Skip to content
Introduction

Introduction

Safetybits is a cybersecurity platform for OT environments. It watches the devices and network traffic on your OT networks, builds an inventory of what it finds, and turns that into vulnerabilities, compliance findings, and alerts you can act on.

A plant engineer opens Safetybits to see what a screen is telling them and what to do about it. A security analyst uses it to triage alerts and vulnerabilities. An administrator installs the sensor and keeps the console running. An auditor pulls a compliance report as evidence for a framework such as NIS2 or IEC 62443. The console serves all four from the same underlying data.

Two components

Safetybits has two parts: a sensor that runs in your facility, and a console that you and your team use.

The sensor watches your network passively, discovers devices, evaluates detection rules, and learns what normal traffic looks like for each one. It reports what it finds to the console.

The console aggregates that data across every facility you monitor, computes risk and compliance scores, matches devices against known vulnerabilities, and is where you triage alerts and pull reports.

See Architecture for how the two talk to each other and what data crosses that boundary.

SaaS or on-prem

You can run the console as a hosted service in the Safetybits cloud, or install it on your own infrastructure alongside the sensor. Either way, the sensor always runs on-prem: it has to sit on your network to see traffic. Architecture covers both layouts.

Where to go next

If this is your first visit, follow the quickstart to get from first login to a populated inventory. The glossary defines the terms the rest of the documentation uses.