Frequently asked questions
What are the utility nodes?
Four appliances that run on your own network: LI-Core (one set of credentials for every system, with a second login step that can't be phished, plus internal DNS and certificates), LI-Vault (a secrets and password vault), LI-Store (backup storage that can't be deleted or encrypted once written), and LI-Scope (log collection, search and alerting). Each is a self-contained hardened appliance rather than software you install and then have to secure yourself.
Do I have to buy all four?
No. Each appliance is useful on its own, and each ships with its own login and MFA so it's secure on day one without the others. LI-Core is the usual starting point: it provides the logins, names and certificates the other three authenticate against, and it benefits every other device on the network whether or not you add the rest.
Does this replace our existing Active Directory?
No. LI-Core steps up whatever identity you already run — your existing Active Directory, or local accounts — by putting phishing-resistant multi-factor authentication in front of privileged logins, including Windows workstations. There is no migration of users out of what you have today.
Does any of this require changes to our control network?
They're separate appliances that sit on your network. They don't change how your PLCs, HMIs or SCADA systems are configured, and nothing needs to be installed onto control equipment. The extra login step applies to the logins you choose to put behind it, not to the machines themselves. Exactly where the appliances sit relative to your existing segmentation is site-specific, and it's one of the first things we work through with you.
What hardware is required at my site?
Your own server, running your own hypervisor. We don't sell hardware — each appliance is a virtual machine image, on its own VM, so the machine stays on the vendor contract you already have and spares and replacement times don't change.
LI-Vault and LI-Store start at 2 CPU cores and 4 GB of RAM; LI-Core and LI-Scope at 4 cores and 8 GB. Each needs a 32 GB system disk, and LI-Store and LI-Scope each take a separate data disk sized to how much you keep and for how long. Per-appliance figures are on each appliance page.
LI-Vault and LI-Store start at 2 CPU cores and 4 GB of RAM; LI-Core and LI-Scope at 4 cores and 8 GB. Each needs a 32 GB system disk, and LI-Store and LI-Scope each take a separate data disk sized to how much you keep and for how long. Per-appliance figures are on each appliance page.
Does installing them need an outage or a change window?
Standing the appliances up doesn't — they go up beside your network rather than inside it, so nothing has to stop. The time goes into connecting things to them: adding the extra login step on Windows workstations, pointing network gear at it, moving devices onto internal DNS, issuing certificates, and installing our root certificate on the machines that should trust it. How much of that you do, and how long it takes, depends on your architecture and how far you want to go — which is what we scope with you.
Do you install it, or do we?
Most customers install it themselves. We offer a paid installation if you'd rather we did it, and a managed option where we handle patching, health checks and a monthly report — that last one is the only case where any connection to us exists at all, and it's one you set up and control.
What happens on power loss, or if an appliance fails?
They come back the way your server does — whatever your hypervisor is set to do when power returns is what happens, and everything picks up from there. The hardware is yours, so replacement runs through your existing vendor, and we'd suggest keeping a spare. LI-Core is the one worth running as a pair of appliances so losing one doesn't stop logins; Windows workstations can also be set to accept a local login, still with the second step enforced, which is what lets an engineer take a laptop off the network and still get into it.
Do the appliances need internet access?
No — not at install, and not afterwards. Every appliance runs fully offline on a network with no internet access at all, none depends on a cloud service, and none of them phones home. Updates arrive as a single signed bundle per appliance: you download it on a connected machine, put it through your own scanning, then upload it to the appliance's own web page from inside the isolated network or carry it in on a USB drive. The appliance checks the signature before it applies anything.
Where is my data stored?
On your own network, on the appliances themselves. Logs, secrets and backups stay on-site. There is no cloud tenancy behind any of the four, and nothing is sent to us as a condition of them running.
Who is behind LineInterpreter, and how big are you?
One engineer, in Australia. LineInterpreter is a one-person company: Alex Visser, PhD, a control systems, OT and software engineer with over a decade in industrial manufacturing. He writes the code, runs the demos and answers the support email.
That means support isn't a queue that eventually reaches someone technical — there is nobody standing between you and the person who can change the software. What that means for the appliances if the company stops existing is covered below, under “What happens to our appliances if you go out of business?”
That means support isn't a queue that eventually reaches someone technical — there is nobody standing between you and the person who can change the software. What that means for the appliances if the company stops existing is covered below, under “What happens to our appliances if you go out of business?”
Can we speak to a reference customer?
No — no utility node has been deployed at a customer site yet, so there is no reference to call and no logo to show you. We're not going to dress up a pilot or a friendly contact as something it isn't.
What we offer instead is a free architecture session: we work through your network, where each appliance would sit, what it would connect to, what it would cost you in effort, and which of the four are worth starting with — including the case for starting with none. You leave with a diagram of your own site and an honest scope you can circulate internally, whether or not you buy anything.
What we offer instead is a free architecture session: we work through your network, where each appliance would sit, what it would connect to, what it would cost you in effort, and which of the four are worth starting with — including the case for starting with none. You leave with a diagram of your own site and an honest scope you can circulate internally, whether or not you buy anything.
