One scan. One install.
One fix you approve.
A thirty-second run of what Spotlight does on a plant network, using the same steps and the same guardrails as the product. Press deploy, then click any device.
Three devices you manage. Two you don't know about.
Most networks look like this before Spotlight: an inventory that was last right a month ago, and no way to act on what it shows. Point us at one machine and we find the rest, with no VPN and no appliance. Press deploy and watch what changes, then click any device to see what you can now see and fix on it.
Select a device above.
Left is with the Spotlight agent on the device. Right is what you had. Every line on the left is something the agent actually reports or executes.
WITH SPOTLIGHT
WITH YOUR EXISTING TOOLS
The AI proposes. You approve. Nothing runs on its own.
The agent on the device carries out instructions. The AI model runs in the dashboard: it reads what the agent reported, explains it in plain English, and drafts the fix. The model never runs on your equipment. Every finding arrives with the exact command attached, so you read what it will do before it does it. Approve it now, leave it open until your maintenance window and approve it then, or acknowledge it with a reason. Nothing executes on a device until an administrator says yes, and every change is written to the activity log with who approved it and when.
Everyone has AI now. Almost none of it can reach a device.
An AI model cannot fix a controller it has no way to talk to. The Spotlight agent is that path. Once it is on a device, the model that explains a finding can draft the fix and, with your approval, have the agent carry it out: on a Linux-based controller, an ARM camera, or a laptop. Use our hosted models, or point a role at a model you host yourself.
| WITH SPOTLIGHTnothing installed yet | NETWORK & PERIMETERPalo Alto, Cloudflare | ENDPOINT AGENTSCrowdStrike and similar |
|---|
Want this run on your network?
Two weeks, $7,500, nothing installed until you approve it. You send a firewall config export and pick the machines. You get back a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.
Discovery is passive by default and reads what your agents already know. Active scanning stays off until an administrator turns it on for a specific network, and anything that looks industrial is excluded from it automatically. When it runs, it is ten packets a second, one host at a time, no version probes. That is enforced in the product, not a setting we remember to switch on.