Protect · Respond · Prove
Every response approved by a person. Every action on the record.
Playbooks, firewall rules and segmentation advice that your team reviews and applies. Compliance evidence builds up as you work, so audits stop being projects.
Human-Approved Response
From alert to firewall rule in minutes. Applied by your team, never by a script.
Automated actions are dangerous in a running plant. Synaptic OT prepares the response for you, with the blast radius and the exact rule text, and stops at the point where a person has to decide.
- Playbooks with approval gates. Incidents match playbooks automatically. Each step that changes anything waits in a manager’s approval queue with the blast radius shown.
- Remediation cards. What to do, why, the risk tier and blast radius, and the exact configuration snippet for your vendor.
- Firewall rule export. FortiOS, Cisco ASA and PAN-OS syntax, plus CSV for any other firewall.
- OT action card. Packet details, maintenance context and the OT Response Checklist in Markdown, ready to paste into a ticket or chat.
# FortiOS · RC-118 · approved by shift manager 03:06
config firewall policy
edit 0
set name "syn-INC-0412-block-ews"
set srcaddr "EWS-02" set dstaddr "PLC-03" "PLC-05" "PLC-07"
set service "MODBUS-TCP-502" set action deny
next
end Zones & Conduits Verifier
Your segmentation design, checked against every packet.
Most plants have a zone-and-conduit drawing. Few can show that the network still matches it. Synaptic OT records your zones and conduits, flags every flow that crosses them without permission, and signs each violation.
- Zone and conduit model. Declare zones and the conduits allowed between them, or derive them from engineering project files.
- Continuous verification. Observed flows are checked against declared conduits as traffic arrives.
- Signed violations. Each cross-zone violation is signed with Ed25519 and can be included in an auditor pack.
- Vendor ACL recommendations. Additive allow and deny suggestions per vendor format, for your network team to review.
violation CV-0077 signed Ed25519 flow Zone IT-Office → Zone Control-L1 tcp/44818 (EtherNet/IP) declared no conduit window outside maintenance status open · recommended: deny on FW-OT-01
Compliance & Audit
The audit evidence builds itself while you work.
Every detection, approval, baseline change and segmentation check already produces evidence. Synaptic OT maps it to the controls your regulator asks about and packages it for the auditor.
- Seven frameworks mapped. NESA (UAE IA), IEC 62443-3-2, IEC 62443-3-3, IEC 61511, NERC CIP, NIST SP 800-82r3 and NIS2.
- Live control scorecard. Each control is bound to the evidence the platform already keeps: logic diffs, conduit violations, maintenance records, audit logs, asset inventory and human attestations.
- Auditor evidence pack. Executive summary, control scorecard, forensic manifests, signed violations and the asset register in one bundle with a Merkle root.
- Tamper-evident audit log. HMAC-chained per tenant, with a verification endpoint and viewer for administrators.
framework IEC 62443-3-3 SR 3.3 security functionality verification compliant SR 5.2 zone boundary protection partial 2 open violations SR 6.1 audit log accessibility compliant SR 2.8 auditable events attested by plant manager
See it on your own traffic.
Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.