Sign-in and roles
Connect Kybernao to Entra ID or Okta with SAML 2.0 or OIDC. SCIM keeps operators in sync, while roles decide who can view the graph, approve a containment plan, or raise an execution level.
Control where Kybernao runs, what it may touch, who can authorize an action, how every step is audited, and what, if anything, leaves your boundary.
Kybernao connects to your identity provider, writes every action to a ledger on the node, keeps your data inside the boundary, and ships with the documents your review teams need.
Connect Kybernao to Entra ID or Okta with SAML 2.0 or OIDC. SCIM keeps operators in sync, while roles decide who can view the graph, approve a containment plan, or raise an execution level.
The graph, findings, telemetry and models stay on the node unless you allow otherwise. Federation is store-and-forward, scoped to the classes you enable, and reversible with a purge.
Every run, finding, approval, containment action and login is written to the node first, then streamed to Splunk, Microsoft Sentinel, Elastic or ServiceNow when a link exists.
Request an MSA, DPA, security questionnaire response, or an architecture session on data flow. A named engineer stays with the deployment rather than a ticket queue.
Run it at the site with optional federation, or fully isolated with no reach-back at all.
The full platform inside your datacenter, plant, or substation. It operates alone and federates only on the schedule and scope you set.
The same platform for remote sites, vessels and vehicles, and for contracts where data is forbidden from leaving at all.
Four engines share a single graph, so a finding is a route with a consequence rather than a row in a scanner export, and every node exposes it through a local API.
Identity, cloud, network, controllers and the physical functions they drive resolve into one graph built from your own configuration.
Validation walks up three execution levels, and nothing reaches a live process until an authorized operator raises the level for a named action.
Detections come from routes that were actually validated. Containment is pre-authorized and a finding closes only when its route fails.
Findings, assets, plans and audit events from a node API that keeps working when the WAN does not.
Automation uses scoped API keys. People use tokens from your identity provider, so a role change there takes effect here.
Route validated findings into ServiceNow or Jira, and pull runs and audit events into the dashboards your team maintains.
Governance is built into the node rather than bolted on. Each control writes its own audit record, and the record stays on site whether or not a link exists.
Observe reasons over configuration and sends nothing. Twin runs full adversary emulation against a model of your site. Live requires the security owner and the process owner to sign the specific action, with abort conditions set first.
Each data class is its own switch, off until you turn it on, and every object that leaves is written to a signed ledger. Raw capture, controller project files, live tag values and secrets have no path at all.
Define who can view the terrain graph, approve a plan, raise a level, or export evidence, scoped per site so a plant team sees its own environment.
Secure boot and a hardware root of trust on every node. Data encrypted at rest and in transit, with keys that never leave your boundary.
Set how long each site keeps its data, and wipe it whenever you need to. The purge is itself recorded in the ledger.
Findings, retests and audit events export as a package mapped to the frameworks your programme already reports against.
A closed finding is re-run on a schedule, so the record shows the control still enforces rather than that it once did.
Contracts, questionnaire answers and a technical walkthrough, ready before your review starts.
Kybernao provides evidence and control mappings. The assessment, and any certification decision, stays with your organization and its auditors.
Validated findings and audit events move into the identity, monitoring and ticketing systems your teams already run.
CrowdStrikeBuilt for operators who answer to a regulator, a board and the people downstream of the plant.
Kybernao Site runs inside substations, generation plants and water systems. It traces routes from enterprise identity through the OT boundary to the physical process, proves them in a twin, and keeps defending the site when the corporate link is gone.
For process and discrete manufacturing, the terrain graph holds cells, lines, historians and the enterprise systems above them, so a finding is a route to a stoppage rather than a list of unpatched hosts.
Data centers, campuses and transport hubs run a control layer under the compute: building management, CRAC rows, switchgear and UPS strings. Kybernao holds that layer in the same graph as your cloud estate.
Nothing runs against a live process without an authorized operator raising the execution level for a specific action, inside a named window, with abort conditions set in advance. Most findings never need a live proof, and safety-instrumented systems are modelled as boundaries the twin refuses to cross.
Discovery on the OT side is passive by default on NODE-I. Active work happens against the twin unless you authorize a specific live action. No sweeping scans of control segments.
No. Every node runs the terrain graph, Red, Sentinel, Guardian and Command locally. Federation is optional, store-and-forward, and scoped to the classes you enable.
Only the classes you turn on, and every object that leaves is recorded in an egress ledger on the node. Raw OT capture, controller project files, live tag values and credentials have no egress path at all.
SAML 2.0 and OIDC through Entra ID or Okta, SCIM provisioning from your directory, and roles scoped per site and per action.
Each event is signed on the node first, then forwarded to Splunk, Microsoft Sentinel, Elastic or ServiceNow. If the link is down the ledger stays complete and drains when it returns.
Findings, retests, containment actions and audit events export as an evidence package with control mappings. We provide evidence and mappings; the assessment stays with your organization and its auditors.
One node on site, the terrain graph built from your own environment, and the first route walked to its physical consequence is a first-week exercise rather than a quarter.
Book a 30-minute session. We build the graph from one site and walk the first route to its physical consequence.