Security posture management for IT, IoT, and OT

Your network and devices don't need an alert. They need direct fixes.

Point us at one machine and we find the rest — then install onto them from the inside, with no VPN and no appliance. We check what's exposed, explain it in plain English, and fix it with your approval. Safe to run beside a plant floor, by design rather than by setting.

Network Exposure Assessment — $5,000, two weeks. Send us a firewall config export and pick 25 machines. You get a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.

spotlight_agent — cyber_logs.txt
[05:37:41] Scanning 847 endpoints across OT/IT fabric...
[05:37:44] DESKTOP-ITVPPAU — DHCP nominal
[05:37:46] SIA-MED-PLC-e0cbbc256 — DHCP nominal
[05:37:48] IP conflict detected — VLAN 20
[05:37:49] XP10893686-2006 — unauthorized traffic
[05:37:49] Source: 10.0.20.11 → 1,552 unexpected packets

Issue Identified

IP 10.0.20.11 exploiting permissive rule — risk: unauthorized access

Recommended action:

$ sudo iptables -A INPUT -s 10.0.20.11 -j DROP

or

Take Action with Spotlight →

Issue Resolved

Remediation time: 0m 43s

Research-backed and industry-validated

Inception Program member
Activate for Startups member
Cybersecurity Grants recipient
T‑Challenge ’26 finalist
Security & Resiliency ’25 member
SecTor Startup Spotlight Finalist
Women in AI Pitch Winner
"A CISO will always take a preventive and corrective control over a purely detective one, any day of the week."
Michael Smith
— former CTO, DigiCert
— Why Spotlight

Other tools stop at the alert.
We go all the way to the fix.

Legacy cybersecurity platforms were built for IT environments and bolt-on OT support. They identify problems, generate tickets, and wait for expensive professional services to intervene. Spotlight was built differently — from the attack surface up.

Legacy platforms

"We found a problem. Here's your alert."

Detection-only tools generate alerts, create tickets, and route issues to professional services engagements that cost thousands and take days. They require manual intervention to act. And they force your team to pivot between an IT console, an OT monitor, and an IoT portal. In other words, three or more panes of glass with zero correlation.

STATUS: ALERTING ONLY
vs.

Spotlight Security

"I found the problem. I fixed it. Here's what I did."

Lightweight agents deployed directly onto your hardware find the problem; our AI explains it in plain English and generates the fix. We empower you with approval-gated actions, no waiting required. No mandatory deployment engagement. One inventory across IT, IoT, and OT — the machines with an agent and the machines without, in the same list on the same dashboard. Including the devices your endpoint tool will not run on and your OT monitor can only watch.

STATUS: MONITORING + MANAGEMENT + DETECTION + RESOLUTION

We turn an unknown estate into a known, controllable one.

— How it works

Four stages. One dashboard. No mandatory deployment engagement.

01

Connects

Lightweight agents deploy in minutes on Windows, macOS, Linux (x86 and ARM), FreeBSD, and QNX — servers, workstations, Linux-based controllers, HMIs, and cameras — and find the rest of the estate from there: firewalls, switches, and the devices with no host OS to install on.

02

Detects

Agents report what is actually on each machine — open ports, running processes, accounts, patch state, firewall rules — and we flag what is exposed or drifting.

03

Resolves

Our LLM translates complex logs and code into plain English explanations. Administrators remediate directly — one-click actions or guided commands from the dashboard.

04

Learns

Telemetry from remediation sharpens Spotlight's models, which are tested against containerised attack scenarios with scored checkpoints, so a detection change can be measured rather than asserted. Every fix will make the next one faster.

Command Centerrural-electric-coop-ok · 847 devices · 412 agents
All agents online
Total Devices847Across site
Critical1Requires action
Warnings3Under review
Healthy843Nominal
Active Threat Feed
View all →
SCADA-NODE-04 Unauthorized IP · Modbus port 502 Critical
RTU-PUMP-STN-7 Policy drift detected Warning
FW-PERIMETER-01 All rules nominal Healthy
CriticalSCADA-NODE-04 — unauthorized access
IP 10.0.20.11 is exploiting an overly permissive firewall rule, probing Modbus port 502. Risk: unauthorized access to operational technology.
Recommended action
sudo iptables -A INPUT -s 10.0.20.11 -j DROP
Resolved Remediation pushed on-device · connection severed · logged for audit 0m 43s
Industries

Built for the organizations that can't afford to go dark.

Spotlight is purpose-built for critical infrastructure environments — where downtime isn't an inconvenience, it's a public safety event.

🏭

Manufacturing

Defend production lines, industrial control systems, and connected equipment without halting operations — because in manufacturing, every minute of downtime costs real money.

Plant-floor PCsIndustrial IoTDCSProtective relays
🤝

MSP & Channel

Run one inventory across every client site from a single multi-tenant portal — the machines with an agent and the machines without — and hand each client a report that shows the work you did.

Multi-tenantPer-client reportingRBACCommission model
⚡

Electric Utilities & Co-ops

Protect grid infrastructure, SCADA systems, and substation automation from nation-state actors and opportunistic attackers — without disrupting power delivery operations.

SCADA hostsRTUsSubstation automationEnergy management systems
💧

Water & Wastewater

Secure treatment plant controls, pump stations, and distribution systems against increasingly targeted attacks on municipal water infrastructure.

HMIsPLCsPump stationsTreatment controls
"I've never seen anything like it. For someone who's in these environments every day, you have no idea how useful these tools are."
Larry Hill
— CEO, Hill Technical MSP
Pricing

Transparent pricing. No mandatory deployment engagement.

One of the most powerful things about Spotlight is what we don't charge for. No expensive remediation engagements. No surprise service fees. Just software that works.

Up to 250 devices

$8/device /month
For networks of 1–250 devices · $7.20/device/month with an annual contract
See it Work

1,001+ devices

$4/device /month
For networks of more than 1,000 devices · $3.60/device/month with an annual contract
Talk to Sales

Every plan includes

  • Lightweight agent deployment across all devices
  • Continuous posture and configuration monitoring
  • Plain-English issue explanations
  • Approval-gated remediation — you approve, we execute
  • Coverage for IT, IoT, and OT devices
  • Multi-site deployment
  • Role-based access control (RBAC)
  • Advanced telemetry & reporting

Save 10% with an annual contract · First network setup included · Each additional network $499 one-time (discovery, enumeration & agent deployment)

Start here

Network Exposure Assessment

An initial scan and report of your network. Send us a firewall config export and pick 25 machines. You get a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.

$5,000· two weeks
Request an Assessment
MSP & channel partners

Resell Spotlight and earn on every client

Subscribe your clients through Spotlight's multi-tenant, branded portal and earn a share of every subscription, with sales and technical enablement and dedicated partner support.

Coming soon
Register Interest

See Spotlight in action

Book a live demo and watch our agents let you find and fix a real issue on a real device. Most first deployments take minutes, not weeks.

Network Exposure Assessment — $5,000, two weeks. Send us a firewall config export and pick 25 machines. You get a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.