{
  "schema": "https://synapticot.com/product.json#v1",
  "publisher": {
    "name": "Synaptic OT",
    "legalName": "Synaptic OT Private Limited",
    "url": "https://synapticot.com",
    "contact": "hello@synapticot.com",
    "security": "security@synapticot.com"
  },
  "product": {
    "name": "Synaptic vSOC",
    "category": "OT/ICS security operations platform",
    "summary": "Passive, air-gap native platform for detecting, recording, investigating, responding to and proving OT security incidents.",
    "deployment": {
      "model": "On-premises appliance or virtual machine (Linux), installed from a signed offline bundle",
      "tiers": [
        {
          "id": "tier1",
          "name": "Full air gap",
          "internet": "none"
        },
        {
          "id": "tier2",
          "name": "Semi air gap",
          "internet": "allow-listed outbound only; OT data never leaves"
        },
        {
          "id": "tier3",
          "name": "Hybrid multi-site",
          "internet": "sites air-gapped; read-only summaries to HQ/DMZ"
        },
        {
          "id": "tier4",
          "name": "MSSP",
          "internet": "sanitised summaries to a multi-tenant console"
        }
      ]
    },
    "principles": [
      "zero packets to controllers",
      "deterministic detection; AI annotates only",
      "human approval for every response action",
      "air-gap first"
    ],
    "protocols": [
      "Modbus TCP",
      "DNP3",
      "OPC UA",
      "IEC 60870-5-104",
      "Siemens S7comm",
      "MQTT",
      "BACnet/IP",
      "EtherNet/IP"
    ],
    "projectFileFormats": [
      "Rockwell L5X",
      "Rockwell ACD",
      "Schneider XEF",
      "Schneider ZEF",
      "PLCopen XML",
      "Siemens IEC 61850 SCD",
      "PROFINET GSDML",
      "EtherNet/IP EDS",
      "AutomationML",
      "CSV tag databases"
    ],
    "complianceMappings": [
      "NESA",
      "IEC 62443-3-2",
      "IEC 62443-3-3",
      "IEC 61511",
      "NERC CIP",
      "NIST SP 800-82r3",
      "NIS2"
    ],
    "complianceByRegion": [
      {
        "region": "International",
        "items": [
          {
            "name": "IEC 62443-3-2",
            "status": "Mapped"
          },
          {
            "name": "IEC 62443-3-3",
            "status": "Mapped"
          },
          {
            "name": "IEC 61511",
            "status": "Mapped"
          },
          {
            "name": "ISO/IEC 27001",
            "status": "Supported via evidence"
          }
        ]
      },
      {
        "region": "European Union",
        "items": [
          {
            "name": "NIS2 Directive",
            "status": "Mapped"
          },
          {
            "name": "CER Directive (critical entities resilience)",
            "status": "Supported via evidence"
          },
          {
            "name": "GDPR and data sovereignty",
            "status": "Supported via evidence"
          }
        ]
      },
      {
        "region": "Germany",
        "items": [
          {
            "name": "KRITIS: attack detection requirement (BSI Act)",
            "status": "Supported via evidence"
          },
          {
            "name": "BSI guidance on attack detection systems",
            "status": "Roadmap"
          }
        ]
      },
      {
        "region": "United Kingdom",
        "items": [
          {
            "name": "NIS Regulations and NCSC CAF",
            "status": "Supported via evidence"
          },
          {
            "name": "NCSC CAF native mapping",
            "status": "Roadmap"
          }
        ]
      },
      {
        "region": "Gulf",
        "items": [
          {
            "name": "UAE IA (NESA)",
            "status": "Mapped"
          },
          {
            "name": "Saudi NCA OTCC",
            "status": "Supported via evidence"
          },
          {
            "name": "NCA OTCC native scorecard",
            "status": "Roadmap"
          }
        ]
      },
      {
        "region": "India",
        "items": [
          {
            "name": "CERT-In directions",
            "status": "Supported via evidence"
          },
          {
            "name": "CEA cyber security guidelines (power sector)",
            "status": "Supported via evidence"
          },
          {
            "name": "CERT-In and CEA native scorecards",
            "status": "Roadmap"
          }
        ]
      },
      {
        "region": "North America",
        "items": [
          {
            "name": "NERC CIP",
