Critical infrastructure security, out of the box.
Admin logins that can't be phished, backups ransomware can't touch, and one searchable record of what happened — for water, energy, and utility operators. Hardened appliances that run on your own network, with no cloud subscription and no server left for your team to lock down.
Purpose-built for OT environments of any scale.
Water utilities, power generators & distributors, transport networks, and the contractors who run them. Whether you are a small team managing a regional plant or an enterprise utility scaling security across dozens of remote substations, our appliances deliver an instant, audit-ready baseline.
No custom OS builds to secure, patch, or maintain.
Four gaps hiding in plain sight on your network.
“We’ll fix security in a quiet week.”
(There isn’t one.)
Patching, documentation, and compliance uplift constantly lose to keeping the plant running.Whatever isn’t urgent gets pushed.
When an auditor asks how privileged access is controlled, verbal assurance won’t pass—you need evidence you can produce on demand.
Four appliances. One hardened baseline.
LI-Core
One set of credentials for every system on your network, with phish-resistant MFA, internal DNS, and auto-renewing certificates.
- Hardware key or app-based MFA (TOTP/WebAuthn) enforced on Windows workstations and admin logins.
- Internal DNS, so every device on the network answers to a name instead of an IP address
- Built-in Certificate Authority (PKI/ACME) that automatically issues trusted certs. Eliminating browser security warnings on internal web interfaces.
LI-Vault
A hardened, self-hosted secrets vault for OT environments—running entirely on your local network without cloud dependencies.
- Individual, named accounts for every engineer, eliminating shared vault logins.
- Checkout auditing for legacy devices, tying every switch or PLC access event to a real person.
- Works 100% offline in air-gapped networks with zero phoning-home.
LI-Store
Time-locked, immutable backup storage for your critical OT assets—protecting configuration dumps, historian databases, and workstation images from ransomware and administrative deletion.
- Policy-enforced WORM retention: Once written, backup files are locked against modification, encryption, or deletion until their retention date expires.
- Protection against compromised credentials: Built so that standard admin accounts and network backup clients cannot alter or purge existing retention holds.
- 100% On-site & Air-gapped: Local backup recovery with zero cloud dependencies, external APIs, or recurring SaaS fees.
LI-Scope
A lightweight OT SIEM and observability engine in a single appliance. Combines security event logging with operational metrics—giving you complete network visibility without the cost or complexity of enterprise SIEMs.
- Unified SIEM logging: Aggregates Syslog, SNMP traps, and Windows Event Logs across switches, PLCs, firewalls, and engineering stations into one searchable record.
- Integrated OT health metrics: Tracks live hardware health—disk usage, CPU temperature, link status, reachability, and uptime—alongside security events in a single dashboard.
- Actionable security alerts: Distills noisy event streams into immediate, plain-English security and operational warnings without requiring a dedicated SOC analyst.
Stands alone. Compounds together.
Deploy a single appliance to solve a specific gap, or combine all four to form an integrated security baseline. LI-Core provides identity for the stack, while LI-Scope centralises logs and metrics across every node.
How it fits together
Hover or tap an appliance to explore how it connects with your network.
LI-Core
Identity, DNS & Certificates
LI-Vault
Secrets & Password Vault
LI-Store
Immutable Backup
LI-Scope
Logging & Alerting
Workstations & servers
Network & OT devices
Hover or tap an appliance node to inspect its roles and integrations.
LI-CoreIdentity, DNS & Certificates
Provides MFA / identity to LI-Vault, LI-Store, and LI-Scope, and to your workstations, servers, and network devices. Streams its own logs to LI-Scope.
LI-VaultSecrets & Password Vault
Authenticates against LI-Core, streams logs to LI-Scope, and holds the passwords for devices too old or too limited to log in through LI-Core themselves.
LI-StoreImmutable Backup
Authenticates against LI-Core, streams logs to LI-Scope, and takes backup jobs from your environment.
LI-ScopeLogging & Alerting
Receives logs and events from LI-Core, LI-Vault, and LI-Store, plus logs and metrics from your workstations, servers, and network devices.
Workstations & servers
Your engineers’ and operators’ workstations, plus any servers that run on-premises. They log in through LI-Core, with the extra login step it enforces, and send their logs and health metrics to LI-Scope.
Network & OT devices
Network devices, switches, PLCs, UPSes and other OT devices. They send logs to LI-Scope, save backups to LI-Store, log in through LI-Core where they support it, and keep their passwords in LI-Vault.
Four virtual machines you run on your own hardware.
Nothing arrives in a crate. Each appliance is an image you run on a server you already own and already have a support contract for — which is deliberate, because it means your spares, your replacement times and your hardware vendor don't change just because you bought security software.
Distributed workloads, redundant authentication.
You don't need a complex server cluster for a resilient setup. A standard deployment splits the four appliances across two physical hypervisor hosts — giving LI-Core high availability for logins, while keeping backup and logging workloads on separate disks.
How a patch reaches a site that has no connection.
An appliance that can't reach the internet still has to be patched, so the update travels as a file you carry in — never as something the appliance goes and fetches.
- Download the signed update from the customer portal, on any machine with an internet connection.
- Put it through whatever scanning and verification your site requires before anything crosses into the isolated network — it’s a file, so it goes through the process you already have.
- Upload it to the appliance’s own web page from inside that network, or carry it in on a USB drive. The appliance checks the signature itself and refuses anything that doesn’t match.
What an auditor asks for, against what you can show them
Whether you are meeting SOCI CIRMP requirements, aligning to AESCSF or NIST CSF, or reporting against the Essential Eight—compliance comes down to audit evidence. Here is what each appliance generates.
Prefer us to handle deployment and updates?
Most utilities self-administer their appliances on-site. But if your team lacks the bandwidth for routine maintenance, we can deploy the stack and handle monthly patching, health checks, and reporting for you, with the same hardened baseline, same local hardware, and complete customer control over outbound access.
Why we build appliances, not software packages.
Traditional software tools leave you responsible for securing, patching, and maintaining the underlying server—a task lean OT teams rarely have bandwidth for. We ship sealed, pre-hardened virtual appliances updated as a single unit. You get an instant, audit-ready baseline with one change request, one patch window, and zero host OS builds to manage.
Ready to harden your OT environment?
Looking for our OEE platform? Visit the OEE platform →