Islanded by design
The network can't reach a vendor cloud or a corporate directory — and usually isn't permitted to.
NIST security for isolated camera, IoT, OT & building-automation networks
Skans gives an islanded network of cameras, controllers, and building systems its own root of trust — an identity for every device, admission for only trusted gear, then encryption, patching, backup and the compliance evidence. One appliance, set up by the technician who installs the cameras.
Community Edition is free forever — $0, no credit card, production-ready up to 25 endpoints.
A sealed, air-gapped enclave of cameras, controllers and building systems, each issued its own identity from an on-site root of trust — and your data never crossing the perimeter.
The gap nobody covers
A building full of IP cameras. A campus of BACnet controllers. A plant floor of PLCs. These run on islanded networks stood up by the technician who mounts the hardware — no domain, no IT team, no cloud. Yet NIST 800-171 and CMMC now demand that every device carry an identity, encryption and access control, with evidence to prove it. The tools that do that assume a directory, a security team, and an internet connection — none of which the island has.
The network can't reach a vendor cloud or a corporate directory — and usually isn't permitted to.
A camera, intercom or controller can't domain-join or enroll itself; most ship with a self-signed cert and a default password.
The crew that installs it hangs cameras and pulls cable — they don't run PKI, Active Directory, or RADIUS.
800-171 and CMMC still require identity, encryption, NAC, patching and evidence — for every device on it.
How it works
No PKI knowledge. No IT team. The Setup Wizard asks two or three plain questions, you press one button, and the appliance stands up the whole posture behind it — directory, certificate authority, network admission, device drivers, hardening. The operator never touches AD, Kerberos, or a CLI.
Site name, network, scope. The wizard takes it from there, on golden-config defaults.
The box stands up the directory, CA and RADIUS, then issues identities and pushes certs to every device it finds.
The console reports results, not certificate chains. Renewals, admission and patches keep running on their own.
The console
One console for the whole enclave — every device and its identity, the compliance posture an assessor asks for, and the alerts that actually matter. Air-gapped, role-based, nothing leaving the wire.
One question away
Ask the box in plain language, or read the triage at a glance — what needs you, where compliance stands, whether last night's backup ran. The operator sees results, never certificate chains.

Compliance by design
Live NIST 800-171 posture mapped to control families, with an ISO 27001 crosswalk, a signed evidence pack, reports and an audit trail you hand straight over.

Signal, not noise
Correlated, deduplicated findings — bounded by device count, not raw volume. Rules decide what fires; routing decides where it goes; suppressions are recorded exceptions.