            "status": "Mapped"
          },
          {
            "name": "NIST SP 800-82r3",
            "status": "Mapped"
          },
          {
            "name": "AWIA 2018 (water)",
            "status": "Mapped"
          },
          {
            "name": "NIST CSF 2.0",
            "status": "Roadmap"
          }
        ]
      }
    ],
    "detectionCorpus": {
      "name": "CyOTE Insights (Idaho National Laboratory)",
      "incidents": 27,
      "observables": 6076,
      "mitreIcsTechniques": 71
    },
    "capabilities": [
      {
        "id": "ot-network-monitoring",
        "name": "OT Network Monitoring & IDS",
        "pillar": "monitor",
        "summary": "Passive intrusion detection across eight industrial protocols, with three independent detection layers.",
        "url": "https://synapticot.com/products/ot-network-monitoring"
      },
      {
        "id": "asset-intelligence",
        "name": "Asset Intelligence & Vulnerabilities",
        "pillar": "monitor",
        "summary": "A living OT asset register with rogue-device detection, passive fingerprinting and CVE correlation.",
        "url": "https://synapticot.com/products/asset-intelligence"
      },
      {
        "id": "project-file-intelligence",
        "name": "Project Files, Baselines & Drift",
        "pillar": "monitor",
        "summary": "Ingest PLC and HMI project files, bless a baseline, and catch unauthorised logic changes on the wire.",
        "url": "https://synapticot.com/products/project-file-intelligence"
      },
      {
        "id": "virtual-soc",
        "name": "Virtual SOC",
        "pillar": "secure",
        "summary": "Triage, investigation and handover workflows that let a small team cover several plants.",
        "url": "https://synapticot.com/products/virtual-soc"
      },
      {
        "id": "wire-dvr",
        "name": "Wire DVR & Forensics",
        "pillar": "secure",
        "summary": "Continuous packet recording with incident-locked clips, state replay and signed evidence packs.",
        "url": "https://synapticot.com/products/wire-dvr"
      },
      {
        "id": "threat-hunting",
        "name": "Threat Hunting & Retro-Hunt",
        "pillar": "secure",
        "summary": "Run new indicators back across stored traffic and find intrusions that started before you knew to look.",
        "url": "https://synapticot.com/products/threat-hunting"
      },
      {
        "id": "response",
        "name": "Human-Approved Response",
        "pillar": "protect",
        "summary": "Playbooks, remediation cards and ready-to-apply firewall rules, with a person approving every action.",
        "url": "https://synapticot.com/products/response"
      },
      {
        "id": "segmentation",
        "name": "Zones & Conduits Verifier",
        "pillar": "protect",
        "summary": "Model IEC 62443 zones and conduits, and verify continuously that live traffic respects them.",
        "url": "https://synapticot.com/products/segmentation"
      },
      {
        "id": "compliance-audit",
        "name": "Compliance & Audit",
        "pillar": "protect",
        "summary": "Control mapping for seven frameworks, auditor evidence packs, retention and a tamper-evident audit log.",
        "url": "https://synapticot.com/products/compliance-audit"
      }
    ],
    "integrations": {
      "available": [
        "Nozomi Networks (alert ingest)",
        "Claroty (alert ingest)",
        "Splunk",
        "ServiceNow",
        "Slack",
        "Email",
        "Fortinet FortiOS rule export",
        "Cisco ASA rule export",
        "Palo Alto PAN-OS rule export",
        "CSV rule export",
        "STIX/TAXII",
        "SAML 2.0",
        "OIDC"
      ],
      "inDevelopment": [
        "Dragos (alert ingest)"
      ]
    },
    "licensing": {
      "axes": [
        "site",
        "monitored asset"
      ],
      "perSeat": false,
      "usageMetering": false,
      "integrationsCountTowardAssets": false,
      "allCapabilitiesIncluded": true,
      "pricing": "on request",
      "types": [
        "evaluation",
        "annual",
        "perpetual"
      ]
    }
  },
  "actions": {
    "requestEvaluation": {
      "method": "POST",
      "url": "https://synapticot.com/api/lead",
      "spec": "https://synapticot.com/openapi.json",
      "kind": "evaluation"
    },
    "contactSales": {
      "method": "POST",
      "url": "https://synapticot.com/api/lead",
      "spec": "https://synapticot.com/openapi.json",
      "kind": "contact"
    }
  },
  "updated": "2026-10-09"
}