What happens to our appliances if you go out of business?
They keep working. There is no licence server to check in with, no dongle and no kill switch — if your subscription lapses, or we're not here, nothing we control can stop an appliance you already have from running. You'd be left with an operational system that stops receiving upgrades, patches and support, which is bad, but is a position you can plan a migration from rather than a licence that locks you out on a date.
Three specifics worth acting on now rather than discovering later. The customer portal is ours — it holds the update bundles, each release's parts list and the daily scan results — so keep a local copy of every bundle you install and its parts list. The emergency recovery key is currently held by us, so recovering a locked-out appliance today means contacting us; letting you hold your own key and remove ours is being built. And there is no source escrow arrangement in place today — if that's a procurement requirement on your side, raise it early.
Three specifics worth acting on now rather than discovering later. The customer portal is ours — it holds the update bundles, each release's parts list and the daily scan results — so keep a local copy of every bundle you install and its parts list. The emergency recovery key is currently held by us, so recovering a locked-out appliance today means contacting us; letting you hold your own key and remove ours is being built. And there is no source escrow arrangement in place today — if that's a procurement requirement on your side, raise it early.
Can LI-Store be a target for the backup software we already run?
LI-Store presents standard object storage with object-lock, so anything on your network that can write to it can use it as a backup target — it isn't limited to backing up the other appliances. We don't claim certification with specific backup products; if you tell us what you run, we'll tell you honestly whether we've seen it working.
Does LI-Scope ingest logs from our existing switches, firewalls and servers?
LI-Scope ingests from anything that can send standard syslog, and collects infrastructure health alongside security logs (including SNMP-capable devices), so device health and security events land in one place instead of two tools.
What does "hardened" actually mean here?
Concretely: an operating system that mounts read-only and has no package manager to install onto, a fixed set of applications and nothing else, a firewall that denies inbound and outbound by default and is generated from your configuration rather than hand-written, updates signed with a key the appliance verifies before applying anything — and rolls back on its own if the new version doesn't boot cleanly. The web interface holds no authority to change the firewall or write the operating system; a separate privileged service checks each request against a fixed list of what that appliance may ask for. There is no emergency password and no standing credential on the box.
What is the pricing structure?
Each appliance is licensed on an annual subscription, priced by how many you deploy — that's what entitles you to upgrades, patches and support. It's a subscription to the appliance itself, running on hardware you control, and it works the same whether or not you're connected to us. We work out the actual figure with you on a call, against your deployment. A fully managed tier is also available, where we handle monthly patching and health-check reporting on top of the standard subscription.
What kind of support is available?
Support is by email and through our helpdesk, and you get a reply within one Australian business day — from the engineer who wrote the software, not a queue. That holds through leave. Raise something late on a Friday and the clock starts Monday.
One business day is when you hear back, not when the problem is solved: what you get in that window is someone who knows the system telling you what is happening, what to do in the meantime, and what the path to a fix looks like. Support runs Australian business hours, with no after-hours or overnight roster — if round-the-clock cover is a hard requirement for your site, talk to us about the managed option. Because the appliances have no remote access and don't phone home, support otherwise means diagnosis, guidance for someone at the console, and a signed update where the fault is ours.
Support pricing, and whether there will be tiers above this, are not settled yet, so we'll give you the current position on a call rather than leave a placeholder number here. Separately, a vulnerability reported to us is acknowledged within 3 business days and assessed within 10, and faults in our own code are fixed and shipped as a signed update prioritised on severity. We don't put a date on fixes for third-party components, because that fix has to come from upstream before we can ship it.
One business day is when you hear back, not when the problem is solved: what you get in that window is someone who knows the system telling you what is happening, what to do in the meantime, and what the path to a fix looks like. Support runs Australian business hours, with no after-hours or overnight roster — if round-the-clock cover is a hard requirement for your site, talk to us about the managed option. Because the appliances have no remote access and don't phone home, support otherwise means diagnosis, guidance for someone at the console, and a signed update where the fault is ours.
Support pricing, and whether there will be tiers above this, are not settled yet, so we'll give you the current position on a call rather than leave a placeholder number here. Separately, a vulnerability reported to us is acknowledged within 3 business days and assessed within 10, and faults in our own code are fixed and shipped as a signed update prioritised on severity. We don't put a date on fixes for third-party components, because that fix has to come from upstream before we can ship it.
How are vulnerabilities found and disclosed?
Every release publishes a full machine-readable inventory of what's inside it, and that inventory is scanned against two vulnerability databases every day — not once per release. Results are in your customer portal. The honest limit: it scans the current release rather than your particular appliance, because nothing reports back to us about what you're running, which is the trade for having no phone-home at all.
To report something to us, email admin@lineinterpreter.com with “security” in the subject. There has been no independent penetration test or third-party assessment of the appliances, and we don't claim one.
To report something to us, email admin@lineinterpreter.com with “security” in the subject. There has been no independent penetration test or third-party assessment of the appliances, and we don't claim one.
Looking for the OEE platform? Its FAQ is here.