Control Plane for Infrastructure Security & Access

Replace 8–12 tools.
Eliminate credentials.
Enforce everything.

SSH keys → certificates. Static passwords → rotated vault. Secrets in pipelines → ephemeral tokens.
Shared agent secrets → mTLS identity. Manual compliance → enforced. Sidecars → eBPF. 8–12 tools → 1.

A unified control plane for infrastructure — compute and network. One agent across Linux, macOS, Windows, FreeBSD, OpenBSD, NetBSD, ARM64 edge, and network switches — SONiC and Cisco IOS-XE. One policy engine. One audit trail. Versiera doesn't just observe your infrastructure. It enforces it.

From servers to switches — one control plane.
versiera-agent · live telemetry
$ versiera-agent --status
● agent v1.0.450 · connected
collector: collector.corp.internal:443
identity: mTLS · x509 leaf CN = agent UUID
platform: linux/amd64 (Ubuntu 24.04)
uptime: 14d 06h 22m

$ versiera fleet --network-devices
✓ sw-core-01 C9300L-24P-4X · IOS-XE 17.15.6 · IOx
24 ports · 3 VLANs · 61 endpoints · PoE 142/370W
✓ sw-leaf-04 SONiC · BGP established · LLDP 6 peers

$ versiera compliance --summary
✓ firewall COMPLIANT (pf template: prod-fw-v3)
✓ sshd COMPLIANT (template: cis-level2)
✓ dns COMPLIANT (resolvers verified)
⚠ users DRIFT DETECTED (1 prohibited account)
→ enforcement job queued · token: a3f8c2...

$ versiera vault --status
✓ vault sealed · 12 credentials managed
next rotation: svc_postgres in 2h 14m
ci/cd tokens: 3 active · 0 expired
$ _
COMPUTE →
🐧 Linux macOS 🪟 Windows 😈 FreeBSD 🐡 OpenBSD 🚩 NetBSD
NETWORK →
🛜 SONiC 🔀 Cisco IOS-XE
SCALE: 100,000+ AGENTS

One control plane.
Access. Visibility. Enforcement.

Not a bundle of security products that happen to ship together. One agent, one policy engine, one audit trail — doing three things across every layer of your estate.

Pillar 1
Access
Who can reach what, and with which credential — none of them permanent.
  • SSH Certificate Authority — host + user PKI
  • x509 Identity CA — mTLS agent authentication
  • Versiera Vault — credential storage & rotation
  • Ephemeral credentials — single-use CI/CD tokens
Pillar 2
Visibility
What is actually happening, from the kernel to the switch port.
  • eBPF TCP flow capture with kprobe RTT
  • Network flows, attack surface, IP intelligence
  • BGP, LLDP and device telemetry
  • Kubernetes pod-to-pod, no sidecar
  • Privileged session audit & traversal graph
Pillar 3
Enforcement
What is allowed — evaluated continuously and corrected, not just reported.
  • 10-module compliance engine
  • Configuration drift detection & remediation
  • Firewall and policy templates
  • Account governance — 3-layer enforcement
Across Servers Kubernetes Network Devices one agent · one console · one audit trail
The 8–12 tools, named

Replace fragmented security tooling.

Every enterprise runs some version of this list — separately licensed, separately deployed, separately audited, and integrated by hand. Each row is a procurement line item and a set of credentials that has to be managed somewhere. Versiera collapses the column.

TODAY
VERSIERA
SSH CA / PAM suite
Access control
Vault / secrets tooling
Credential lifecycle
SIEM / flow analysis
Network visibility
Config mgmt / compliance
Policy enforcement
Network management (NMS)
Device enforcement
EARLY ACCESS · VALIDATED ON CATALYST HARDWARE Platform Expansion · September 2026

Now extending to network infrastructure —
SONiC and Cisco IOS-XE.

The same agent that runs on your servers now runs inside your switches — natively on SONiC, and as an IOx container on Cisco Catalyst. One binary, one policy engine, one audit trail, validated on real hardware rather than in a lab emulator. Network devices stop being the estate nobody can inventory.

Start by eliminating static credentials on every system — including your switches.

SONiC
Native agent · Redis state
Port state · BGP · LLDP · DNS/NTP/Syslog templates
CISCO IOS-XE
IOx container · RESTCONF
Faceplate · switchports · MAC endpoints · PoE · sensors
SHARED
One fleet, one console
Same jobs, tags, groups, alerts and audit log as servers
From servers to switches — one control plane.

Versiera vs. the traditional stack.

Every row is a category of infrastructure tooling that enterprises currently buy, manage, and integrate separately. Versiera replaces the entire column.

Category Traditional Versiera
SSH accessstatic keysSSH CA · short-lived certificates
secretsenv vars · config filesephemeral tokens · zero stored secrets
credentialsstatic passwords · never rotatedvault rotation · time-limited checkout
observabilitysidecars / agentseBPF · kernel-level · no overhead
compliancemanual · quarterly auditsenforced · continuous · auto-remediated
platformsLinux + Windows (maybe)6 OS · BSD · ARM64 · edge native
tools8–121

Five components. One control plane.

Lightweight agent → central collector → security core → policy engine → operator console. Every component is purpose-built, self-hosted, and air-gap compatible.

📡
Agent
15MB · outbound-only
HTTPS to collector
All 6 OS + ARM64
Go binary
⚙️
Collector
Job dispatch · signing
compliance evaluation
alert engine · schedulers
Control core
🔐
Security Core
SSH CA · x509 mTLS CA
Vault (PAM) · Vault API
KRL · CRL · AES-256-GCM
Zero credentials
📏
Policy Engine
10 compliance modules
drift detection · enforce
3-layer account security
Enforcement
🖥️
Web Console
HTMX · real-time
fleet dashboard · audit
cert lifecycle · vault UI
Operator UI
DATA STORE
PostgreSQL + TimescaleDB
Hypertables for telemetry · 100K+ node capacity
TRANSPORT
TLS · Nginx reverse proxy
Agent → collector over HTTPS · outbound-only
DEPLOYMENT
Self-hosted · air-gap ready
Your infrastructure · your data · your control

Infrastructure is fragmented.
Security is paying the price.

Enterprise infrastructure security has been sold as a collection of specializations. One tool watches your servers. Another manages SSH keys. A third vaults credentials. A fourth enforces firewall policy. A fifth handles compliance. A sixth governs accounts.

Each of those tools is built by a different vendor, priced independently, maintained separately, and integrated by your team using brittle scripts and manual runbooks. None of them share context. None of them enforce anything across all your platforms. And none of them were built for the ARM64 edge infrastructure where your fleet is actually growing.

