner and the process owner to sign the specific action, with abort conditions set first.

Egress by class

Each data class is its own switch, off until you turn it on, and every object that leaves is written to a signed ledger. Raw capture, controller project files, live tag values and secrets have no path at all.

Scoped roles

Define who can view the terrain graph, approve a plan, raise a level, or export evidence, scoped per site so a plant team sees its own environment.

Keys and hardware root

Secure boot and a hardware root of trust on every node. Data encrypted at rest and in transit, with keys that never leave your boundary.

Retention and purge

Set how long each site keeps its data, and wipe it whenever you need to. The purge is itself recorded in the ledger.

Evidence your auditors can work from.

Framework mapping

Findings, retests and audit events export as a package mapped to the frameworks your programme already reports against.

Retest as evidence

A closed finding is re-run on a schedule, so the record shows the control still enforces rather than that it once did.

Vendor review pack

Contracts, questionnaire answers and a technical walkthrough, ready before your review starts.

NIST SP 800-53Findings tagged to control families
NIST SP 800-82Evidence for OT system profiles
NERC CIPEvidence organized for review
IEC 62443Zones, conduits and findings
Contract packMSA and DPA templates on request
Review questionnaireAnswered by the engineers who built it
Design walkthroughNode placement, egress and trust paths
Named engineerStays with the deployment

Kybernao provides evidence and control mappings. The assessment, and any certification decision, stays with your organization and its auditors.

Findings land where your teams already work.

Validated findings and audit events move into the identity, monitoring and ticketing systems your teams already run.

  • Microsoft Entra IDEntra ID
  • OktaOkta
  • Amazon Web ServicesAWS
  • Microsoft AzureAzure
  • GitHubGitHub
  • KubernetesKubernetes
  • SiemensSiemens
  • SplunkSplunk
  • Sentinel
  • ServiceNowServiceNow
  • PalantirPalantir
  • CrowdStrikeCrowdStrike
  • STIX/TAXIISTIX/TAXII
INPUTS · IDENTITY, CLOUD, CODE, OTOUTPUTS · SIEM, C2, TICKETS, INTEL

Where a breach moves steel, water or power.

Built for operators who answer to a regulator, a board and the people downstream of the plant.

Kybernao Site runs inside substations, generation plants and water systems. It traces routes from enterprise identity through the OT boundary to the physical process, proves them in a twin, and keeps defending the site when the corporate link is gone.

  • Passive OT discovery on NODE-I. No packet a plant engineer would not approve.
  • Routes that end at a breaker, a pump or a cooling loop, with the consequence stated in megawatts.
  • Evidence organized for NERC CIP and IEC 62443 review.

Frequently asked questions

Can Kybernao touch a running process?

Nothing runs against a live process without an authorized operator raising the execution level for a specific action, inside a named window, with abort conditions set in advance. Most findings never need a live proof, and safety-instrumented systems are modelled as boundaries the twin refuses to cross.

Will an agent or scanner touch our control network?

Discovery on the OT side is passive by default on NODE-I. Active work happens against the twin unless you authorize a specific live action. No sweeping scans of control segments.

Does Kybernao need a connection to your cloud?

No. Every node runs the terrain graph, Red, Sentinel, Guardian and Command locally. Federation is optional, store-and-forward, and scoped to the classes you enable.

What leaves our network?

Only the classes you turn on, and every object that leaves is recorded in an egress ledger on the node. Raw OT capture, controller project files, live tag values and credentials have no egress path at all.

Which identity providers and provisioning standards work?

SAML 2.0 and OIDC through Entra ID or Okta, SCIM provisioning from your directory, and roles scoped per site and per action.

Where do the audit events go?

Each event is signed on the node first, then forwarded to Splunk, Microsoft Sentinel, Elastic or ServiceNow. If the link is down the ledger stays complete and drains when it returns.

How does this map to the frameworks our auditors use?

Findings, retests, containment actions and audit events export as an evidence package with control mappings. We provide evidence and mappings; the assessment stays with your organization and its auditors.

How long does a first deployment take?

One node on site, the terrain graph built from your own environment, and the first route walked to its physical consequence is a first-week exercise rather than a quarter.

Watch one route go from graph to proof.

Book a 30-minute session. We build the graph from one site and walk the first route to its physical consequence.

Site design sessions open

Request a Kybernao demo

Tell us a little about your environment. A Kybernao engineer will follow up to arrange a focused walkthrough.

  • 01Focused architecture walkthrough
  • 02Mapped to your mission environment
  • 03Led by a Kybernao engineer
SECURE INTAKE→ENGINEERING
01Contact coordinatesRequired fields
02Mission profileFor a focused session

By submitting, you agree that Kybernao may contact you about this request.