Introducing Skans 2.0
Today we’re announcing Skans 2.0 — the release that brings identity, access control, monitoring and compliance evidence to an isolated camera, IoT, OT, or building-automation network, without a security team and without the enclave having to reach the internet.
What’s new #
- Every device gets an identity. Cameras, controllers, and Windows endpoints each receive their own certificate from the built-in CA — no shared passwords anywhere.
- Bounded, correlated findings. You see a meaningful list of issues per device, never a raw firehose of events.
- Compliance evidence, automatically. Controls map to NIST families and produce audit-ready records as the system runs.
Everything inside #
Skans is air-gap-first. The whole root of trust — identity, certificates, access control, monitoring, patching, and audit — runs on the local network itself, and a disconnected appliance is a fully working one. When a feature needs outside data it arrives as signed content: either imported from an offline bundle, or pulled down by the optional Skans Update Service if an operator chooses to turn it on. That service is off unless you enable it — it fetches signed content; a connected check-in posts licensing and aggregate health counts, not identities, keys, inventory or audit data.
What’s coming #
Being clear about what isn’t here yet is part of the point:
- Distributed Core + Edge. A central Core with lightweight per-site Edges, so multi-site estates run under one pane. The wire protocol, Edge enrolment and the store-and-forward spool are working on a two-box lab bench; it is not a production deployment you can stand up today, and there are no committed per-Edge device figures. The shipping flagship is the single appliance.
- High availability. Design-stage, tracked alongside the distributed tier.
Ready to try it? Start with the Installation guide, then enroll your first device.