Attackers don't exploit your best tool. They exploit the gaps between them — the SSH key nobody revoked, the service password nobody rotated, the firewall rule that drifted six months ago, the stale account that was never cleaned up.

Versiera was built to fix this.

Not as another monitoring tool. Not as another compliance scanner. As a unified enforcement layer — one agent that observes, enforces, controls access, and eliminates permanent credentials across your entire fleet.

01
Tools are fragmented

8–12 tools means 8–12 trust boundaries, 8–12 audit logs, and 8–12 places for policy to diverge from reality. Security teams spend more time maintaining integrations than enforcing policy.

Nagios + CyberArk + StepCA + Ansible + ...
02
Enforcement is inconsistent

Most tools detect problems. Almost none fix them. Drift is found, a ticket is filed, and the misconfiguration persists for weeks. Versiera closes the loop: detect, remediate, verify, audit.

Observe → Enforce → Verify → Audit
03
Credentials are everywhere

SSH keys never revoked. Service passwords never rotated. CI/CD secrets hardcoded in env vars. When one is compromised, the blast radius spans the entire fleet — and nobody knows how long it's been exposed.

SSH CA + Vault + Vault API = zero static creds
04
The edge has no security layer

ARM64 edge nodes — Raspberry Pi clusters, industrial gateways, retail POS — are running real workloads with zero security governance. No enterprise platform was built for them. Until now.

15MB agent · ARM64 native · edge pricing
Versiera eliminates three root causes of breaches:
🔑
Static Credentials
→ Vault rotation + time-limited checkout
🔐
Unmanaged SSH Access
→ SSH CA + short-lived certificates
👁️
Invisible Lateral Movement
→ eBPF flow capture + K8s pod-level RTT

Security teams manage too many tools.
Versiera changes that.

The average enterprise runs 8–12 separate tools to cover what Versiera provides in a single platform. The result is gaps, drift, and operational overhead that grows with every new host.

🔥
Firewall Drift

Rules diverge across hundreds of hosts with no baseline, no compliance visibility, and no automated remediation path.

🔑
SSH Key Chaos

Authorized_keys files proliferate with no revocation mechanism, no audit trail, and no certificate lifecycle management.

👤
Account Sprawl

Stale accounts linger after offboarding across Linux, BSD, macOS, and Windows with no enforcement engine to act on them.

🐛
Patch Blindness

CVE exposure remains unknown until breach. Security updates go unapplied for months across the fleet without central visibility.

📜
Certificate Expiry

X.509 and SSH certificates expire silently, causing outages and authentication failures with no centralized alerting.

🌐
No Single Pane

Network flows, RTT, DNS, NTP, and syslog compliance are scattered across vendor-specific tools with no unified dashboard.

🔓
Privileged Credential Sprawl

Service accounts accumulate static passwords shared across systems. Manual rotation is skipped. Privileged credentials never expire. When one is compromised, the blast radius spans the entire fleet — and nobody knows for how long it's been exposed. This is the problem Versiera Vault was built to eliminate.

What Versiera eliminates.

Every row in this table was previously a separate tool, a separate vendor, a separate bill — and a separate gap in your security posture.

Problem ❌  Without Versiera ✓  With Versiera
SSH key sprawl unmanaged authorized_keys everywhere, no audit trail, no revocation centralized SSH CA · short-lived certs · KRL auto-distribution
Privileged credential reuse static passwords · shared service accounts · manual rotation never happens Vault rotation · time-limited checkout · break-glass access · full audit
Firewall config drift rules diverge across hundreds of hosts · manual audits every quarter enforced templates · drift auto-remediation · dual-hash detection
Stale account sprawl offboarded users linger on Linux, BSD, macOS, Windows for months 3-layer cryptographic enforcement · accounts locked, never deleted
Certificate expiry outages SSH + X.509 certs expire silently · no centralized alerting auto-renewal scheduler · 30-day + 7-day expiry alerts · audit log
ARM64 security blindspot no enterprise tooling supports Raspberry Pi, Jetson, or ARM blade clusters native ARM64 agent · 15MB binary · edge class pricing · full feature parity
CI/CD embedded secrets credentials stored in GitHub/GitLab secrets, env vars, and config files — permanently exposed Vault API tokens · single-use · time-limited · SHA-256 hashed · pipelines never store secrets
Invisible lateral movement no visibility into east-west traffic · attackers move between systems undetected eBPF flow capture · pod-to-pod RTT · service dependency mapping · anomaly detection
Tool sprawl 8–12 fragmented tools · 8–12 vendors · 8–12 contracts 1 platform · 1 agent · 1 console · 1 audit log

Everything in one place.

From agent deployment to certificate lifecycle, compliance enforcement to network visibility — Versiera covers the full surface of infrastructure security operations.

Privileged Access Management
CyberArk alternative
Versiera Vault

Credential storage, automated rotation, time-limited checkout, and dual-control approval — across all 6 platforms. AES-256-GCM encrypted. Scheduler-driven. Tamper-evident audit trail.

  • Automated password rotation for service accounts — all 6 platforms
  • Time-limited checkout with break-glass access & mandatory audit reason
  • Dual-control approval workflow for privileged credentials
Vault API
NEW
CI/CD Secrets

CI/CD pipelines never store secrets. Ever. Single-use, time-limited API tokens — no credentials in env vars or config files. SHA-256 hashed. Plaintext shown once.

Replace GitHub/GitLab secrets with
time-limited Vault tokens.
SSH PKI
SSH Certificate Authority

Full PKI for SSH. Host and user cert signing, KRL generation and auto-distribution, renewal scheduling. Enterprise-grade SSH PKI without another security product.

Core Platform
Unified Policy Engine

Template-based compliance for Firewall, SSHD, DNS, NTP, Syslog, Users, Sudo, service-account governance, service baselines, and agent configuration — assigned to agent groups, evaluated continuously, and enforced automatically. One workflow. Ten compliance domains.

  • Group-based template assignment (static & dynamic)
  • Continuous drift detection with severity scoring
  • Multi-channel alerting: Email · Webhook · Slack
  • Config snapshots, backups, and full audit log
Observability
eBPF Network Flows

TCP flow capture with kprobe-based RTT measurement. Business Application Monitoring baselines. IP intelligence scoring for fleet connections.

Kubernetes
NEW
Kubernetes eBPF Monitoring

Service mesh observability without a service mesh. Pod-to-pod RTT, flow visibility, workload identity resolution — no sidecar, no CNI changes. Single DaemonSet per node.

