FAQ

Straight answers to the hard questions.

Safety, autonomy, air-gap, false positives, deployment and licensing: the things security buyers ask before anything else.

Is it safe to run against production?
Yes, with control you set. Nexich authors each proof-of-concept and detonates it in an isolated sandbox where hardware virtualization is available (a constrained host runner otherwise), then fires the validated exploit only at the target you authorized. Credential replay is lockout-safe by design: one scheduler holds the dial, with a per-pair interval, per-host attempt caps and a lockout cooldown, so a spray never trips account lockouts. Nexich also eases off automatically if a service shows stress, and Classic mode is fully deterministic and hands-on, so you set exactly how far the autonomy dial turns.
Is it safe to run against a live PLC?
It is read-only on the plant floor by construction rather than by a setting. On Modbus the write function codes cannot be framed at all: the function that builds a request accepts only the read set and ends in a default that refuses, so no flipped default or forgotten flag produces a write. S7comm reads the CPU's own diagnostic list and never downloads a block. A short list of channels, including GuardLogix safety I/O and SCADA failover synchronisation, is refused outright at the last step of port resolution, after the preset, after any custom ports, and after an operator's own typed entry. Rate limits follow the vendor's documented storm-protection thresholds rather than our defaults, and a per-host do-not-touch switch closes the aggressive classes on equipment you name.
Do you ever write to a controller?
No. Nothing in an industrial pass writes to a process, and the report says so on the finding itself. Controllability is established from what a device reports about itself: a Siemens CPU reporting protection level 1, a DNP3 outstation answering without a Secure Authentication challenge, an EtherNet/IP identity reply naming a device profile. Where a protocol offers no read that establishes it, we say the protocol contributes no controllability primitive rather than performing a write to find out. Modbus is exactly that case, and the report states it rather than leaving a blank.
What happens when the scan reaches a safety instrumented system?
It stops there, and the report records that it stopped. A device declaring one of ODVA's four safety device profiles has the aggressive and brute-force classes closed on it for the rest of the engagement, off a single unauthenticated identity reply. The limit is stated rather than hidden: a GuardLogix safety controller declares the ordinary programmable logic controller profile, so the absence of that signal is never treated as evidence that a device is not safety related, and Rockwell equipment carries a shipped do-not-touch note that reaches both the operator and the planner. A route from the business network to a safety network is reported as a critical finding on its own, before anything is done with it, because reaching it is the finding and doing more adds risk without adding information.
Which industrial protocols does it speak natively?
Fourteen, implemented in the engine with no third-party tool involved: Modbus/TCP, DNP3, S7comm, EtherNet/IP and CIP, OPC UA, BACnet/IP, IEC 61850 MMS, IEC 60870-5-104, PROFINET DCP, KNXnet/IP, Beckhoff ADS, HART-IP, Niagara Fox and CIP Safety. Identification keys off what a service said rather than the port it sits on, which matters because plants move software and because port 102 carries both S7comm and IEC 61850 MMS, so a port-keyed inventory labels every substation protection relay a Siemens PLC. The IEC 60870-5-104 active read is its own named opt-in, default off, because a STARTDT claims a master role on the link and some RTUs permit exactly one active master.
Does the AI phone home or send any data off-box?
By default, nothing. Nexich runs air-gapped: models run locally on your hardware with zero internet access, no telemetry or crash reporting, and no model API called, so topology, credentials and findings stay in a database you control. Nexich is also model-agnostic: if you prefer, you can connect a hosted or cloud model, in which case only your prompts reach that model. The recommended sovereign default is fully local. See the trust and sovereignty page.
Which AI models can I use?
Nexich is model-agnostic and connects to any OpenAI-compatible endpoint. Run a local model fully air-gapped for zero egress, or connect a frontier cloud model when your policy allows. Autonomy is gated on inferred model capability, not on a fixed vendor allow-list. See the supported models.
Won't an autonomous AI hallucinate false positives?
The AI plans and prioritizes, but exploitation is deterministic execution: in AI-driven modes, a finding is only shown as a trusted result once a real payload reproduces it (a captured shell, a dumped table, a replayed credential). Unproven claims are held back from the report, not padded into it. There is even a negative control: before trusting a credential success, Nexich re-dials the service with a bogus credential, and if that also gets in, the service is flagged accept-any rather than owned. That proof-first discipline is what separates it from a scanner's backlog of maybes.
How is this different from a vulnerability scanner?
A scanner infers risk from versions and banners and hands you a list. Nexich chains and detonates those findings into a proven exploit and builds cross-host kill chains from looted credentials. You triage exploited facts, not maybes. The full comparison breaks it down row by row.
What does deployment look like?
A self-contained on-prem deployment (you connect a local or cloud model): no agents to install on targets, no mandatory cloud services, no external dependencies. It runs on Windows and Linux, and installs self-contained on air-gapped hosts.
What are the five operating modes?
An autonomy ladder. Classic is deterministic and hands-on; Smart is an adaptive automated web-app pass; AI Hybrid advises while you drive; AI Autonomous plans and runs the engagement; AI Forge is the deepest mode, authoring custom exploits and hunting n-day variants across every service and credential. Turn the dial to match the engagement and the trust you want to extend.
What does it cover, which services and hosts?
In autonomous AI modes, a full TCP and UDP port and service sweep per host, with service detection by protocol behavior for web and banner-emitting services rather than port number. Coverage spans every service class an attacker touches: web apps, databases, message queues, Active Directory, remote access, file shares, VoIP, and OT/ICS down to the wire protocols (Modbus, S7comm, BACnet, DNP3), 397 native attack modules in all. Where a known exploit exists, Nexich uses it; where no list covers the gap, it writes a custom one on the spot.
Can I re-test after we ship a fix?
Yes. Re-fire proven web and network findings that carry a captured reproducer; Nexich replays the original exploit path and the AI returns a verdict (still vulnerable, fixed, or inconclusive with the reason) plus a plain-language note on what changed. Validation is a one-click loop, not a new engagement.
Who is authorized to use it?
Nexich is licensed for owners of the network under test and for providers running authorized engagements on behalf of clients. Evaluation builds are supervised and scoped to authorized use only.
How is it licensed and priced?
Self-hosted and licensed by in-scope IP address, from a 32-address minimum to 1,024 addresses. One all-inclusive license: there are no tiers and no feature held back for a higher package, so air-gapped operation and every capability ship with every license. Past 1,024 addresses we size the estate with you. There is no public price list. Tell us your in-scope IP count and we size it with you. See licensing or request an evaluation.
Still curious

Still have a question?

Evaluation builds · Authorized testing only