Continuous internal-network security

Security for the devices nobody else tests.

Lanciot keeps a live picture of every device on your internal network: cameras, controllers, printers, industrial gear. For each weakness we find, we run a safe check against the device itself and keep the evidence.

Evidence on every finding

A confirmed finding carries the result of a check that ran on the device.

IoT, OT and building systems

Cameras, controllers, access points and industrial equipment.

European infrastructure

Your data stays in the EU. The AI layer can be pointed at a model you choose.

What we find

A probe inside the network reaches the equipment that external scanning cannot. Most of it was installed by someone other than your IT department.

12345
Offices
Workstations, printers, VoIP phones, meeting room screens.
Default passwords, open file shares, desktops that open without a login.
Cameras and recorders
Dome cameras, recorders, intercoms.
Streams anyone already on the network can watch, and recorders still on their factory password.
Building management
Access control, HVAC, lighting, lifts.
Exposed control services, and management logins behind obsolete encryption.
Production and process
PLCs, drives, machine panels, weighbridges.
Controllers that answer Modbus or Siemens S7 without asking who is calling. We only ever read.
Network and server room
Switches, access points, servers, storage.
VLANs that do not separate traffic in practice, default SNMP community strings, obsolete TLS.

How it works

Deploy a probe

One command on a VM or a small mini PC inside your network. It updates itself.

It discovers and identifies

Outbound HTTPS only, with nothing inbound to open. It listens first, then scans, and establishes what each device is.

We check each weakness

Each candidate weakness gets a researched, safe check that runs against the device. Without evidence it is not reported as confirmed.

You act, we re-test

Confirmed findings arrive in plain language with their evidence, get assigned to whoever fixes them, and are re-tested when they do.

Your site

The equipment already on your network

Cameras and recorders
Access control, HVAC, building management
PLCs and production equipment
Printers, phones, workstations
Switches and access points
The Lanciot probe. One virtual machine or a small mini PC. One command to install, and it keeps itself up to date.

Outbound HTTPS only

Nothing is opened inbound. No VPN, no firewall change, no port forward.

Lanciot, in the EU

Where the work happens

Every device identified and kept current
Each weakness researched, then checked safely
An analyst reviews before a report goes out
Your dashboard
PDF reports
The probe starts every connection itself. Your data stays in the EU, and the address ranges it may look at are the ones you set.

What you get

One dashboard, organised around what has been confirmed and what to do about it.

app.lanciot.com/dashboard

Action required

3 confirmed vulnerabilities on your network

Each one was demonstrated by a check that ran against the device.

1critical2high

What happened to everything we looked at412 candidate issues triaged

Proven on your devices3Being tested18Needs a look on site11Matched on version only142Tested, nothing established238

Assets148 devices · 1,206 open services · 2 sites

Cameras42IoT31Building24Workstations22Printers18Other11

Proven on your devices

F-0142 Camera recorder reachable on its factory password

10.40.12.8 · Warehouse North

Critical

F-0139 Controller answers Modbus without authentication

10.60.4.21 · Plant 2

High

F-0131 Management login accepts an obsolete TLS version

10.40.3.4 · Warehouse North

Medium
A drawing of the customer dashboard, with example figures from a fictional site. No customer data appears on this page.

A live device inventory

Every device found, with its type, site, services, when it was last seen, and how its identity was established.

Findings separated by certainty

Vulnerabilities apart from security notes, and within them: action required, potential, informational, still being validated.

Evidence on every confirmed finding

The evidence itself, with the full history of validation attempts behind it.

The credentials that work

A credential proven to open a device is recorded against it, stored encrypted and revealed only on request.

PDF reports

Reviewed by a Lanciot analyst before they reach you. Full report, or executive summary.

Roles for your team

Owner, admin, member and limited. A contractor given the limited role sees only the findings assigned to them.

Why it is different

The work is in deciding what is real. Most of what a network scan turns up never becomes your problem, and sorting that out is the part you are buying.

What happens to everything we look at

A scanner hands you the whole bar and asks you to sort it out. Lanciot sorts it first, and only the left-hand band asks anything of you.

Everything you are asked to act on

Proven on your devices
Demonstrated by a check that ran, with the evidence attached.
Being tested
A check is being written and run. Nothing for you to do yet.
Needs a look on site
Real, but not something a network probe can exercise safely.
Matched on version only
A version matches a known weakness, but nothing was shown on your device.
Tested, nothing established
We tried and could not demonstrate it. That is not the same as proving it safe.

The bands are the ones your dashboard uses. The widths here show the shape of the work rather than a measured average, because the mix depends on your network. Your dashboard counts your own.

Four things make that possible. Open any card for the detail.

See it on your own network

We walk you through a live deployment. If it makes sense for your network, we can set up a probe and show you your own devices and findings.

You can also email hello@lanciot.com.