Governance
Account Enforcement

3-layer cryptographic enforcement: API gate → DB constraint → agent verification callback. Accounts locked automatically on policy violation — impossible to abuse even with DB access.

Agent Identity
NEW
Mutual TLS on every agent

A built-in x509 CA issues each agent its own identity certificate — leaf CN is the agent UUID. The collector can require a verified client certificate instead of trusting a bare agent ID. Per-group rollout, dual-trust while you migrate, CRL-backed revocation, and a break-glass kill switch.

Forensics
NEW
Privileged Session Audit & Traversal Graph

Who accessed what server, when, and with which credential — correlated across eBPF flows, auth logs, Vault checkouts, and firewall policy. The traversal graph then reconstructs identity movement hop by hop, so a bastion chain reads as one story instead of six disconnected logins.

  • Vault-backed vs. non-Vault sessions separated, not merged
  • Blocked attempts attributed per source against privileged ports
  • Answers both directions: where has this identity been, who touched this host
Vulnerability Management
CVE Tracking + Patch Management

Per-host CVE exposure tracking with CVSS scoring, security update scheduling, patch compliance dashboards, and X.509 certificate expiry monitoring across your entire fleet.

SSH CA + Vault + Vault API = Zero permanent credentials anywhere.
Short-lived SSH certificates from the CA. Rotated service passwords from Vault. Time-limited CI/CD tokens from the Vault API. The result: no credential in your fleet — human, service, or pipeline — is static, shareable, or permanent.
System Architecture

Not a feature set. A system architecture.

The same three pillars, seen from the inside — what each one is actually made of.

Pillar 1 — Access
Who can access what
Identity-based access across every system — no static keys, no permanent credentials, no embedded secrets.
  • SSH Certificate Authority (host + user PKI)
  • x509 Identity CA (mTLS agent authentication)
  • Versiera Vault (credential storage + rotation)
  • Vault API (CI/CD token management)
Pillar 2 — Visibility
What is happening
Kernel-level visibility into every connection — from bare metal servers to Kubernetes pods to switch ports.
  • eBPF TCP flow capture + RTT
  • Privileged session audit + traversal graph
  • Kubernetes pod-to-pod monitoring
  • Network device telemetry (SONiC · IOS-XE)
Pillar 3 — Enforcement
What is allowed
Continuous compliance evaluation with automatic remediation — not just detection, but enforcement.
  • 10-module compliance engine
  • 3-layer account enforcement
  • Firewall drift auto-remediation
6+2
Operating systems + 2 network OS
with native agent support
10
Compliance modules
in one platform
100K+
Agent capacity
by design
3
Security layers in
enforcement engine
15MB
Ultralight agent —
single binary, no runtime
Zero
Static SSH keys —
cert-based authentication
Native
ARM64 support —
Raspberry Pi to blade clusters
PLATFORM SPECIFICATIONS
100,000+ nodes
Designed and capacity-tested at this scale — PostgreSQL + TimescaleDB hypertables purpose-built for fleet telemetry
6 operating systems
Linux · macOS · Windows · FreeBSD · OpenBSD · NetBSD — tested on real infrastructure, not VMs
Air-gapped deployments
Fully functional with no internet connectivity — designed for financial, industrial, and government environments
15MB agent
Single binary · zero runtime
AES-256-GCM vault
Encryption key off-database
<15 min revocation
KRL auto-distribution to fleet
ARM64 native
Raspberry Pi to blade clusters

What makes Versiera different.

Six capabilities that competitors can't replicate — because they each require separate products, or have never been built.

🌐
BSD + Linux + Windows + macOS

The only enterprise security platform with first-class support for FreeBSD, OpenBSD, and NetBSD — including pf template management, NPF compliance, and POSIX-compatible installers. CrowdStrike doesn't touch BSD. CyberArk barely does.

Unique capability
💪
ARM64 Native — Edge Ready

15MB single binary. Zero runtime dependencies. Full feature parity on Raspberry Pi 4 through enterprise blade clusters. No competitor offers this. The ARM64 security gap is a $4B+ untapped market.

Market gap
🔑
SSH CA Built In — Not an Add-On

Full PKI for SSH: host certs, user certs, KRL auto-distribution. CyberArk charges a separate license for this. StepCA requires a separate product entirely. Versiera includes it at every paid tier.

Included, not extra
🔐
Vault Built In — No Separate PAM Product

Enterprise-grade PAM — encrypted storage, automated rotation, time-limited checkout, break-glass, full audit trail — in the same platform as your compliance engine and SSH CA. CyberArk costs $150K+ standalone. Versiera includes it at Professional.

CyberArk alternative
Enforcement, Not Just Monitoring

Dashboards don't secure infrastructure — enforcement does. When an account violates policy, it is locked. When a firewall drifts, it is remediated. The 3-layer cryptographic enforcement engine is tamper-resistant by design, not policy.

Active security
🏠
Self-Hosted. Air-Gap Ready.

No cloud dependency. No telemetry phone-home. No data leaves your environment. Runs entirely on infrastructure you control. Financial institutions and industrial operators require this. SaaS-based competitors cannot offer it.

Sovereign deployment

You own the infrastructure.
You own the data.

Versiera is fully self-hosted. There is no Versiera cloud, no telemetry reporting, no vendor dependency. This is a deliberate design choice that matters to financial, industrial, and government buyers.

🏠
Self-Hosted
Collector, web console, and database run on your infrastructure — dedicated server, VM, or bare-metal.
🔒
No Telemetry
Zero calls to external services. No usage tracking. No fleet data leaves your environment under any circumstances.
✈️
Air-Gap Ready
Full functionality in isolated networks with no internet connectivity. Supported at Enterprise tier — standard for regulated industries.
🛡️
Sovereign Deployment
Agents make outbound HTTPS connections only — no inbound firewall rules. No vendor access to your fleet data, ever.
Designed for:  Financial institutions (PCI-DSS, SOC2) · Industrial OT (IEC 62443) · Government (air-gapped requirements) · Healthcare (HIPAA) · Any organization that cannot place infrastructure telemetry in third-party hands.

Built for Edge and
ARM Infrastructure.

ARM64 is the fastest-growing segment of enterprise compute — and the most unprotected. Every competitor was designed for x86 data centre servers. Versiera is the only security platform built for where the fleet is actually going.

🍓
The Raspberry Pi is no longer a hobbyist board.
Pi CM4/CM5 modules run Heathrow Airport's digital signage, PLC controllers, and medical edge compute. ARM blade clusters power retail POS, logistics telemetry, and industrial AI inference. They run real workloads — with zero security governance because enterprise tools never followed them there.
$1/node
Edge class pricing
🍓
Raspberry Pi & SBC Clusters

Native ARM64 agents run on Raspberry Pi 4/5, CM4/CM5, Orange Pi, and Jetson clusters. The 15MB single-binary agent imposes negligible overhead — no container runtime, no JVM, no interpreter. Full feature parity with x86, not a stripped-down port.

