Sovereign network intelligence

Discover your entire network — without it ever leaving the building.

DiscoveryHub is an air-gapped appliance for network discovery, IPAM, topology, automation and compliance. No cloud dependency. No data egress. Yours by design.

On-premises · node-locked · offline signed updates

Built for ISM Information Security Manual Essential Eight IRAP PSPF SOCI Act
The product

One appliance for the whole picture of your network.

DiscoveryHub runs entirely on your infrastructure and brings together the capabilities that usually take five disconnected tools — with the operational data staying exactly where it belongs.

01

Discovery & IPAM

Agentless L2/L3 discovery, address management and a live inventory that reconciles itself as the network changes.

02

Topology

Evidence-based topology from real device data — physical, logical and impact-aware, not a hand-drawn guess.

03

Automation

Config, NAPALM and OpenTofu-driven change with approval-pinned plans and a full audit trail.

04

Compliance & posture

Local-by-default vulnerability self-audit, AI-governance posture and security controls mapped to AU frameworks.

05

Design Studio

Take a network from tender to as-built, with a private on-appliance AI assisting the whole lifecycle.

06

On-appliance AI

Ask questions of your own network with a local model. Nothing is sent to a third party — ever.

Sovereignty by design

Not "cloud you can trust" — no cloud at all.

Most discovery platforms ask you to connect your network to their cloud. DiscoveryHub is built the opposite way. Sovereignty isn't an enterprise add-on here; it's the architecture.

— No egress

Your data never leaves

All discovery, analysis and AI runs on the appliance inside your perimeter. There is no outbound telemetry and no vendor backchannel.

— Node-locked

Bound to your hardware

Each appliance is licensed to its node. The software is source-compiled and the filesystem is hardened for a closed deployment.

— Offline updates

Signed, air-gap-safe

Updates arrive as offline RSA-signed packages you verify and apply on your schedule — no internet connection required.

— Auditable

Mapped to your obligations

Controls line up with the ISM, Essential Eight, IRAP, PSPF and the SOCI Act, so posture evidence is there when you need it.

Where it fits

For the networks that can't phone home.

OT & critical infrastructure

Discover and map OT/ICS estates where cloud connectivity is prohibited and uptime is non-negotiable.

Government

Hold network intelligence on-shore and on-premises, aligned to PSPF and ISM controls, under your own control.

Defence & sovereign

Operate fully air-gapped, node-locked and offline — designed for classified and isolated environments.

How it works

Two planes, cleanly separated.

The capability lives on an appliance you own. The only thing that connects to us is licensing — never your network data.

Plane 1 · the appliance

Everything technical, on-prem

Discovery, IPAM, topology, automation, compliance, Design Studio and the AI all run on the air-gapped appliance. Your operational and network data never leaves it.

Plane 2 · this site

Only the commercial layer

Buying, licensing, support and updates live here — and hold no customer network data. The single bridge between the two is a signed licence you download and apply offline.

Get started

See DiscoveryHub on your own terms.

Book a walkthrough, or request an evaluation appliance to run it inside your own environment — no data leaves your building to try it.