AESCSF · NIST CSF · Essential 8 · SOCI Act

Critical infrastructure security, out of the box.

Admin logins that can't be phished, backups ransomware can't touch, and one searchable record of what happened — for water, energy, and utility operators. Hardened appliances that run on your own network, with no cloud subscription and no server left for your team to lock down.

LI-CoreIDENTITY, DNS & CERTIFICATESLI-VaultSECRETS & PASSWORD VAULTLI-StoreIMMUTABLE BACKUPLI-ScopeLOGGING & ALERTING
Who this is for

Purpose-built for OT environments of any scale.

Water utilities, power generators & distributors, transport networks, and the contractors who run them. Whether you are a small team managing a regional plant or an enterprise utility scaling security across dozens of remote substations, our appliances deliver an instant, audit-ready baseline.

No custom OS builds to secure, patch, or maintain.

What's at stake

Four gaps hiding in plain sight on your network.

01 // ACCESS
The login everyone knows
One shared account on the engineering workstation, a password unchanged since the last integrator visit, and no way to say afterwards who made the change.
02 // STORAGE
A backup on a writable share
If your last-resort copy sits somewhere an administrator account can reach and delete, then whoever takes that account decides whether you still have a backup.
03 // AUDIT
Logs that die with the machine
When you need to reconstruct what happened, the record is sitting on the box that was compromised — assuming anything was being kept at all.
04 // TELEMETRY
Sites nobody visits for months
Remote pump stations and substations run unattended. Failed logins, new accounts and configuration changes all happen with nobody watching.
What it costs you

“We’ll fix security in a quiet week.”

(There isn’t one.)

Patching, documentation, and compliance uplift constantly lose to keeping the plant running.Whatever isn’t urgent gets pushed.

When an auditor asks how privileged access is controlled, verbal assurance won’t pass—you need evidence you can produce on demand.

Four appliances. One hardened baseline.

LI-CoreIdentities
j.alvarezOperatorMFA Enforced
m.chenAdministratorMFA Enforced
t.nguyenObserverMFA Enrolled
r.patelOperatorMFA Pending
Identity, DNS & CertificatesFoundation

LI-Core

One set of credentials for every system on your network, with phish-resistant MFA, internal DNS, and auto-renewing certificates.

  • Hardware key or app-based MFA (TOTP/WebAuthn) enforced on Windows workstations and admin logins.
  • Internal DNS, so every device on the network answers to a name instead of an IP address
  • Built-in Certificate Authority (PKI/ACME) that automatically issues trusted certs. Eliminating browser security warnings on internal web interfaces.
LI-VaultCredentials
network-switch-01••••••••
router-admin••••••••
scada-historian••••••••
plant-vpn••••••••
Secrets & Password Vault

LI-Vault

A hardened, self-hosted secrets vault for OT environments—running entirely on your local network without cloud dependencies.

  • Individual, named accounts for every engineer, eliminating shared vault logins.
  • Checkout auditing for legacy devices, tying every switch or PLC access event to a real person.
  • Works 100% offline in air-gapped networks with zero phoning-home.
LI-StoreBackup jobs
plc-config-backup
historian-db
switch-configs
engineering-workstation
Immutable Backup

LI-Store

Time-locked, immutable backup storage for your critical OT assets—protecting configuration dumps, historian databases, and workstation images from ransomware and administrative deletion.

  • Policy-enforced WORM retention: Once written, backup files are locked against modification, encryption, or deletion until their retention date expires.
  • Protection against compromised credentials: Built so that standard admin accounts and network backup clients cannot alter or purge existing retention holds.
  • 100% On-site & Air-gapped: Local backup recovery with zero cloud dependencies, external APIs, or recurring SaaS fees.
LI-ScopeEvent stream
Auth failure threshold exceeded
Switch port flapping detected
Firmware update completed
New device joined network
Logging & Alerting

LI-Scope

A lightweight OT SIEM and observability engine in a single appliance. Combines security event logging with operational metrics—giving you complete network visibility without the cost or complexity of enterprise SIEMs.

  • Unified SIEM logging: Aggregates Syslog, SNMP traps, and Windows Event Logs across switches, PLCs, firewalls, and engineering stations into one searchable record.
  • Integrated OT health metrics: Tracks live hardware health—disk usage, CPU temperature, link status, reachability, and uptime—alongside security events in a single dashboard.
  • Actionable security alerts: Distills noisy event streams into immediate, plain-English security and operational warnings without requiring a dedicated SOC analyst.

Stands alone. Compounds together.

Deploy a single appliance to solve a specific gap, or combine all four to form an integrated security baseline. LI-Core provides identity for the stack, while LI-Scope centralises logs and metrics across every node.

MFA / identityMFA / identity & backupsIdentity, logs & metricsLogs & metricsLogs & metricsBackupsBackupsLogin + MFALogs & metricsSecretsBackup jobsLogin + MFALogs & metricsSecretsBackups

How it fits together

Hover or tap an appliance to explore how it connects with your network.