🏭
Industrial & OT Environments

Factory-floor edge compute, PLCs with Linux or BSD embedded OS, and SCADA-adjacent systems that are networked but never governed. Versiera brings IEC 62443-aligned firewall enforcement, account governance, and Vault PAM to OT environments with no security tooling at all.

🛒
Retail, Logistics & POS

Thousands of point-of-sale nodes, distribution hubs, and cold-chain gateways — ARM-based, geographically dispersed, zero on-site IT. Versiera enforces consistent firewall policy, NTP sync, credential rotation, and account governance across every location from one console.

15MB
Agent binary — zero runtime dependencies
$1/node
Edge class rate — ARM64 ≤4GB RAM
100%
Feature parity — not a stripped-down port
0
Competitors with equivalent ARM64 coverage
TARGET INDUSTRIES
🏦 Financial Institutions 🛒 Retail Infrastructure 🚚 Logistics Networks 🏭 Industrial OT 🏥 Healthcare Edge 📡 Telecom Edge

The distribution moat
nobody else has.

Hardware manufacturers are the fastest path to fleet-scale adoption. Versiera Community bundled in firmware means the agent is already running before the customer makes a purchasing decision.

OEM Model
Bundled in Firmware

Blade cluster vendors (Turing Pi, Compute Blade, OnLogic), industrial compute manufacturers (Beckhoff, Kontron, Axiomtek), and ARM-based hardware partners license Versiera Community as a bundled management layer. End customers deploy hardware with the agent already running — and see immediate value at boot.

  • Zero cold-start for the customer — agent running on day 1
  • OEM partner receives reseller margin on tier upgrades
  • Co-marketing support & validated hardware integration
  • Pre-qualified leads at fleet scale from hardware sales
DISTRIBUTION FLYWHEEL
01 Hardware vendor ships Versiera Community in firmware
02 Customer boots hardware → agent auto-connects to console
03 Customer sees fleet telemetry → value self-evident
04 Upgrade to Standard or Professional → OEM receives margin
TARGET HARDWARE PARTNERS
⚡ Turing Pi 🔲 Compute Blade 🍓 Raspberry Pi CM 🏭 OnLogic ⚙️ Kontron 🔧 Axiomtek 🖥️ Beckhoff

Contact sales to discuss OEM partner terms →

Built for the "Fleet of Many."

When you're managing hundreds or thousands of distributed nodes — across data centres, retail sites, edge locations, and industrial clusters — consistency and enforcement aren't optional. Versiera was designed specifically for this scale.

Edge Observability
eBPF Network Flows for ARM Clusters

Monitor east-west traffic within high-density blade clusters. Detect lateral movement and RTT latency at the kernel level — without heavy sidecars, service meshes, or network taps. Works natively on ARM64 nodes including Raspberry Pi clusters and industrial compute hardware.

  • kprobe-based TCP RTT measurement per connection
  • IP intelligence scoring for every remote endpoint
  • Business Application Monitoring baselines
  • No network reconfiguration required
Security
Cluster-Wide SSH CA

Eliminate manual management of authorized_keys across every node in the fleet. Issue short-lived, identity-based certificates for entire racks of nodes instantly. KRL auto-distribution ensures revoked credentials are blocked fleet-wide within 15 minutes of compromise detection.

  • Bulk signing for hundreds of hosts in seconds
  • Ed25519 certificates — compact and fast on ARM
  • Automatic renewal — no manual cert rotation
  • Audit trail for every certificate event

Ready to see Versiera in action?

Request a live demo or a technical deep-dive. We'll walk through the platform with your actual infrastructure in mind.

Everything you need.
Nothing you don't.

Versiera uniquely combines: SSH CA, mTLS agent identity, Vault (PAM + CI/CD), eBPF observability, privileged session audit, an enforcement engine, multi-OS including BSD, ARM64 edge, and network devices running SONiC or Cisco IOS-XE. No major vendor does all of these. Versiera does.

Category Definition
Control Plane for Infrastructure Security & Access
SSH CA + x509 mTLS identity + Vault + CI/CD secrets + eBPF observability + session audit + enforcement engine + multi-OS (BSD included) + ARM64 edge + network devices. No major vendor combines all of these. Versiera does.

Fleet-Grade Features.

eBPF
Deep Network Visibility

Observe all traffic within edge clusters at the kernel level. eBPF-based TCP flow capture with kprobe RTT measurement — no sidecars, no agents-within-agents, no network reconfiguration. Works on amd64 and ARM64.

PKI
Integrated SSH CA

Eliminate manual management of authorized_keys with short-lived, identity-based certificates. Host and user cert signing, KRL auto-distribution, and renewal scheduling — Enterprise-grade PKI built into the platform at no extra cost.

NATIVE
BSD Support

First-class support for FreeBSD, OpenBSD, and NetBSD — including pf template management, NPF compliance, BSD-native rc.d service integration, and POSIX-compatible installers. The only enterprise security platform that takes BSD seriously.

Fleet visibility across every platform

Real-time telemetry from Linux, macOS, FreeBSD, OpenBSD, NetBSD, Windows — and now SONiC switches — unified in one console.

Compute
ARM64
🐧
Linux
Debian · Ubuntu
Alpine · RHEL
amd64 + ARM64
M1/2/3
🍎
macOS
Silicon & Intel
macOS 11+
launchd managed
🪟
Windows
Server 2016–2022
Workstation
SCM service
ARM64
😈
FreeBSD
13.x · 14.x
Enterprise Networking
pf firewall
🐡
OpenBSD
7.x · Security focus
pf enforcement
hardened default
ARM64
🚩
NetBSD
9.x · 10.x
Industrial Edge
NPF firewall
Network Infrastructure
NOW AVAILABLE
🛜
SONiC
Open-source NOS
BGP · LLDP · ACL
Early access
Unified control plane across compute and network.

The same 15MB agent runs natively on SONiC switches. Same policy engine. Same audit trail. Network devices are no longer managed as isolated systems — they live in the same control plane as the rest of your fleet.

Policy → Template → Enforce

Define once. Assign to groups. Evaluate continuously. Enforce automatically.

