OT and air-gapped environments
OT and air-gapped environments are a promising fit precisely because the protocol runs with no AI in the loop: a site that cannot put a model on its network still gets authenticated, request-linked records of what was requested, attempted, and received. Write governance on live OT has not been demonstrated with a client.
- No agent on the equipment. You can't put an agent on a 15-year-old PLC, and active scanning can crash gear that was never built to be probed. VIRP installs nothing on the equipment; the O-Node is a separate collector that executes a closed table of read operations over the management interfaces you already expose, and authenticates each response at collection. There is no passive adapter that merely watches an existing monitoring feed; collection is an operation the O-Node performs, and the record shows what that path can and cannot observe.
- It gets stronger air-gapped, not weaker. Verification can be performed offline by an authorized verifier holding the required verification material. Approval signatures can be checked with public keys; current observation and chain verification use symmetric keys and therefore place the verifier inside the trusted key boundary. Evidence can still cross the gap one way: an auditor without network access to the plant can check that every recorded action was approved, in order, unmodified — a check that authenticates the collector's records within the collector trust boundary, not the devices themselves.
- Provenance, not prevention. VIRP does not claim to stop attacks, and this page won't tell you it would have caught the last incident you read about. What it gives you is a verifiable record of authorized action, so anything unaccounted for is conspicuous by its absence.
Current limits, stated plainly: the read-only evidence path, an authenticated record of what your monitoring saw and of what it can and can't see, is the most exercised capability today. Governing writes on live OT equipment is design-complete but not yet demonstrated with a client. If you run a plant, what we can offer you today is visibility.
Regulated environments without AI
A bank or a utility that keeps AI off its network still needs to show an examiner what was requested, what the collector attempted, what response came back, what was approved, and that the record wasn't altered afterward within the collector trust boundary. VIRP produces that evidence whether or not a model is in the loop. What it does not do is certify that a response reflects the device's true state; it certifies that the designated collector authenticated this request-and-response pair.