Sealed
Inside the perimeter. No internet connection, inbound or outbound.
Sovereign
Your hardware, your models. The data never leaves your control.
Complete
Network, code, AI and databases, assessed from one place.
Evidenced
Verified findings, with evidence, exported for the auditor.
Guessing is not enough when you have to answer for it.
Ibex gives you what you need to secure your assets, from a box that never goes online.
Across the EU, NIS2 has required essential and important entities to handle vulnerabilities and assess whether their security measures work since October 2024, and DORA asks the same of the financial sector. In Switzerland, the Information Security Act (ISG) has applied since January 2024, and since April 2025 critical-infrastructure operators must report cyberattacks to the BACS within 24 hours.
What crosses the perimeter
Nothing leaves Ibex on its own: no finding, no inventory, no telemetry, and nothing on the box opens a connection to the outside. Two things cross the perimeter, and both are carried by hand.
No internet connection, inbound or outbound. Licence checked on the box.
Air-gapped, as Ibex means it
- No connection to the internet, inbound or outbound.
- No call home: the licence is checked on the appliance, and nothing on it resolves or downloads anything at run time.
- No probe outside the network ranges you agree to.
- What crosses the perimeter crosses on physical media, by an operator's hand: the signed bundle in, the exports out.
Each update bundle carries an Ed25519 signature and a SHA-256 manifest per file; the appliance refuses anything that does not verify, applies what does in one step, and keeps a record of it.
One appliance,
the whole attack surface
Network, code, AI and databases on one sealed box, correlated across all of them.
Find the needle in your haystack
Scanners produce more lines than anyone can read. Ibex gives you traceability: from a finding to the host.
- One page per host
- Network findings and the code findings that map to it
- Predictability
- Same result on every run, with the rules in plain sight
- Deduplication
- One record per device, however many sources saw it
- Adaptability
- Deterministic where it can be, a model where it must
Traceability runs both ways. Open a finding and see its host. Open a host and see its findings.
- Code to host Repository name in the hostname
- Dependency to service Package name equal to the service product
- Database to host By address, then by hostname
- Database to segment Which network segments can reach it
- AI asset to host Recorded when discovery finds it
Every device on the network, measured against your baseline
Ibex maps what is on the network and flags anything outside your baseline.
- Identity
- IP, MAC, hostname and operating system
- Services
- Port, product, version and CPE
- Stable identifiers
- SSH host key, TLS certificate, DHCP fingerprint
- Provenance
- Every source that saw it, and how confident the merge was
- Status
- Outside the baseline with the reason, or dormant after 24 hours unseen
Scope is a fixed rule. Every target is checked against the agreed ranges, and anything outside them is refused before a packet is sent.
- Passive listening ARP, DHCP and mDNS from a SPAN port
- Layer-2 discovery Hosts on the local segment
- Port sweep Local and routed segments
- Service fingerprinting Product, version, OS and CPE
- Web probing Server banner and page title
- Identity resolution One record per device
- Baseline comparison Flags assets outside the baseline
- Shadow AI signatures Ollama, vLLM, LM Studio, Open WebUI
The code audit and how it happens
Nine independent passes over an immutable snapshot of the source, offline.
- Location
- File and lines, quoted from the source
- Blind verification
- A second, independent review confirms or refutes it without seeing the first report
- Severity
- Based on the CVSS v4.0 model
- Standards
- OWASP ASVS chapter and CWE identifier
- Remediation
- What to do, step by step
The source code never leaves the appliance, only the report does. A technical and a board version, with an ASVS coverage table.
- 01 Secrets and cryptography Keys in code and history
- 02 Authentication and session Tokens, expiry, recovery
- 03 Authorisation Where the check is missing
- 04 Injection and input SQL, commands, paths
- 05 Web layer XSS, CSRF, headers
- 06 Business logic Flows bypassed cleanly
- 07 Configuration and logging Insecure defaults
- 08 Supply chain Dependencies and CVEs
- 09 Services and APIs Exposed routes, contracts
The method behind it, the obligations each finding maps to, and how an audit runs on your premises are on the Security Audit page. For self-service scans of your own repositories, see Goshawk.
Finding the AI on your network and checking it
Ibex finds the model servers and agents in use and checks their setup. Red-team and an in-line gateway are optional.
- Guardrails
- Guards chosen per endpoint
- Red-team verdict
- Pass or fail per attack category, with a grade
- Frameworks
- Ten packs, among them the EU AI Act, ISO/IEC 42001 and OWASP LLM Top 10
- Gateway evidence
- Audit event, alert and a redacted record
- Exports
- SARIF findings, audit PDF, ML-BOM
Every block, redaction and verdict leaves an audit record on the appliance. Red-team and the gateway are optional modules, enabled per deployment.
- AI discovery Model servers, notebooks and agents
- Repository markers Weights, frameworks and model cards
- Posture rules Authentication, rate limits, version pinning
- Model-artifact scanning Inspected without being loaded
- Sensitive data PII and secrets, redacted
- Red-team 25 categories mapped to MITRE ATLAS
- In-line gateway Block, redact or alert
- Framework mapping Evidence for the auditor
- AI bill of materials CycloneDX 1.6 ML-BOM
What your databases allow, checked against a set of rules
PostgreSQL, MySQL, SQL Server, Oracle and MongoDB, through an account your DBA creates from our script.
- Rule
- Engine-specific, in the families listed
- Verdict
- Pass, fail, or unknown if it could not be read
- Evidence
- The setting as read, and any change since the last run
- Network context
- The discovered segment that can reach it
- Standards
- NIS2, ISO 27001 and NIST CSF controls, SARIF export
Ibex shows where personal and sensitive data is kept. It reports the kind of data, such as card numbers or dates of birth, and none of the values. Column names are read in six languages, German, French and Italian among them.
- Authentication and accounts Passwordless and default logins
- Least privilege PUBLIC grants and privilege sprawl
- Encryption in transit TLS enforcement
- Encryption at rest What the engine reports
- Audit logging Whether it is on, and what it records
- Network exposure Which network segments can reach it
- Patch level The version actually running
- Backup History or current configuration
We come to you,
not the other way around.
Nothing leaves the appliance but the report. Nothing outside the agreed scope is touched.
Source code, database settings and model traffic are read on your hardware and stay there.
One inventory behind every module, so a finding can name the host it runs on.
Verified findings with evidence, an audit record on the appliance, SARIF and PDF for the auditor.