1
Define
Create policy templates for each module
2
Assign
Target static or dynamic inventory groups
3
Evaluate
Scheduler compares live config vs template
4
Alert
Email · Webhook · Slack notifications
5
Enforce
Deploy remediation jobs to fix drift
Module Engines / Platforms What's managed Status
Firewallpf · NPF · iptables · nftables · WFWTemplate-based rule sets with dual-hash drift detection. Supports dynamic sets without false positives.Live
SSHD ConfigLinux · macOS · FreeBSD · OpenBSD · NetBSDMaxAuthTries, PermitRootLogin, AllowUsers, cipher suites, key types, port settings.Live
User AccountsAll 6 platformsProhibited account detection with 3-layer cryptographic enforcement. Accounts locked, never deleted.Live
Sudo PolicyLinux · macOS · BSDsudoers template management, NOPASSWD rules, command whitelisting, compliance snapshots.Live
DNS Resolverresolv.conf · netplan · systemd-resolvedNameserver addresses, search domains, resolver options. Drift detection and correction jobs.Live
NTPntpd · chrony · Windows TimeTime server sources, stratum requirements, drift file configuration.Live
Syslogrsyslog · syslog-ng · BSD syslogdRemote log targets, facility/severity filtering, protocol (UDP/TCP/TLS) enforcement.Live
Svc Acct GovernanceAll 6 platformsService accounts held to declared ownership, shell, login policy and Vault coverage. Surfaces the accounts nobody owns.Live
Service Baselinesystemd · launchd · rc.d · SCMDeclared running/stopped/enabled state per service. Drift raises a finding; remediation restores the baseline.Live
Agent ConfigAll platforms incl. network devicesThe agent's own configuration under template control — intervals, log rotation, restart policy — pushed and verified like any other module.Live
DNS · NTP · Syslog (SONiC)SONiC network OSThe same three templates evaluated against switch configuration through the SONiC adapters — one policy surface for servers and switches.Live

Enterprise SSH PKI, Built In

Enterprise SSH PKI without a second security product to buy, deploy and audit. Ed25519 to RSA, host to user certs, KRL to auto-renewal — all in the platform.

🖥️
Host Certificate Signing

Agents collect SSH host public keys automatically. Bulk signing across the fleet. Deployed certificates update sshd_config with HostCertificate directive. Eliminates known_hosts sprawl.

Ed25519ECDSARSA
🔐
User Certificate Issuance

Issue per-user certs with principals mapped to Unix usernames. Source address restrictions, force-command option. 8-hour interactive sessions or up to 90-day service accounts.

PrincipalsSource restrictForce-command
🚫
Key Revocation Lists

KRL auto-regenerated every 5 minutes when new revocations exist. Deployed to all affected agents. sshd_config updated with RevokedKeys directive. Compromise-to-blocked in under 15 minutes.

Auto-regenFleet deploySerial tracking
🔄
Auto-Renewal Scheduler

Certificates renewed automatically before the configurable expiry window (default 30 days). No manual intervention, no outages. All renewal actions recorded in the audit log.

Hourly schedulerConfigurable windowAudit trail
NEW

Your agents prove who they are.
Not just claim it.

Most fleet agents authenticate with a shared secret or an agent ID. Anything that learns the ID can impersonate the host. Versiera issues every agent its own certificate from a built-in CA and lets the collector require it — mutual TLS, with the leaf CN bound to the agent UUID.

The hard part of mTLS is not the crypto. It's the rollout.
Versiera treats that as the actual product.
🪪
Built-in Certificate Authority

Generate a CA in the console; the newest active CA becomes the default signer. The root is exported to Nginx for verification and downloadable as PEM. Private keys are never stored for issued certificates. Retire a CA by deactivating it — certificates it already signed keep validating until they expire or are revoked.

Ed25519 / ECDSA / RSAPEM + DER exportSoft retire
🎚️
Per-Group Enforcement, Dual-Trust by Default

Enforcement is off until you turn it on, and then group by group. While the master switch is off the collector accepts either a UUID or a presented certificate, and coverage is measured so you can confirm readiness before flipping anything. No fleet-wide big bang, no morning where half the estate goes dark.

Dual-trustCoverage preflightGroup scoped
🧯
Break-Glass Kill Switch

One control forces enforcement off fleet-wide during an incident, and it is loud and audited when active. Your enforce configuration is preserved rather than reset — clear the flag when the incident closes and the previous posture returns. A clock guard catches the certificate-validity failure mode that time skew produces.

Preserves configAuditedClock guard
📜
Revocation That Tells the Truth

The revocations view separates serials that are published in a CRL from those that are merely marked revoked in the database — because only the first is actually enforced. Pending revocations are labelled as not-yet-blocking rather than counted as done. CRLs regenerate on a schedule and republish to Nginx.

Published vs pendingRFC 5280 reasonsNginx distribution
♻️
Enrollment & Auto-Renewal

Hosts enrol through the reconciler and are re-provisioned automatically after a revoke-and-reissue. A scheduler re-mints any identity certificate entering its renewal window, with configurable window, renewed validity, and scan interval. An enrollment grace path prevents the deadlock where enforcement locks out a host that was never issued a certificate.

Auto re-enrollRenewal schedulerGrace path
📖
Attributable Audit Trail

Every CA operation — signing, revocation, CRL generation, CA creation and deactivation — is written by the collector with operator identity, source, and timestamp. Read-only from the console: entries cannot be edited or deleted through the UI. Rejected connections are recorded with their reason, so a failing agent is diagnosable rather than merely absent.

Immutable from UIRejection reasonsFull lifecycle
Not to be confused with X.509 certificate monitoring

Versiera does both, and they are separate features. The Identity CA above issues certificates to your agents. X.509 Certificate Monitoring watches the SSL/TLS certificates on your endpoints — discovery, chain validation, and expiry alerting against configurable warning and critical thresholds.

No permanent credentials.
Anywhere.

Enterprises rely on static credentials, shared passwords, and manual rotation. Versiera Vault eliminates all of it — automated, audited, time-limited credential access across every system in your fleet.

SSH CA + Vault + Vault API = Zero permanent credentials anywhere in your fleet.
The SSH CA issues short-lived certificates for server access. Vault rotates and controls service account passwords. The Vault API provides time-limited tokens so CI/CD pipelines never store secrets. Together they eliminate the three root causes of the widest enterprise breaches. This is what CyberArk sells as a $150K+ engagement. It's included in Versiera Professional.
Versiera Vault
Credential Storage, Rotation & Checkout
🔐
Encrypted Credential Storage

Service account credentials stored with AES-256-GCM encryption. Encryption key lives in server configuration — never in the database. Credentials are never transmitted in plaintext or logged in any form.

