Security posture management for IT, IoT and OT

Your network and devices don't need an alert. They need direct fixes.

Point us at one machine and we find the rest — then install onto them from the inside, with no VPN and no appliance. We check what's exposed, explain it in plain English, and fix it with your approval. Safe to run beside a plant floor, by design rather than by setting.

Network Exposure Assessment — $7,500, two weeks. Send us a firewall config export and pick 25 machines. You get a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.

spotlight_agent — cyber_logs.txt
[05:37:41] Scanning 847 endpoints across OT/IT fabric...
[05:37:44] DESKTOP-ITVPPAU — DHCP nominal
[05:37:46] SIA-MED-PLC-e0cbbc256 — DHCP nominal
[05:37:48] IP conflict detected — VLAN 20
[05:37:49] XP10893686-2006 — unauthorized traffic
[05:37:49] Source: 10.0.20.11 → 1,552 unexpected packets

Issue Identified

IP 10.0.20.11 exploiting permissive rule — risk: unauthorized access

Recommended action:

$ sudo iptables -A INPUT -s 10.0.20.11 -j DROP

or

Take Action with Spotlight →

Issue Resolved

Remediation time: 0m 43s

Research-backed and grant-funded

Inception Program member
Activate for Startups member
Cybersecurity Grants recipient
T‑Challenge ’26 finalist
Security & Resiliency ’25 member
SecTor Startup Spotlight Finalist
"A CISO will always take a preventive and corrective control over a purely detective one, any day of the week."
Michael Smith
— former CTO, DigiCert
— Why Spotlight

Other tools stop at the alert.
We go all the way to the fix.

Legacy cybersecurity platforms were built for IT environments and bolt-on OT support. They identify problems, generate tickets, and wait for expensive professional services to intervene. Spotlight was built differently — from the attack surface up.

Legacy platforms

"We found a problem. Here's your alert."

Detection-only tools generate alerts, create tickets, and route issues to professional services engagements that cost thousands and take days. They require manual intervention to act. And they force your team to pivot between an IT console, an OT monitor, and an IoT portal. In other words, three or more panes of glass with zero correlation.

STATUS: ALERTING ONLY
vs.

Spotlight Security

"I found the problem. I fixed it. Here's what I did."

Lightweight agents deployed directly onto your hardware find the problem; our AI explains it in plain English and generates the fix. We empower you with approval-gated actions, no waiting required. No mandatory deployment engagement. One inventory across IT, IoT and OT — the machines with an agent and the machines without, in the same list on the same dashboard. Including the devices your endpoint tool will not run on and your OT monitor can only watch.

STATUS: MONITORING + MANAGEMENT + DETECTION + RESOLUTION

We turn an unknown estate into a known, controllable one.

— How it works

Four stages. One dashboard. No mandatory deployment engagement.

01

Connects

Lightweight agents deploy in minutes across your Windows, macOS and Linux machines — and find the rest of the estate from there: firewalls, switches, PLCs, HMIs, IoT sensors, and more.

02

Detects

Agents report what is actually on each machine — open ports, running processes, accounts, patch state, firewall rules — and we flag what is exposed or drifting.

03

Resolves

Our LLM translates complex logs and code into plain English explanations. Administrators remediate directly — one-click actions or guided commands from the dashboard.

04

Learns

Telemetry from remediation sharpens Spotlight's models, which are tested against containerised attack scenarios with scored checkpoints, so a detection change can be measured rather than asserted. Every fix will make the next one faster.

Command Centerrural-electric-coop-ok · 847 devices · 412 agents
All agents online
Total Devices847Across site
Critical1Requires action
Warnings3Under review
Healthy843Nominal
Active Threat Feed
View all →
SCADA-NODE-04 Unauthorized IP · Modbus port 502 Critical
RTU-PUMP-STN-7 Policy drift detected Warning
FW-PERIMETER-01 All rules nominal Healthy
CriticalSCADA-NODE-04 — unauthorized access
IP 10.0.20.11 is exploiting an overly permissive firewall rule, probing Modbus port 502. Risk: unauthorized access to operational technology.
Recommended action
sudo iptables -A INPUT -s 10.0.20.11 -j DROP
Resolved Remediation pushed on-device · connection severed · logged for audit 0m 43s
Industries

Built for the organizations that can't afford to go dark.

Spotlight is purpose-built for critical infrastructure environments — where downtime isn't an inconvenience, it's a public safety event.

🏭

Manufacturing

Defend production lines, industrial control systems, and connected equipment without halting operations — because in manufacturing, every minute of downtime costs real money.

Plant-floor PCsIndustrial IoTDCSProtective relays
🤝

MSP & Channel

Run one inventory across every client site from a single multi-tenant portal — the machines with an agent and the machines without — and hand each client a report that shows the work you did.

Multi-tenantPer-client reportingRBACCommission model

Electric Utilities & Co-ops

Protect grid infrastructure, SCADA systems, and substation automation from nation-state actors and opportunistic attackers — without disrupting power delivery operations.

SCADA hostsRTUsSubstation automationEnergy management systems
💧

Water & Wastewater

Secure treatment plant controls, pump stations, and distribution systems against increasingly targeted attacks on municipal water infrastructure.

HMIsPLCsPump stationsTreatment controls
"I've never seen anything like it. For someone who's in these environments every day, you have no idea how useful these tools are."
Larry Hill
— CEO, Hill Technical MSP
Pricing

Transparent pricing. No mandatory deployment engagement.

One of the most powerful things about Spotlight is what we don't charge for. No expensive remediation engagements. No surprise service fees. Just software that works.

Starter

$10/endpoint /month
Billed annually at $120/endpoint/yr · $499 one-time network setup — discovery, enumeration & agent deployment · 1 admin seat included
  • Lightweight agent deployment across all endpoints
  • Continuous posture and configuration monitoring
  • Plain-English issue explanations
  • Approval-gated remediation — you approve, we execute
  • Dashboard access (1 admin)
  • Coverage for IT, IoT and OT devices
See How it Works

MSP Partner

Partner
pricing available · Manage your clients. Earn commissions.
  • Everything in Growth
  • Authorized reseller program
  • Commission-based revenue model
  • Save up to 10 hrs/week per client
  • Branded multi-tenant portal
  • Sales & technical enablement
  • Dedicated partner success support
Coming Soon
Start here

Network Exposure Assessment

Send us a firewall config export and pick 25 machines. You get a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.

$7,500· two weeks
Request an Assessment

See Spotlight in action

Book a live demo and watch our agents let you find and fix a real issue on a real device. Most first deployments take minutes, not weeks.

Network Exposure Assessment — $7,500, two weeks. Send us a firewall config export and pick 25 machines. You get a ranked list of what is exposed and exactly how to fix it, plus a walkthrough. No commitment afterwards, and you keep the report either way.