The plant floor is in scope now.
Nexich validates industrial networks from the inside. It speaks 14 industrial protocols, reads controllers without ever writing to them, and proves the path from a business-network credential to a running process. Air-gapped on a local model, nothing you own leaves your network.

An OT assessor's reach, without the site visit.
Point Nexich at a plant network and it identifies what each device really is from what the device said, reads controllers the way a commissioning engineer would, and traces the route from the business network down to the cell. It thinks like an OT assessor and moves like software.
When no exploit exists, it writes one.
Nexich authors a custom exploit, detonates it in an isolated sandbox where hardware virtualization is available, and captures the shell. On an industrial network that matters more than anywhere else: the vendor software running your plant is rarely in a public exploit database, and a bespoke gateway never is.
It reads. It does not write.
Every plant-floor module runs read-only by default. Write function codes cannot be framed at all, and a per-host do-not-touch switch closes the aggressive classes on equipment you name.
Findings are stated by level. The question an OT engineer asks first is whether level 4 can reach level 1, and that is the question the report answers.
On your metal.
A self-contained, on-prem deployment. The AI, the exploit and the loot all stay inside the perimeter. No plant data reaches a vendor cloud, because there is no vendor cloud.
A version we cannot read is a version we do not claim.
Where a vendor publishes no unauthenticated version endpoint, Nexich says so rather than inferring one. An advisory is applied to your equipment only when the equipment told us what it runs.
If it answers on the wire, it is in scope.
Identification keys off what a service SAID, never the port it sits on. Plants move software, and a historian on a non-standard port is still a historian. That is why the industrial layer below is read the way an engineer would read it, and not the way a port list would.
- Modbus/TCP: unit discovery, device identification, eight read function codes. No write function code can be framed by the module at all
- DNP3: outstation sweep, the IIN2.1 fingerprint oracle, Group 0 device attributes, and Secure Authentication v5 detection that stops at the challenge
- S7comm: COTP handshake with family-aware addressing, firmware and order code, block list, and the CPU protection level
- EtherNet/IP and CIP: identity, device profile and safety-profile recognition from a single datagram, with no session slot consumed
- OPC UA: endpoint discovery, security policy and application identity, from the catalogue's own endpoint paths
- BACnet/IP: Who-Is discovery, object inventory and BBMD tables
- IEC 61850 MMS: substation IEDs told apart from S7 on the shared ISO-on-TCP port
- IEC 60870-5-104: the master-role read, behind its own named opt-in because it can displace a live SCADA master
- PROFINET DCP, KNXnet/IP, Beckhoff ADS, HART-IP, Niagara Fox and CIP Safety
- Historians: AVEVA PI, Proficy Historian, Wonderware, Exaquantum, zenon
- HMI and SCADA: SIMATIC WinCC, FactoryTalk View, Ignition, iFIX, GENESIS64, VTScada, Plant SCADA
- DCS and process: PCS 7, CENTUM VP, System 800xA, DeltaV and Experion estates
- Building and energy: WebCTRL, Metasys, Niagara Framework, enteliWEB
- Gateways and connectivity: Kepware, Softing dataFEED, OPC servers and serial gateways
- Controllers and field devices: PLCs, RTUs, safety controllers, drives and robot controllers
- Active Directory and identity: Kerberos, LDAP, ADCS, SSO and federation
- Web apps and APIs: the application layer, login flows and admin panels
- Databases: Postgres, MySQL, MSSQL, Oracle, MongoDB, Redis, Elasticsearch
- Remote access: SSH, RDP, VNC, WinRM and jump hosts into the industrial DMZ
- File shares: SMB, NFS and the engineering project files sitting on them
- Infrastructure: routers, switches, firewalls, VPNs, out-of-band controllers, UPS and PDU
- IoT fabrics: CoAP and MQTT device networks
- Cameras and NVR: IP cameras and video recorders on the plant VLAN
- Printers, VoIP and MFPs: the forgotten devices that answer anyway
- Robotics and AGV: UR, FANUC, KUKA, ABB, Yaskawa and the fleet controllers
- Medical devices: clinical inventory and connected equipment
- Transport and aviation systems
A port list is a rumor. What the controller said is the truth.
Every industrial finding names the exact exchange that produced it: the diagnostic the CPU answered, the byte that came back, the request an operator can send again themselves. Nothing was written to the process to earn it.

Your operation. Your model.
Nexich runs on any OpenAI-compatible model. On a plant network that usually means a local model with no route out at all, which is the deployment this product was built for. Connect a frontier cloud model instead when your policy allows. One screen, either way.
Cloud
Local
