Continuous internal-network security
Security for the devices nobody else tests.
Lanciot keeps a live picture of every device on your internal network: cameras, controllers, printers, industrial gear. For each weakness we find, we run a safe check against the device itself and keep the evidence.
Evidence on every finding
A confirmed finding carries the result of a check that ran on the device.
IoT, OT and building systems
Cameras, controllers, access points and industrial equipment.
European infrastructure
Your data stays in the EU. The AI layer can be pointed at a model you choose.
Where this fits
A one-off pentest
Human led and thorough. It happens once or twice a year, and it describes the network as it was on the day.
A vulnerability scanner
Cheap and continuous. It reasons from version numbers, so the output is a long list of possibilities that still has to be checked by hand.
Lanciot
Continuous, and every finding it reports as confirmed has been checked against the device. A weakness it cannot demonstrate stays out of that list.
Why it is different
Open any card for the detail.
What we find
A probe inside the network reaches the equipment that external scanning cannot.
Default credentials
Common in IoT and building networks. We test documented default passwords once a device is identified, and confirm the login from what appears on screen afterwards.
Unauthenticated cameras and desktops
RTSP streams and VNC desktops that anyone already on the network can open. The evidence is a single frame captured from the stream or screen. No keyboard or pointer input is sent.
Industrial controllers
Modbus over TCP, UDP and TLS, and Siemens S7 and S7comm-plus. We read the device identity and the CPU's effective protection level, which shows whether reading from the controller requires authentication.
Network segmentation failures
DTP trunk negotiation and per-VLAN enumeration, which shows whether the VLANs isolate traffic in practice.
Exposed services and weak encryption
SNMP default community strings, unauthenticated MQTT brokers, open SMB shares, and TLS configurations that still accept obsolete protocols, ciphers and key sizes.
Newly published CVEs
We track the NVD and CISA known-exploited feeds continuously and match new entries against your current inventory within hours. Matches then go through the same validation as everything else.
How it works
Deploy a probe
One command on a VM or a small mini PC inside your network. It updates itself.
It discovers and identifies
Outbound HTTPS only, with nothing inbound to open. It listens first, then scans, and establishes what each device is.
We check each weakness
Each candidate weakness gets a researched, safe check that runs against the device. Without evidence it is not reported as confirmed.
You act, we re-test
Confirmed findings arrive in plain language with their evidence, get assigned to whoever fixes them, and are re-tested when they do.
What you get
One dashboard, organised around what has been confirmed and what to do about it.
A live device inventory
Every device found, with its type, site, services, when it was last seen, and how its identity was established.
Findings separated by certainty
Vulnerabilities apart from security notes, and within them: action required, potential, informational, still being validated.
Evidence on every confirmed finding
The evidence itself, with the full history of validation attempts behind it.
The credentials that work
A credential proven to open a device is recorded against it, stored encrypted and revealed only on request.
PDF reports
Reviewed by a Lanciot analyst before they reach you. Full report, or executive summary.
Roles for your team
Owner, admin, member and limited. A contractor given the limited role sees only the findings assigned to them.
See it on your own network
We walk you through a live deployment. If it makes sense for your network, we can set up a probe and show you your own devices and findings.
You can also email hello@lanciot.com.