You cannot fix what nobody has measured.

We map your network from the devices themselves — not from the diagram — and hand you a report that names every finding next to the evidence behind it.

1400+Devices in one pass
11Platforms, and growing
60+Checks

The scale the instrument is built to work at. Measured against a real multi-vendor fleet, not brochure numbers.

Demo fleet · synthetic data
Two addresses in, a report out. Fifty-four seconds, start to finish: the scan, the security checks, CVEs crossed with what is known to be exploited, a change window, and the report. The fleet is invented; the method is the one we run.

The diagram is three years old, and it was wrong when it was drawn.

Nobody documents a network that grew. The switch added during an outage, the link to the new building, the VLAN that was meant to be temporary — none of it is on the drawing, and the only place the truth exists is inside the devices themselves.

We ask them. Two addresses are enough to start: we log in, read the neighbours each device declares over LLDP and CDP, and walk outward until we stop finding new ones. What comes back is not an opinion about your network — it is what your network says about itself.

Finding them is half of it. The map is assembled in layers: the neighbours both ends declare, the links we verify by MAC against the forwarding database — that is how the firewall that speaks no LLDP shows up, with its exact port — the VSX, VSS, stack and MLAG clusters, and GRE and IPsec tunnels as their own layer. Whatever is left standalone hangs off whoever owns its gateway. A link makes it onto the drawing because it was measured.

A report you can act on Monday.

Nothing to install on your devices. No licence, no dashboard to keep alive, no tool to learn — you get these documents. Not a slide deck with traffic lights either: every finding carries the device, the interface and the output it came from.

Security report: 198 collected, 312 links, security posture and vendor breakdown
Demo fleet · synthetic data
The security report. What was collected, what could not be, and the posture in one page — KEV-exploited CVEs, critical CVEs, devices past End-of-Life, and how much of the fleet the CVE source actually covers.
Configuration exposure: each item lists the devices by name
Demo fleet · synthetic data
Exposure, with names. Not '9 devices have telnet' — which nine. Every line lists the hostnames, so it can be handed to whoever fixes it without a second query.
Findings report: 192 total findings across 60 checks
Demo fleet · synthetic data
The findings report. One number up front, then every check — including the ones that came back clean, because a category nobody ran and a category with nothing wrong are different answers.
Findings detail: 21 VLAN mismatches, each naming both ends and the discrepancy
Demo fleet · synthetic data
And the evidence. Both ends of the link, the interface on each, and exactly what disagrees. Enough to argue with, dismiss, or fix — without measuring again.

Sixty-plus checks, and every one names its evidence.

Deterministic: run by code, not by a judgement that varies with who is auditing or with the day. A selection by category below.

Physical

  • CRC / input-errors rising
  • Duplex mismatch
  • Speed mismatch
  • MTU mismatch
  • Down endpoint on an active link
  • Devices that rebooted on their own

Layer 2

  • VLAN mismatch on trunks
  • Native VLAN mismatch
  • VLAN allowed but not defined
  • L2 loop with no STP protection
  • One MAC in two broadcast domains
  • Duplicate MAC · Duplicate IP

Spanning tree

  • STP root on an access port
  • Accidental STP root
  • STP disabled with redundant links
  • STP reconverging
  • STP guard triggered

Routing

  • OSPF area mismatch
  • OSPF adjacency stuck
  • OSPF configured but not activated
  • Routing loop or blackhole
  • Subnet mismatch on an L3 link
  • BGP peer down · Tunnel down

Redundancy

  • FHRP virtual-IP mismatch
  • FHRP priority tie
  • Port-channel member not bundled
  • VSX consistency
  • FortiGate HA cluster

Security

  • Telnet server exposed
  • Readable secrets on the device
  • No centralised authentication
  • Log export configured but switched off
  • No NTP · Device clock is wrong
  • Actively-exploited CVEs and End-of-Life

Data health

  • Coverage and staleness of what was collected
  • Topology drift between scans
  • Config changed since the previous scan
  • Unreadable files — counted and named, never dropped
Demo fleet · synthetic data
The order that matters is not the count. Same fleet, sorted by how many CVEs each device has — then crossed against CISA's catalogue of vulnerabilities known to be exploited. The device with three ends up above the device with forty-one.
Where to start: 192 findings ordered by impact
Demo fleet · synthetic data
192 findings over this fleet. Sixty-plus checks produce a list; this turns it into an order. Broken connectivity first, then what needs a credential read, then what cannot be reconstructed afterwards.

What we will not do.

You are going to give us access to your devices. Whoever asks for that should be judged on what they cannot do, not on their feature list.

01

We never write. Ever.

Every command comes from a whitelist: reads, plus the few mode changes some platforms need before they will show their configuration, each one named, and none of them changes a line of your configuration. You get that list, vendor by vendor, before we start, and your AAA logs can check every command against it. The test that enforces it walks the module instead of a hand-written list, so a command added later is checked whether or not anyone remembered.

02

Your credentials do not leave your network.

The instrument runs inside your perimeter, on a machine you control. Credentials live in memory and are never written to disk. No configuration file from your fleet is uploaded anywhere: the only things that leave are a query to NVD by model and firmware version, and the download of the public CISA catalogue — never a configuration, an address or a hostname.

03

We will not spend a failed login.

A failed authentication can log, alert, or lock an account out across your whole fleet — and that is the auditor causing an incident, not finding one. Vendor-specific accounts are tried only against their own vendor. There is no default username and no second password for the same user.

04

We will not hand you a clean report we cannot stand behind.

A fleet-wide silence is a broken measurement, not a state of the network: the instrument refuses to overwrite good data with it and carries that refusal in its exit code. A measurement that failed says so; it never dresses up as a healthy network.

No agents, no change window, no three-hour meeting.

Nothing is installed on your devices. No outage window is needed: these are the same sessions anyone opens to look at a configuration, and nothing we run can modify a device.

One fixed price per audit, set by device count and agreed before we start. No licence, no subscription.

We sign first

A written authorisation naming the ranges and the dates, and a non-disclosure agreement. Not one device is touched before both exist.

You create the account

An account you create and remove yourself, with the exact command list in hand. You choose the addresses and the ports. Two devices are enough to start — the crawl finds the rest.

We measure, from a machine in your network

It runs on a virtual machine you provide, inside your network, and nowhere else. It collects, scrubs the passwords, parses and builds the graph; each stage writes a file the next one reads, and nothing is inferred that could be read.

You get the report

The map, the findings with their evidence, and the exposure inventory. Over a short call if you want, but the report stands on its own.

Your data stays with you

What was collected stays on your machine for the next pass, or is deleted and confirmed to you in writing. We keep nothing.

And again, when it makes sense

A second pass is not another audit from scratch — it is the delta. What changed, what got fixed, and what is new, and it costs less than the first.

Six vendors, eleven platforms, each with its own dialect.

A network that grew is a mixed network, and that is exactly where a single-vendor tool gives up. Each brand brings its own command set, its own way of spelling LLDP, and its own parsing branch.

Cisco IOSIOS XEIOS XRNX-OS Cisco Small BusinessAruba AOS-CXAruba / HP ProCurve HP ComwareFortinet FortiOS TP-Link JetStreamLantronix

Start with two IP addresses.

On the network side, that is all a first pass needs. Tell us what you have and what you suspect, and we will come back with what your network actually says.

You do not need an inventory, a device list, or the old diagram. If the diagram existed and were right, none of this would be necessary.

The first pass only ever reads: it changes nothing, installs nothing, and needs no maintenance window.

Or write to us: [email protected]