What's in the appliance
One appliance stands up the enclave's root of trust and issues an identity to every device on it — cameras, controllers, building systems, network gear, and Windows/Linux/macOS servers and endpoints (via a lightweight agent) — then handles admission, patching, backup and the compliance evidence. One console, air-gapped by default, nothing of yours leaving the wire.
Find every camera, controller, PLC and switch by multi-protocol discovery — ONVIF, network scan, industrial — auto-classified by class and capability tier.
Stand up a root of trust the enclave owns and issue an X.509 identity to every device. Per-vendor drivers push certs onto the cameras, intercoms and controllers that can't enroll themselves.
802.1X EAP-TLS admits only trusted, cert-bearing devices; MAB and dynamic VLANs for limited gear; legacy OT segmented and gated.
Staged patch rings for Windows without WSUS, plus a vetted, hash-verified firmware repository for cameras and IoT/OT gear — no internet required. Air-gapped estates stay current.
TLS on every device and service, default creds gone, a CIS/STIG baseline applied — the island goes from "not secure" to verified-secure, device by device.
Correlated, deduplicated findings bounded by device count — signal that scales with your fleet, not a firehose. Plus offline CVE, KEV, EPSS, ATT&CK & Sigma intel.
Versioned backups of camera, PLC and network configs, databases, secrets and firmware — encrypted and held off the source machine.
The operator sees outcomes — "cameras encrypted · 2 certs expiring" — never AD or CA internals, and hands the assessor a NIST 800-171 / CMMC evidence pack.
We meet your gear where it is
Mixed-vintage estates are the norm. Skans sorts every device into a tier and applies the strongest control it can support — full identity where possible, a driver-pushed cert where the device is limited, segmentation and a gateway where it's legacy.
Full identity + 802.1X admission + encryption + patching + config backup.
Driver-pushed certificate + config backup + monitoring + a dynamic VLAN.
Segmentation + security gateway + allow-list + monitoring — NIST 800-82 compensating controls.
How it's built
The constraints of a disconnected, regulated network drive the architecture — they aren't worked around after the fact. These are the assumptions Skans was designed on from the first line of code.
Disconnected by default: your identities, keys and data never leave, threat feeds can sync offline, and a severed WAN changes nothing about your protection. The one optional egress — the Skans Update Service — is yours to switch on or leave off.
A field tech can run it — issue a hardware token, approve a device, push a patch ring — without touching a CLI or a specialist.
Your certificate authority, your identities, your data. Nothing about your enclave lives on someone else's server.
Mapped to NIST 800-171 and CMMC controls from the start, so the evidence is in place before the assessor arrives.
Editions
One self-contained appliance, five editions — priced per site by the managed endpoints you protect, never by seats or agents. Community is free forever ($0, no card); paid editions add depth as a site grows. Each includes everything in the one before it.
No directory on site? Skans becomes the enclave's directory, CA and RADIUS.
A Windows fleet joins the Skans domain; GPO pushes trust, policy and patch rings.
A healthy AD already exists? Skans publishes trust through it — it never hijacks your domain.
Compliance by design
Skans maps its capabilities to NIST 800-171 and CMMC control families from the start — no badge-spam, just an honest alignment you can hand an assessor.
The same measured checks also support ISO/IEC 27001:2022 — crosswalked to all 93 Annex A controls via NIST's published OLIR mapping, with a signed supporting-evidence pack and responsibility matrix for your auditor. Skans supplies the technical evidence; organizational, people and physical controls stay yours — it's your ISMS that gets certified, never a product.
The one-command evidence-pack export (NIST 800-171 / CMMC and ISO 27001) is an Enterprise feature.
Questions
Straight answers on phoning home, your existing Active Directory, the standards it meets, and who actually installs and runs it.
By default, no — Skans runs disconnected and never sends your identities, keys or device data out. Security feeds (CVE, KEV, EPSS, MITRE ATT&CK including ICS, Sigma), malware definitions, and agent/product content reach an air-gapped site by offline sync. If you'd rather have automatic online updates, you can switch on the optional Skans Update Service — a single, operator-controlled egress that only pulls signed content down (available on every edition, including free Community); it's off by default and never sends your data anywhere. Offline sneakernet bundles and offline licensing are Enterprise.
Only if you want it to. The Joined profile publishes trust through your AD without taking it over; the Island profile stands up its own directory when you don't have one on site.
It ships meeting the technical controls of NIST 800-171 and CMMC at mandated defaults — FIPS mode, MFA, a CIS/STIG baseline, TLS everywhere — and hands you an evidence pack. Organizational controls stay yours via a control-responsibility matrix, with any gaps tracked in a POA&M.
No — ISO/IEC 27001 certifies your organization's ISMS, not any product. What Skans does is support the audit: its continuously measured technical checks are crosswalked to the 93 Annex A controls of ISO/IEC 27001:2022, and it exports a signed supporting-evidence pack — per-control evidence, a three-way responsibility matrix, and a tamper-evident manifest. Organizational, people and physical controls remain yours.
It's sorted into a capability tier: limited devices get a driver-pushed cert and a dynamic VLAN; legacy devices get segmentation and a security gateway with compensating controls.
The field technician who installs the cameras. The Setup Wizard is two or three plain questions and one button; the PKI, directory and RADIUS run behind it. CLI and PowerShell exist only for experts.
Yes — free forever. Community is $0 with no credit card and is production-ready up to 25 managed endpoints: root of trust, full driver pack, NAC visibility, security feeds (CVE, KEV, EPSS, ATT&CK, Sigma) and malware defs, vault and monitoring. When a site outgrows that band or needs deeper controls, step up to a paid edition — each includes everything below it. See editions →
No — Skans is proprietary, closed-source software, solely owned by its author. What you get isn't source access, it's independence: nothing of yours leaves the enclave, and you own the CA, the identities and the data. The Community Edition is free forever ($0, no credit card) for production use up to 25 managed endpoints; paid editions add depth, scale and support as a site grows.
Who holds the line
The same root of trust, tuned to three worlds that live off the cloud — physical security, building automation, and the plant floor. Need design help beyond a single product? We offer IoT / OT professional services across cameras, BMS and plant floor.
IP cameras, access control, intercoms and recorders on islanded networks — every device given an identity and encrypted, installed by the integrator who mounts them.
HVAC, lighting, elevators and metering from the major BMS vendors — Siemens, Honeywell, Johnson Controls, Tridium — given identity where the device supports it, segmented and gated where it doesn't, without ripping out the install.
PLCs, SCADA, OPC UA and sensors across plant and utility floors — modern gear gets full identity; legacy gets segmentation and a security gateway.
Professional services — broad IoT/OT expertise: architecture, identity, containment, firmware risk, and evidence planning for air-gapped islands. Not limited to the Skans appliance — design the enclave first; product is optional.
Talk to us
Skans is built for the teams running networks the cloud can't reach. If your network can't touch the cloud and still has to pass an audit, email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.
Talk straight to engineering, not a sales funnel.
Appliance briefings when you want the box — or broader IoT/OT architecture and risk help on whatever stack you run.