See it work

One scan. One install.
One fix you approve.

A thirty-second run of what Spotlight does on a plant network, using the same steps and the same guardrails as the product. Press deploy, then click any device.

Interactive · deploy Spotlight

Three devices you manage. Two you don't know about.

Most networks look like this before Spotlight: an inventory that was last right a month ago, and no way to act on what it shows. Point us at one machine and we find the rest, with no VPN and no appliance. Press deploy and watch what changes, then click any device to see what you can now see and fix on it.

Agent runs onWindowsmacOSLinux x86_64Linux ARMFreeBSDQNXone static binary, no runtime dependencies
About 30 seconds. Nothing to click until it finishes.
TOTAL DEVICES
3
UNDER MANAGEMENT
0
SHADOW DEVICES FOUND
0
FINDINGS
0
Agent installedKnown, no agentShadow device
Scan offSafe off
SPOTLIGHT COMMAND CENTER
3 devices · 0 installed
Inventory only. Nothing to act on.
ACTIVITYidle
Waiting. Press DEPLOY SPOTLIGHT to map the environment. Every step is written here with who did it.
What you can see and change

Select a device above.

Left is with the Spotlight agent on the device. Right is what you had. Every line on the left is something the agent actually reports or executes.

WITH SPOTLIGHT

Deploy first, then select a device.

WITH YOUR EXISTING TOOLS

Select a device.

The AI proposes. You approve. Nothing runs on its own.

The agent on the device carries out instructions. The AI model runs in the dashboard: it reads what the agent reported, explains it in plain English, and drafts the fix. The model never runs on your equipment. Every finding arrives with the exact command attached, so you read what it will do before it does it. Approve it now, leave it open until your maintenance window and approve it then, or acknowledge it with a reason. Nothing executes on a device until an administrator says yes, and every change is written to the activity log with who approved it and when.

Human approval requiredCommand shown before it runsFull activity logActive scanning and agent writes switched per networkSafe mode per operator
Where your AI can actually go

Everyone has AI now. Almost none of it can reach a device.

An AI model cannot fix a controller it has no way to talk to. The Spotlight agent is that path. Once it is on a device, the model that explains a finding can draft the fix and, with your approval, have the agent carry it out: on a Linux-based controller, an ARM camera, or a laptop. Use our hosted models, or point a role at a model you host yourself.

WITH SPOTLIGHTnothing installed yetNETWORK & PERIMETERPalo Alto, CloudflareENDPOINT AGENTSCrowdStrike and similar
Actions:See it·Read detail·Patch it·Change config·Run AI on it·Reviewed change, applied by you
Rows are what the agent does once installed. Devices with no host OS to install on (bare PLCs, RTUs, switches) are discovered from the network and kept in the same inventory. Firewalls: we read a config export, reconcile it against the logs, and hand you the exact rule change; we do not push to the firewall.

Want this run on your network?

Two weeks, $7,500, nothing installed until you approve it. You send a firewall config export and pick the machines. You get back a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.

1Send a firewall config export
2Pick 25 machines for a read-only agent
3Ranked findings and a walkthrough in two weeks

Discovery is passive by default and reads what your agents already know. Active scanning stays off until an administrator turns it on for a specific network, and anything that looks industrial is excluded from it automatically. When it runs, it is ten packets a second, one host at a time, no version probes. That is enforced in the product, not a setting we remember to switch on.