A utility node is one hardened appliance that solves one OT security problem.
Deploy modular, single-purpose security nodes designed specifically for air-gapped or segmented OT networks. No multi-year implementation projects, just plug-and-play compliance and control.
The four appliances
How the four compare
| Node | What it does | What it replaces |
|---|---|---|
| LI-Core | One set of credentials for every system on your network, with phish-resistant MFA, internal DNS, and auto-renewing certificates. | A separate MFA product, manual internal DNS records, and certificates issued and renewed by hand. |
| LI-Vault | A hardened, self-hosted secrets vault for OT environments—running entirely on your local network without cloud dependencies. | A shared spreadsheet, a sticky note, or a cloud password manager that assumes an internet connection. |
| LI-Store | Time-locked, immutable backup storage for your critical OT assets—protecting configuration dumps, historian databases, and workstation images from ransomware and administrative deletion. | A plain writable backup share, or a cloud object-lock subscription. |
| LI-Scope | A lightweight OT SIEM and observability engine in a single appliance. Combines security event logging with operational metrics—giving you complete network visibility without the cost or complexity of enterprise SIEMs. | A cloud log-aggregation subscription, or reading raw logs by hand. |
One hardened baseline across your OT environment.
Any one of these solves a real problem on its own. But they're designed to run together: LI-Core issues the certificates and enforces the login step the other three sit behind, so buying all four means every appliance logs in the same way, patches the same way, and gets audited the same way — not four separate products with four separate security postures bolted together after the fact.
- One hardened baseline and one signed update across all four — not four vendors on four different patch schedules, each needing its own change request.
- LI-Core's logins, names, and certificates cover the other three automatically — no separate integration project to wire each one up.
- LI-Scope sees across all four appliances, not just what a single product chooses to export.
- A single OT security posture to audit, instead of four.
Stands alone. Compounds together.
Deploy a single appliance to solve a specific gap, or combine all four to form an integrated security baseline. LI-Core provides identity for the stack, while LI-Scope centralises logs and metrics across every node.
How it fits together
Hover or tap an appliance to explore how it connects with your network.
LI-Core
Identity, DNS & Certificates
LI-Vault
Secrets & Password Vault
LI-Store
Immutable Backup
LI-Scope
Logging & Alerting
Workstations & servers
Network & OT devices
Hover or tap an appliance node to inspect its roles and integrations.
LI-CoreIdentity, DNS & Certificates
Provides MFA / identity to LI-Vault, LI-Store, and LI-Scope, and to your workstations, servers, and network devices. Streams its own logs to LI-Scope.
LI-VaultSecrets & Password Vault
Authenticates against LI-Core, streams logs to LI-Scope, and holds the passwords for devices too old or too limited to log in through LI-Core themselves.
LI-StoreImmutable Backup
Authenticates against LI-Core, streams logs to LI-Scope, and takes backup jobs from your environment.
LI-ScopeLogging & Alerting
Receives logs and events from LI-Core, LI-Vault, and LI-Store, plus logs and metrics from your workstations, servers, and network devices.
Workstations & servers
Your engineers’ and operators’ workstations, plus any servers that run on-premises. They log in through LI-Core, with the extra login step it enforces, and send their logs and health metrics to LI-Scope.
Network & OT devices
Network devices, switches, PLCs, UPSes and other OT devices. They send logs to LI-Scope, save backups to LI-Store, log in through LI-Core where they support it, and keep their passwords in LI-Vault.