AES-256-GCMKey rotationZero plaintext
🔄
Automated Password Rotation

Scheduler-driven rotation for Tier 1 service accounts across all platforms. Platform-native password change commands: usermod on Linux, net user on Windows, pw on FreeBSD, pwpolicy on macOS. All reversible, none deleted.

All 6 platformsScheduler-drivenReversible
⏱️
Time-Limited Checkout

Credentials issued with configurable expiry windows. Checked-out credentials automatically revoked at expiry. Break-glass access for emergency scenarios with mandatory reason capture and immediate alert notification.

Expiry windowsBreak-glassAuto-revoke
📋
Complete Audit Trail

Every vault operation — creation, checkout, rotation, revocation — is recorded with operator identity, source IP, timestamp, and outcome. Tamper-evident audit log with configurable retention for compliance requirements.

Full audit logIdentity trackingCompliance ready
Versiera Vault API
NEW
CI/CD Tokens & Programmatic Access
CI/CD pipelines never store secrets. Ever.

Replace GitHub Actions secrets, GitLab CI variables, and AWS Secrets Manager with single-use, time-limited Vault tokens. No credentials in env vars. No secrets in config files. No permanent exposure.

🔑
Single-Use API Tokens

Pipelines request a credential by presenting a time-limited, single-use API token. The token is consumed on first use and cannot be replayed. SHA-256 hash stored server-side — plaintext shown once at creation. No secrets persist anywhere in your CI/CD pipeline.

Single-useTime-limitedSHA-256 hashed
Dual-Control Approval Workflow

Sensitive credentials require operator approval before the token is issued. Approval request, approval grant, and token usage are all recorded in the audit trail. For critical infrastructure credentials, no pipeline can self-serve.

Approval workflowAudit trailZero stored secrets
NEW

Who accessed what, when,
and with which credential.

Session logs live in one system, credential checkouts in another, and network flows in a third — so answering a simple audit question means joining three exports by hand. Versiera correlates them at ingest: eBPF flows, authentication events, Vault checkouts, and firewall policy verdicts against a single session record.

🔎
Correlated Session Record

Every privileged session carries source, target, protocol, authentication method, duration, byte volume, and the firewall verdict that allowed or blocked it. Sessions are classified as allowed, blocked, or unknown-verdict — the third bucket exists deliberately, because pretending a partial correlation is a clean one is how audits go wrong.

SSH · RDP · WinRM · SMBLive + historicalAnomaly flags
🗝️
Vault-Backed vs. Everything Else

Sessions opened with a Vault-issued credential are separated from those that were not. That single split is the difference between "we have a PAM product" and "we can show which access actually went through it" — and the non-Vault rows are precisely the follow-up list.

Checkout correlationExcess-duration viewException list
🕸️
Traversal Graph

Forensic reconstruction of identity movement across the fleet. A bastion chain — laptop to jump host to database server, changing username at each hop — reads as one connected path instead of three unrelated logins. Ask it both ways: where has this identity been, or who touched this host.

Bastion-hop resolutionPostmortem modeClick to pivot
🌐
Fleet Graph & Identity Mappings

The fleet-wide view of identity movement, plus the mapping layer that ties local usernames on different hosts to the same human. Without it, jsmith, j.smith and svc_deploy look like three people.

Identity resolutionFleet-wide viewTime-windowed
🛑
Blocked-Attempt Attribution

Denied connections against privileged ports are bucketed per source with the matched rule and target host retained. Aggregation reduces noise without collapsing attribution — you still know which source, against which host, on which rule.

Per-source historyMatched ruleInbound-only scope
📋
Evidence Frame for Auditors

The session view is mapped to the controls an auditor asks about — logical access controls, least privilege, and system-level monitoring — with the specific rows that evidence each one. Export the window, not a screenshot of a dashboard.

CC6.1 · CC6.2 · CC7.2Window exportNamed identities
NEW

Pod-level visibility.
No sidecar. No service mesh.

Detect latency, map service dependencies, and identify lateral movement — without sidecars or service mesh overhead.

Service mesh observability without a service mesh. One DaemonSet per node. Zero application changes. Works with any CNI.

Why This Matters
Detect latency regressions instantly
🔍
Identify noisy neighbours across namespaces
🗺️
Map service dependencies automatically
🛡️
Detect lateral movement between pods
📡
Pod-to-Pod Flow Matrix

Every TCP connection between pods captured with source workload, destination workload, namespace, protocol, byte count, packet count, and RTT. Sortable flow matrix showing top talkers — immediately reveals unexpected cross-namespace communication.

Workload identityNamespace-awareService mapping
RTT Heatmap

Per-workload-pair RTT aggregated into 5-minute buckets via TimescaleDB continuous aggregate. Avg, min, max, and standard deviation surfaced for every path. Jitter detection via stddev threshold flags unstable paths before they become outages.

5-min bucketsAvg/Min/Max/StdDevJitter detection
🔔
RTT Threshold Alerting

Three default alert rules — warning (25ms avg), critical (45ms avg), jitter (10ms stddev) — integrated into the existing Versiera alert engine. Auto-resolves when RTT normalizes. Email, webhook, and Slack notifications with full workload context.

Warning 25msCritical 45msAuto-resolve
🗂️
Namespace Traffic Analysis

Cross-namespace flows identified and classified as Internal or Cross-NS — immediately highlighting unexpected service communication paths. Traffic volume bars, total flows, and search make audit and policy review fast and visual.

Cross-NS detectionTraffic volumePolicy audit
How it works — no kernel changes required
① eBPF Capture

kprobe on inet_sock_set_state fires on every TCP event. CgroupID, IPs, and RTT captured at kernel level — zero overhead on application code.

② Pod Resolution

/proc/<pid>/cgroup path parsed to extract pod UID. client-go informer cache maps UID to pod name, namespace, workload, and node — all in-process, no API calls per flow.

③ Flow Enrichment

Flow reports include full pod identity fields. Collector writes to kubernetes_flows hypertable. TimescaleDB compresses after 7 days, drops after 90.

④ Alerting

kubernetes_flow_rtt_5min continuous aggregate evaluated hourly. Threshold violations fire alerts with workload pair, cluster name, and node context — resolved automatically when RTT normalizes.

NEW

The agent runs inside the switch.

Not an SNMP poller pointed at it from a management VLAN. The same Versiera agent, built once as a network variant, running natively on SONiC and as an IOx application container on Cisco Catalyst — reading the chassis through the platform's own management interfaces and reporting into the same fleet as your servers.

