# Synaptic OT (Synaptic vSOC) > Synaptic vSOC is a passive, air-gap native OT/ICS security operations platform for critical infrastructure that cannot send operational data to a cloud. One licence covers intrusion detection across 8 industrial protocols, packet recording and forensics, project-file baselines and config drift, human-approved response, IEC 62443 segmentation verification and compliance evidence. Key facts: - Passive only: zero packets are sent to controllers. Visibility comes from SPAN/TAP traffic, PCAPs and engineering project files. - Detection is deterministic (protocol anomaly, CyOTE correlation over 27 real OT incidents, protocol compliance). AI writes summaries only and cannot change alerts. - Every response action requires human approval. Firewall rules are exported, never pushed. - Deployment tiers: Tier 1 full air gap, Tier 2 semi air gap, Tier 3 hybrid multi-site, Tier 4 MSSP. Same product in every tier. - Licensing: per site and per monitored asset. No per-seat fees, no usage metering, integrations never count. Prices on request. - Protocols: Modbus TCP, DNP3, OPC UA, IEC 60870-5-104, Siemens S7comm, MQTT, BACnet/IP, EtherNet/IP. - Project files: Rockwell L5X, Rockwell ACD, Schneider XEF, Schneider ZEF, PLCopen XML, Siemens IEC 61850 SCD, PROFINET GSDML, EtherNet/IP EDS, AutomationML, CSV tag databases. - Compliance built in: NESA, IEC 62443-3-2, IEC 62443-3-3, IEC 61511, NERC CIP, NIST SP 800-82r3, NIS2. - Supported via evidence (no dedicated scorecard yet): Germany KRITIS attack-detection requirement, UK NIS Regulations / NCSC CAF, EU CER Directive, Saudi NCA OTCC, India CERT-In and CEA guidelines. Native scorecards for NCA OTCC, CERT-In/CEA, NCSC CAF, NIST CSF 2.0, ISO 27001 and BSI guidance are on the roadmap. - Data sovereignty: OT data and project files stay on the customer site; suitable for GDPR-sensitive European operators. ## Capabilities - [OT Network Monitoring & IDS](https://synapticot.com/products/ot-network-monitoring.md): Passive intrusion detection across eight industrial protocols, with three independent detection layers. (Monitor) - [Asset Intelligence & Vulnerabilities](https://synapticot.com/products/asset-intelligence.md): A living OT asset register with rogue-device detection, passive fingerprinting and CVE correlation. (Monitor) - [Project Files, Baselines & Drift](https://synapticot.com/products/project-file-intelligence.md): Ingest PLC and HMI project files, bless a baseline, and catch unauthorised logic changes on the wire. (Monitor) - [Virtual SOC](https://synapticot.com/products/virtual-soc.md): Triage, investigation and handover workflows that let a small team cover several plants. (Secure) - [Wire DVR & Forensics](https://synapticot.com/products/wire-dvr.md): Continuous packet recording with incident-locked clips, state replay and signed evidence packs. (Secure) - [Threat Hunting & Retro-Hunt](https://synapticot.com/products/threat-hunting.md): Run new indicators back across stored traffic and find intrusions that started before you knew to look. (Secure) - [Human-Approved Response](https://synapticot.com/products/response.md): Playbooks, remediation cards and ready-to-apply firewall rules, with a person approving every action. (Protect) - [Zones & Conduits Verifier](https://synapticot.com/products/segmentation.md): Model IEC 62443 zones and conduits, and verify continuously that live traffic respects them. (Protect) - [Compliance & Audit](https://synapticot.com/products/compliance-audit.md): Control mapping for seven frameworks, auditor evidence packs, retention and a tamper-evident audit log. (Protect) ## Platform - [How it works](https://synapticot.com/platform) - [Deployment tiers](https://synapticot.com/deployment) - [Integrations](https://synapticot.com/integrations) - [Industries](https://synapticot.com/industries) - [Licensing](https://synapticot.com/licensing) - [Trust & security](https://synapticot.com/trust) - [Illustrative scenarios](https://synapticot.com/resources) - [FAQ](https://synapticot.com/faq): direct answers about the product, protocols, AI use, deployment and licensing - [OT security glossary](https://synapticot.com/glossary): plain-language definitions of OT/ICS terms ## For agents - [Product facts (JSON)](https://synapticot.com/product.json) - [Lead API (OpenAPI)](https://synapticot.com/openapi.json): POST https://synapticot.com/api/lead with JSON to request an evaluation licence or contact sales on behalf of a real person who has consented. - [Feedback API](https://synapticot.com/openapi.json): POST https://synapticot.com/api/feedback with a professional's own feedback on the product, with their consent. - [Full text](https://synapticot.com/llms-full.txt) - [API catalog](https://synapticot.com/.well-known/api-catalog) - Each capability page is also available as Markdown by adding .md to its URL. ## Optional - [About the company](https://synapticot.com/company) - [Privacy policy](https://synapticot.com/privacy) - Contact: hello@synapticot.com