  • LI-Core

    Identity, DNS & Certificates

  • LI-Vault

    Secrets & Password Vault

  • LI-Store

    Immutable Backup

  • LI-Scope

    Logging & Alerting

  • Workstations & servers

  • Network & OT devices

Hover or tap an appliance node to inspect its roles and integrations.

What you get

Four virtual machines you run on your own hardware.

Nothing arrives in a crate. Each appliance is an image you run on a server you already own and already have a support contract for — which is deliberate, because it means your spares, your replacement times and your hardware vendor don't change just because you bought security software.

Your existing hardware & contracts
We don’t sell proprietary boxes. Each appliance is a virtual machine running on your existing servers—keeping your hardware vendor contracts, spare pools, and SLA response times unchanged.
Dedicated lightweight VMs
Each appliance runs on its own isolated VM rather than sharing a host OS.
Hypervisor compatibility
Images are delivered for standard OT hypervisors, with Hyper-V as the primary default for Windows-centric control networks. We confirm image compatibility for your stack prior to deployment.
Zero production downtime to stand up
Appliances deploy alongside your network without inline disruption. You stand up the VMs first, then progressively point switches, workstations, and DNS to them at your own pace.
Self-administered or fully managed
Most sites self-administer locally. We also offer turnkey installation and an optional managed tier for routine patching, health checks, and reporting over customer-controlled access.
No internet dependencies
No outbound connectivity required at install or during operation. None of the four appliances phone home, and patch releases arrive as offline signed update files.
Automatic power-loss recovery
Appliances recover automatically alongside host server boot policies. For zero-downtime authentication, LI-Core runs as a dual-appliance High Availability pair.
Redundancy & offline fallback
If hardware fails, replacement follows your standard server RMA process. For mobile engineering laptops taken off-network, local MFA policies maintain secure offline access.
Typical two-server deployment

Distributed workloads, redundant authentication.

You don't need a complex server cluster for a resilient setup. A standard deployment splits the four appliances across two physical hypervisor hosts — giving LI-Core high availability for logins, while keeping backup and logging workloads on separate disks.

Server A
LI-Core
Primary auth / MFA
LI-Vault
Credential checkout
LI-Store
Immutable backups
Server B
LI-Core
Secondary auth / MFA
LI-Scope
OT SIEM & telemetry
High availability for auth (LI-Core)
LI-Core is the only appliance that runs as a dual-instance pair. If Server A drops offline for maintenance or a hardware fault, Server B carries MFA logins on its own, so plant access is never interrupted.
Balanced workload distribution
The single-instance appliances split across both hosts too — LI-Scope’s continuous log ingestion on Server B, LI-Vault and LI-Store’s writes on Server A — so neither competes with the other for the same disk.
Simple hypervisor setup
No multi-node cluster or shared SAN storage to configure — just two standalone hosts you already own, running Hyper-V, Proxmox, or VMware ESXi.
Updates without internet

How a patch reaches a site that has no connection.

An appliance that can't reach the internet still has to be patched, so the update travels as a file you carry in — never as something the appliance goes and fetches.

  1. Download the signed update from the customer portal, on any machine with an internet connection.
  2. Put it through whatever scanning and verification your site requires before anything crosses into the isolated network — it’s a file, so it goes through the process you already have.
  3. Upload it to the appliance’s own web page from inside that network, or carry it in on a USB drive. The appliance checks the signature itself and refuses anything that doesn’t match.

What an auditor asks for, against what you can show them

Whether you are meeting SOCI CIRMP requirements, aligning to AESCSF or NIST CSF, or reporting against the Essential Eight—compliance comes down to audit evidence. Here is what each appliance generates.

What an auditor asks to seeWhat the appliance produces
Who has admin access, and how it’s authenticated
A per-login record of which account authenticated, with which factor, and when
LI-Core
Who retrieved a shared device credential, and when
A named-account access log for every credential checkout — even when the device itself only has one shared account
LI-Vault
A record of what happened, across every device
Centrally aggregated, searchable logs from every device that ships them
LI-Scope
Proof a backup exists and hasn’t been altered since
Backup objects locked under retention, with the lock and expiry recorded on the object itself
LI-Store
Current software inventory and vulnerability exposure
A parts list and vulnerability scan for every appliance image, refreshed and published to your portal
Every appliance — LI-Core · LI-Vault · LI-Store · LI-Scope
A second way to buy

Prefer us to handle deployment and updates?

Most utilities self-administer their appliances on-site. But if your team lacks the bandwidth for routine maintenance, we can deploy the stack and handle monthly patching, health checks, and reporting for you, with the same hardened baseline, same local hardware, and complete customer control over outbound access.

See the managed service →

Why we build appliances, not software packages.

Traditional software tools leave you responsible for securing, patching, and maintaining the underlying server—a task lean OT teams rarely have bandwidth for. We ship sealed, pre-hardened virtual appliances updated as a single unit. You get an instant, audit-ready baseline with one change request, one patch window, and zero host OS builds to manage.

Ready to harden your OT environment?

Looking for our OEE platform? Visit the OEE platform →

© Copyright 2026 Line Interpreter · ABN 45 523 604 790