An agent inside the chassis does not lose its arm when reachability breaks.
That is the entire argument for putting it there.
🔀
Cisco Catalyst — Validated on Hardware

Deployed as an IOx container and validated end-to-end on a Catalyst C9300L-24P-4X running IOS-XE 17.15.6 — not an emulator. Chassis serial, model and software version; every interface with counters, speed, duplex, media type and VLAN membership; environment sensors with vendor-supplied thresholds; PoE budget and allocation; control-plane memory; flash storage.

RESTCONF · NETCONFSNMP · CLIC9300 / 9400 / 9500
🛜
SONiC — Native, Redis-Backed

Runs directly on SONiC-based switches, reading device state from the SONiC Redis socket rather than scraping a CLI. Port state, BGP session status through vtysh, and LLDP neighbours land in the same inventory as everything else. DNS, NTP and Syslog compliance templates evaluate against switch configuration through SONiC adapters.

Redis stateBGP · LLDPShared templates
🔲
Vendor-Accurate Faceplate

The device page renders the actual front panel — correct port count, correct uplink module, correct physical ordering — with live link state, throughput and error rates per port. Hover any port for its detail. Grid and faceplate views, sortable by port order or by busiest.

Live port stateThroughput · errorsQueue drops
🔌
Switchports, VLANs & Endpoints

Access and trunk configuration per port with VLAN membership, plus the MAC address table decoded into an endpoint inventory — what is actually plugged into which port. A bundled OUI registry resolves manufacturers offline, with longest-prefix matching down to /36 for the registry blocks that need it. Move detection surfaces endpoints that changed port.

MAC bindingsOffline OUIMove detection
PoE, Sensors & Neighbours

Per-port PoE draw against the chassis budget, environment sensors carrying the vendor's own thresholds rather than invented ones, and LLDP/CDP neighbour discovery. The unsaved-config flag gives an immediate partial answer on configuration divergence — running versus startup — before full drift detection lands.

Per-port PoEVendor thresholdsLLDP / CDP
🧩
Same Fleet, Same Everything

Network devices are ordinary fleet members: same tags, static and dynamic groups, jobs, alerts, agent-config template push, x509 identity and audit log. No second console, no separate inventory to reconcile, no export step between the network team's tooling and the security team's.

Tags & groupsOne audit logOne console
Where this honestly stands today

Everything described above is the read plane, and it is validated on real hardware. Write-side enforcement on IOS-XE — pushing NTP, syslog, SNMP, AAA and banner configuration back over NETCONF, IOS-XE local user management, and ACL policy — is designed and reachable but not yet shipped. Two capabilities are deliberately compiled out of the network build: security patch management and internet speed testing, because both would report the container's posture and present it as a fact about the switch. Declining to answer is more honest than answering wrongly.

Known blocked: ISR 4000 series, which needs 8 GB DRAM and internal SSD storage before IOx is available at all.

Defense-in-Depth by Design

The account enforcement engine uses three independent layers. An attacker with full DB access and full API access combined cannot trigger unauthorized enforcement actions.

01
API Gate

The restricted_job_types table blocks enforcement job types from any HTTP API endpoint. Only the scheduler process (direct DB insert) can create these jobs. Returns 403 Forbidden to any external attempt.

POST /api/jobs → blocked for users_enforce_lock
02
Database Constraint

A CHECK constraint enforces created_by = 'users_enforcement_scheduler'. Even with direct DB access, rows cannot be inserted with a different creator. Each action receives a cryptographic 32-byte verification token.

INSERT with wrong created_by → constraint violation
03
Agent Verification Callback

Before locking any account, the agent calls back to POST /api/users/enforce/verify with job_id + token. The collector validates token authenticity, originator identity, and a 2-hour freshness window. All three must pass.

Verify: job_id + token + created_by + timestamp < 2h

And everything else that ships with it.

The sections above are the headline capabilities. These are the rest of the console — each one live, each one sharing the same agent, inventory, groups, alerting and audit trail.

Flows
Attack Surface

Every listening service across the fleet, ranked by exposure — what is reachable, from where, and whether any policy actually constrains it.

Flows
IP Intelligence

Scoring and enrichment for every external address your fleet talks to, so unexpected egress is visible without a separate threat-intel product.

Diagnostics
MTR Paths & Ping Monitor

Scheduled path and reachability probes run from the agent itself. Per-hop loss, jitter and latency from where the problem actually is, not from a central prober.

Lifecycle
Host Enrollment

Guided onboarding that tracks each host through SSH-CA and x509 identity provisioning, with the failure state named rather than hidden behind a spinner.

Lifecycle
Deployment & Upgrades

Push and upgrade agents from the console across every platform, with per-version rollout views, rollback evidence and persistent-binary upgrade on constrained devices.

Lifecycle
Decommission

A defined exit path — retire a host, revoke its certificates, and stop it appearing as a false gap in coverage metrics.

Inventory
Groups & Tag Rules

Static and dynamic groups driven by rule-based tagging. Assign policy to a rule, not to a list you have to remember to update.

Inventory
Services

Fleet-wide service inventory with per-host detail, feeding the service-baseline compliance module.

Firewall
Rule Builder

Build and review firewall policy visually with impact preview before anything is pushed, across pf, NPF, iptables, nftables and Windows Firewall.

Monitoring
Business Application Monitoring

Baselines for the flows that matter to a named application, so a regression is reported in business terms rather than as an anomalous port.

Monitoring
Network Diagrams

Editable topology diagrams built from observed inventory rather than drawn by hand and left to rot.

Certificates
X.509 Monitoring

Discovery and expiry alerting for the SSL/TLS certificates on your endpoints, with configurable warning and critical thresholds.

Access
Authorized Keys

Fleet-wide visibility of every remaining authorized_keys entry, plus migration tracking as you move hosts onto certificates.

Operations
Alerts & Audit Log

One alert engine across every module — email, webhook and Slack — and one immutable operator audit log covering every console action.

One platform replaces five.

CrowdStrike watches. Ansible configures. CyberArk vaults. Splunk logs. Versiera does all of it — in a single 15MB agent, across every OS you run, including BSD and ARM64 edge hardware none of them support.

