Asset inventory
Manufacturer, model, firmware, protocols, addressing, role and location derived from real traffic.
Industrial asset visibility and governance
Rutile brings together the inventory, topology, configurations and lifecycle of every asset. One source of truth to support operations and prove regulatory compliance.
Rutile · product interface
One network, complete context
Rutile’s digital twin turns the reality of the industrial network into a single, navigable view that always remains connected to the process.
Starting from the real topology, we can open any asset to see which vulnerabilities affect it, the risk they represent in context, the status and age of its backups, available patches and its compliance position. Every decision is therefore based on the complete relationship between the asset, its communications and its industrial function.
Capabilities
What it is, where it is, what it communicates with, what it needs and what can be proven about it.
Manufacturer, model, firmware, protocols, addressing, role and location derived from real traffic.
A navigable graph of communications, routes and protocols on which all other data is projected.
CVEs and manufacturer advisories prioritised by actual exposure in the topology, not by CVSS alone.
Versions, availability, approval, maintenance window and before-and-after evidence.
Configuration copies, age, version comparison and last known good backup.
Inventory and history turned into continuous evidence for regulatory frameworks and audits.
Two sources, one reality
Rutile’s real strength lies in combining what the network reveals on its own with what only a direct query can confirm. These are not competing modes: they are two layers of the same industrial knowledge.
Rutile analyses traffic from a SPAN port or TAP to discover assets, communications, protocols and topology without directly accessing plant devices.
Active querying completes visibility and is required, at a minimum, for an in-depth understanding of network infrastructure. Not every endpoint needs to be accessed: controlled queries target those that add the most context.
Passive + activeBy combining network context with asset-level detail, Rutile ICS builds a living, verifiable digital twin that supports operational decisions from a shared view.
Exposure with context
Rutile correlates the identified asset with CVEs and manufacturer advisories. It then adds its function, communications and the routes that lead to it.


Operational recovery
See which parts of the plant retain a last known good configuration, when it was obtained and what has changed since.
- Profinet name: PLC-LINEA-03 + Profinet name: PLC-LINEA-03A Firmware: 2.9.2 · verified checksum
Change under approval
Rutile compares installed and available versions and takes each change to an authorised window. Nothing is applied without approval.

Evidence that stays current
Inventory, changes and controls leave an audit-ready trail. Evidence stays current instead of being rebuilt in a spreadsheet every year.

NIS2Documented inventory, risk management, incidents and continuity.
IEC 62443Zones, conduits, assets and technical controls linked to the topology.
ENS · RD 311/2022Asset status, applied measures and a verifiable change log.
CRAVersions, vulnerabilities and remediation lifecycle by product.
ISO 27001Inventory, owners, risks and operational control evidence.
On-premise architecture
No agents on plant devices.
Passive capture through a SPAN port or TAP.
Distinct, optional and scoped active querying.
SIEM and CMDB integration through controlled interfaces.
Industrial contexts
Strict traceability, long-lived assets and authorised changes.
Process continuity and visibility across instrumented systems.
Distributed infrastructure and versions coexisting for decades.
Remote sites, third parties and high operational criticality.
Geographically distributed sites and multi-vendor equipment.
Heterogeneous lines where availability and maintenance take precedence.
Treatment plants, pumping stations and distributed control systems delivering an essential 24/7 service.
Control centres, protection systems and remote assets where availability and visibility are critical.
Validated environments where every configuration, change and item of evidence must be traceable.
Continuous production, traceability and equipment from multiple generations and vendors.
Continuous processes, remote facilities and assets operating under demanding conditions.
Terminals, cranes, automated warehouses and distributed systems that cannot stop.
Product interface
Product decisions
Operations, maintenance, engineering, security and compliance work on the same asset and the same history.
A vulnerability is assessed with its route, exposure and plant function, not just an isolated score.
Queries and changes require an explicit scope, window and approval.
Developed in Europe by a team that performs penetration testing and operates an industrial SOC.
On-premise deployment and controlled integration with the required corporate systems.
Developed in Europe and deployed on-premise: data remains under the customer’s control, in line with Cybersecurity Made in Europe.
Information by need
Focused pages for evaluating the product, its deployment and its fit in an industrial environment.
Identity, communications, software, configurations and exposure in a living record.
Topology, vulnerabilities, risk, backups, patches and compliance.
NIS2, IEC 62443 and internal controls backed by maintained evidence.
Twelve operational realities where priorities and evidence differ.
Passive discovery, controlled active queries and no agents on plant devices.
Direct contact, office details and useful context for an initial discussion.
Technical questions
Demo request
Tell us briefly about your environment and what you need to solve. Our team will contact you to prepare a focused, useful demonstration.
Request sent. Thank you; our team will contact you.