New · Wire DVR with time-travel retro-hunt: rewind the plant network to the second it mattered →
SYNAPTIC OT Secure · Monitor · Protect

Protect · Respond · Prove

Every response approved by a person. Every action on the record.

Playbooks, firewall rules and segmentation advice that your team reviews and applies. Compliance evidence builds up as you work, so audits stop being projects.

Human-Approved Response

From alert to firewall rule in minutes. Applied by your team, never by a script.

Automated actions are dangerous in a running plant. Synaptic OT prepares the response for you, with the blast radius and the exact rule text, and stops at the point where a person has to decide.

  • Playbooks with approval gates. Incidents match playbooks automatically. Each step that changes anything waits in a manager’s approval queue with the blast radius shown.
  • Remediation cards. What to do, why, the risk tier and blast radius, and the exact configuration snippet for your vendor.
  • Firewall rule export. FortiOS, Cisco ASA and PAN-OS syntax, plus CSV for any other firewall.
  • OT action card. Packet details, maintenance context and the OT Response Checklist in Markdown, ready to paste into a ticket or chat.
Explore Human-Approved Response
Exported rule, ready for your firewall team
# FortiOS · RC-118 · approved by shift manager 03:06
config firewall policy
  edit 0
    set name "syn-INC-0412-block-ews"
    set srcaddr "EWS-02"  set dstaddr "PLC-03" "PLC-05" "PLC-07"
    set service "MODBUS-TCP-502"  set action deny
  next
end

Zones & Conduits Verifier

Your segmentation design, checked against every packet.

Most plants have a zone-and-conduit drawing. Few can show that the network still matches it. Synaptic OT records your zones and conduits, flags every flow that crosses them without permission, and signs each violation.

  • Zone and conduit model. Declare zones and the conduits allowed between them, or derive them from engineering project files.
  • Continuous verification. Observed flows are checked against declared conduits as traffic arrives.
  • Signed violations. Each cross-zone violation is signed with Ed25519 and can be included in an auditor pack.
  • Vendor ACL recommendations. Additive allow and deny suggestions per vendor format, for your network team to review.
Explore Zones & Conduits Verifier
A conduit violation
violation   CV-0077   signed Ed25519
flow        Zone IT-Office → Zone Control-L1   tcp/44818 (EtherNet/IP)
declared    no conduit
window      outside maintenance
status      open · recommended: deny on FW-OT-01

Compliance & Audit

The audit evidence builds itself while you work.

Every detection, approval, baseline change and segmentation check already produces evidence. Synaptic OT maps it to the controls your regulator asks about and packages it for the auditor.

  • Seven frameworks mapped. NESA (UAE IA), IEC 62443-3-2, IEC 62443-3-3, IEC 61511, NERC CIP, NIST SP 800-82r3 and NIS2.
  • Live control scorecard. Each control is bound to the evidence the platform already keeps: logic diffs, conduit violations, maintenance records, audit logs, asset inventory and human attestations.
  • Auditor evidence pack. Executive summary, control scorecard, forensic manifests, signed violations and the asset register in one bundle with a Merkle root.
  • Tamper-evident audit log. HMAC-chained per tenant, with a verification endpoint and viewer for administrators.
Explore Compliance & Audit
Scorecard extract
framework   IEC 62443-3-3
SR 3.3  security functionality verification   compliant
SR 5.2  zone boundary protection               partial   2 open violations
SR 6.1  audit log accessibility                compliant
SR 2.8  auditable events                       attested  by plant manager

See it on your own traffic.

Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.