Continuous internal-network security
Security for the devices nobody else tests.
Lanciot keeps a live picture of every device on your internal network: cameras, controllers, printers, industrial gear. For each weakness we find, we run a safe check against the device itself and keep the evidence.
Evidence on every finding
A confirmed finding carries the result of a check that ran on the device.
IoT, OT and building systems
Cameras, controllers, access points and industrial equipment.
European infrastructure
Your data stays in the EU. The AI layer can be pointed at a model you choose.
What we find
A probe inside the network reaches the equipment that external scanning cannot. Most of it was installed by someone other than your IT department.
- Offices
- Workstations, printers, VoIP phones, meeting room screens.
- Default passwords, open file shares, desktops that open without a login.
- Cameras and recorders
- Dome cameras, recorders, intercoms.
- Streams anyone already on the network can watch, and recorders still on their factory password.
- Building management
- Access control, HVAC, lighting, lifts.
- Exposed control services, and management logins behind obsolete encryption.
- Production and process
- PLCs, drives, machine panels, weighbridges.
- Controllers that answer Modbus or Siemens S7 without asking who is calling. We only ever read.
- Network and server room
- Switches, access points, servers, storage.
- VLANs that do not separate traffic in practice, default SNMP community strings, obsolete TLS.
How it works
Deploy a probe
One command on a VM or a small mini PC inside your network. It updates itself.
It discovers and identifies
Outbound HTTPS only, with nothing inbound to open. It listens first, then scans, and establishes what each device is.
We check each weakness
Each candidate weakness gets a researched, safe check that runs against the device. Without evidence it is not reported as confirmed.
You act, we re-test
Confirmed findings arrive in plain language with their evidence, get assigned to whoever fixes them, and are re-tested when they do.
Your site
The equipment already on your network
Outbound HTTPS only
Nothing is opened inbound. No VPN, no firewall change, no port forward.
Lanciot, in the EU
Where the work happens
What you get
One dashboard, organised around what has been confirmed and what to do about it.
Action required
3 confirmed vulnerabilities on your network
Each one was demonstrated by a check that ran against the device.
What happened to everything we looked at412 candidate issues triaged
Assets148 devices · 1,206 open services · 2 sites
Proven on your devices
F-0142 Camera recorder reachable on its factory password
10.40.12.8 · Warehouse North
F-0139 Controller answers Modbus without authentication
10.60.4.21 · Plant 2
F-0131 Management login accepts an obsolete TLS version
10.40.3.4 · Warehouse North
A live device inventory
Every device found, with its type, site, services, when it was last seen, and how its identity was established.
Findings separated by certainty
Vulnerabilities apart from security notes, and within them: action required, potential, informational, still being validated.
Evidence on every confirmed finding
The evidence itself, with the full history of validation attempts behind it.
The credentials that work
A credential proven to open a device is recorded against it, stored encrypted and revealed only on request.
PDF reports
Reviewed by a Lanciot analyst before they reach you. Full report, or executive summary.
Roles for your team
Owner, admin, member and limited. A contractor given the limited role sees only the findings assigned to them.
Why it is different
The work is in deciding what is real. Most of what a network scan turns up never becomes your problem, and sorting that out is the part you are buying.
A scanner hands you the whole bar and asks you to sort it out. Lanciot sorts it first, and only the left-hand band asks anything of you.
Everything you are asked to act on
- Proven on your devices
- Demonstrated by a check that ran, with the evidence attached.
- Being tested
- A check is being written and run. Nothing for you to do yet.
- Needs a look on site
- Real, but not something a network probe can exercise safely.
- Matched on version only
- A version matches a known weakness, but nothing was shown on your device.
- Tested, nothing established
- We tried and could not demonstrate it. That is not the same as proving it safe.
The bands are the ones your dashboard uses. The widths here show the shape of the work rather than a measured average, because the mix depends on your network. Your dashboard counts your own.
Four things make that possible. Open any card for the detail.
See it on your own network
We walk you through a live deployment. If it makes sense for your network, we can set up a probe and show you your own devices and findings.
You can also email hello@lanciot.com.