Ibex

Ibex

Air-gapped AI Security & Attack Surface Platform

See everything. Connect nothing. A sealed appliance that maps the attack surface of your most sensitive environments and governs the AI inside them, without ever touching the internet.

Get in Touch Try the live demo
What is sealed, and what comes out
The internet No route out, in either direction
Your perimeter
Ibex appliance

Own hardware, on-board model, local vulnerability database.

Network & AI Hosts, services, models, agents
Code Dependencies, secrets, IaC
Runtime Inline AI gateway
Auditor-ready evidence Leaves as a document, not as a connection

Secure your network and your AI,
behind your perimeter

Ibex is a sealed, on-premises appliance that secures both your network and the AI running inside it. It maps the complete attack surface of your most sensitive environments, scans the code your teams build, and governs every model and agent on your network: discovering them, enforcing guardrails on live AI traffic, watching for AI-specific threats, and producing auditor-ready compliance evidence, all without ever touching the internet.

True to its name, Ibex is an Isolated Bastion for Exposure & eXamination.

The challenge

The networks that matter most (classified, isolated, operational) are exactly the ones cloud attack-surface and AI-security tools can never reach. Connectivity is forbidden, so the very environments where visibility is most critical are the ones left in the dark.

Assets nobody registered pile up unseen, models and agents spin up ungoverned, and the code teams build ships with vulnerable dependencies, leaked secrets, and insecure infrastructure-as-code that no external scanner is allowed to inspect.

The solution

Ibex is a sealed appliance that runs entirely on its own hardware inside your perimeter. It maps the complete attack surface, scans your repositories offline, governs the AI running on the network, and ranks every finding against a locally held vulnerability database.

No cloud, no data egress, no external dependencies. Your data never leaves your control, and you still get the full discovery, detection, governance, and reporting the high-trust network has always lacked.

Shadow detection

What is really on the network, and what was never approved?

Ibex compares what is actually live against your approved baseline and surfaces the assets nobody registered: the unmanaged, forgotten, and rogue devices, and the unsanctioned local AI services running where no one was looking. Every unknown is a blind spot on your attack surface. Finding them stops being a matter of luck and becomes a process.

Secure the AI inside your perimeter

The same appliance that maps your network governs every model and agent running on it, the air-gapped equivalent of a full AI-security platform.

AI inventory & discovery

Finds the models, endpoints, notebooks, and agents on the network, surfaces shadow AI, and keeps model cards with a review-and-approval workflow and a portable AI bill of materials.

AI posture & compliance

Scans AI for misconfiguration and supply-chain risk and produces auditor-ready evidence against ISO 42001, the EU AI Act, NIST AI RMF, and Swiss frameworks.

Runtime AI gateway

An inline gateway enforces guardrails on live AI traffic, blocking, redacting, or alerting on PII, jailbreaks, and code leakage, with a zero-trust authorisation hub controlling who may reach each model.

AI monitoring & threat detection

Captures AI activity into a sovereign data lake and flags abuse and anomalies with behavioural detection, the AI-native equivalent of detection-and-response, entirely on-box.

Offline vulnerability intelligence

Every finding, on the network and in your code, is cross-checked against a vulnerability database held locally on the appliance, so exposures are identified and ranked with no external lookups and nothing leaving the perimeter.

Knowledge stays current through signed updates carried in by hand. Every change is deliberate, cryptographically verified, and audited, so the appliance is never out of date and never online.

Sovereign AI analysis

An on-board model plans each sweep, interprets the results, judges device roles and anomalies, and writes the findings in German, French, Italian, or English, drawing only on the appliance's own data.

Because the model runs locally on dedicated hardware, your data never leaves the infrastructure, which matters in classified and regulated environments where data sovereignty is non-negotiable.

Key features

Total visibility

Discovers every live host, device, service, application, and AI system into a continuously accurate inventory.

Code & application security

Scans repositories offline for vulnerable dependencies, code flaws, leaked secrets, and insecure IaC.

Offline vulnerability intelligence

Ranks every finding against a locally held vulnerability database, with no external lookups.

Sovereign AI analysis

An on-board model plans each sweep, judges device roles and anomalies, and reports in DE, FR, IT, or EN.

Sealed and sovereign

Runs entirely on its own hardware inside your perimeter, with no cloud and no data egress.

Signed, manual updates

Knowledge stays current through cryptographically verified updates carried in by hand, audited end to end.

How it works

1
Discover

Sweep the network to find every live host, device, service, application, and AI system, then fingerprint what each one is.

2
Inventory

Build a continuously accurate inventory of assets and AI, and flag everything that strays from your approved baseline.

3
Assess posture

Scan code, assets, and AI offline and rank every finding against the local vulnerability database.

4
Enforce & monitor

Optionally enforce guardrails on live AI traffic and watch for abuse and anomalies with behavioural detection.

5
Prove compliance

Deliver a prioritised report and auditor-ready compliance evidence, written by the on-board model in your language of choice.

Built for the networks the cloud cannot reach

Truly air-gapped

Sealed on its own hardware inside your perimeter, with no cloud, no data egress, and no external dependencies.

Discovery by default, control optional

A watchful posture that maps and scans without disruption, with runtime enforcement and offensive testing operator-activated and off by default.

Modular by edition

A core plus licensable add-ons, so each deployment runs only the capabilities it licenses. Talk to us about editions and pricing.

Your data stays yours

A sovereign, on-board model and a local vulnerability database mean nothing ever leaves your control.

Ready to see Ibex in action?

Walk a scoped Ibex estate shaped like your own environment, live in minutes.