Capability Versiera CrowdStrike
Falcon
Ansible /
Puppet
CyberArk
PAM Suite
Splunk
Enterprise
HashiCorp
Vault
Fleet Monitoring — 6 OS
Linux, macOS, Windows, FreeBSD, OpenBSD, NetBSD
Linux/Win/Mac onlyAgent requiredLog-only
ARM64 & Edge Native
Raspberry Pi, blade clusters, industrial IoT
Partial
Firewall Compliance
pf · NPF · iptables · nftables · WFW — drift detection + remediation
Config mgmt only
SSH Certificate Authority (PKI)
Host + user certs, KRL, auto-renewal — built in
(add-on)
Privileged Access Management (Vault)
AES-256-GCM encrypted vault, rotation, checkout, audit
(core product)(secrets only)
Account Enforcement (3-layer)
Cryptographic verification — API + DB + agent callback
No enforcement
eBPF Network Flows + RTT
Kernel-level TCP capture, IP intelligence, BAM baselines
NDR add-onLog ingest only
Kubernetes Pod-Level eBPF
Pod-to-pod RTT, flow matrix, workload identity — no sidecar
CI/CD Secrets Management
Single-use, time-limited API tokens — no stored secrets in pipelines
Separate product(core)
DNS / NTP / Syslog Compliance
Template-based, continuously evaluated, auto-remediated
Config mgmt only
Vuln & Patch Management
CVE tracking, CVSS scoring, patch compliance dashboards
mTLS Agent Identity (x509 CA)
Per-agent certificates, per-group enforcement, CRL revocation — built in
PKI engine only
Privileged Session Audit + Traversal
Flows + auth + Vault + firewall correlated; bastion-hop reconstruction
Detections onlySession recordingManual correlation
Network Device Agent — SONiC / IOS-XE
Runs on the switch; ports, VLANs, MAC endpoints, PoE, sensors
Log ingest only
BSD Platform — FreeBSD / OpenBSD / NetBSD
First-class pf, NPF, rc.d — not an afterthought
Limited
Single unified platform
All of the above. One agent. One console. One bill.

Competitive assessments based on publicly available product documentation as of 2026. CyberArk PAM Suite includes SSH key management as a separate licensed component. HashiCorp Vault manages secrets and dynamic credentials but does not perform host compliance, fleet monitoring, or SSH host certificate signing.

One security control plane across open and proprietary network operating systems.

Network
Infrastructure.

Access, visibility and enforcement reach the network itself — not through an external poller, but through an agent running on the device. Native on SONiC. An IOx container on Cisco Catalyst. Same control plane either way.

🛜
SONiC
Native Linux agent
CONFIG_DB · STATE_DB · vtysh
🔀
Cisco IOS-XE
IOx container
RESTCONF · NETCONF · SNMP
More platforms
Juniper in development
One control plane, any NOS
From servers to switches — one control plane.
Why Now

The last unmanaged perimeter.

Network devices remain one of the last parts of infrastructure still relying on static credentials, manual configuration, and fragmented tooling. As SONiC adoption grows, the need for a unified control plane becomes critical.

Start by eliminating static credentials on every system — including your switches.

The full Versiera platform —
now on your network switches.

Access control, visibility, and enforcement — the same three pillars Versiera provides for servers, delivered natively on SONiC-based network infrastructure.

Pillar 1 — Access Control
Eliminate static credentials
Switches have been the worst offenders for permanent, shared credentials — enable passwords, admin accounts, shared SSH keys across thousands of devices. Versiera brings the same SSH CA that governs your servers to the network itself.
  • SSH CA on switches — short-lived certificates
  • Host + user cert signing, KRL auto-distribution
  • Centralized revocation — compromise-to-blocked in <15 min
  • SNMP community strings rotated via Vault
Pillar 2 — Observability
Unified visibility
Port state, BGP sessions, LLDP neighbors, interface utilization, and configuration state — surfaced in the same console, under the same agent identity, as every server in your fleet. One dashboard. One query model.
  • Port status & link utilization (live from STATE_DB)
  • BGP neighbor state via vtysh
  • LLDP adjacency map
  • Physical environment — temp, fans, PSUs
Pillar 3 — Enforcement
Policy enforcement
Configuration drift on network devices is a silent risk that traditional NMS tools detect but rarely fix. Versiera brings the same template-based compliance and drift remediation to SONiC that it already provides for servers.
  • Configuration drift detection across DNS · NTP · Syslog · SNMP · SSH
  • Security baseline enforcement
  • Template-based policy assignment
  • Continuous evaluation · automatic remediation
🔑
In practice
One certificate. Server and switch.

A DevOps engineer gets temporary SSH access to both a server and a switch using the same certificate — no shared credentials, no manual provisioning.

Network devices are still managed
as isolated systems.

Every enterprise runs two parallel security programs. One for compute — EDR, vault, compliance, SSH CA. And another for the network — separate NMS tools, separate credential systems, separate audit trails, separate on-call rotations. The two worlds rarely share context.

That split made sense when network devices ran proprietary, closed operating systems. It doesn't anymore. SONiC is Linux. It runs real processes, has a real filesystem, speaks the same protocols as the servers it connects. There's no technical reason for it to sit outside your control plane.

Versiera brings network devices into the same control plane as the rest of your infrastructure.

One agent. One policy engine. One audit trail. Compute and network, governed as a single fleet.

❌ Without Versiera
Two parallel programs
  • Separate NMS tool polling via SNMP from outside
  • Shared enable passwords · rarely rotated
  • Config drift discovered during outages
  • Network team · server team · no shared context
  • Audit logs scattered across 4+ systems
✓ With Versiera
One unified control plane
  • Agent runs on the switch — inside-out visibility
  • SSH CA · Vault-rotated SNMP · no static creds
  • Drift caught continuously · auto-remediated
  • Switches alongside servers in one console
  • Single audit trail · compute and network

The Network Device page,
live from a SONiC switch.

Port state, BGP neighbors, LLDP adjacencies, ACL rules, and configuration drift — surfaced inside-out from the agent running natively on SONiC. Below is the actual Versiera UI.

versiera.corp.internal/agents/…/network-device
Dashboard  ›  Agents  ›  sonic-vs-01  ›  Network Device

sonic-vs-01

SONiC
← Back to Agent
🖧
Force10-S6000 LEAF ROUTER
SONiC master.1086014-6c8d17dde · ASIC vs · Platform x86_64-kvm_x86_64-r0 · ASN 65100 · Mgmt 10.22.112.45 · Uptime 0d 06h 03m
Collected 2026-04-23 05:09:39 EDT
Port Status
32 total
32 UP 0 ADMIN DOWN
BGP Sessions
0 / 32
established
LLDP Neighbors
0
no adjacencies
ACL Rules
0
installed
Config Drift
4 / 6
services configured
Ports · 32
Up Admin down
DELL FORCE10 S6000 32× QSFP+ · 40GbE
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
MGMT  ·  eth0  ·  10.22.112.45
Link up Link up · high util Admin down / no link Hover a port for details
BGP Neighbors · 32
Click a row to expand
Neighbor Remote AS State Rx / Tx Pfx Uptime
10.0.0.49 64009 eBGP ACTIVE 0 / 0 never
Local Iface
10.0.0.48
Hold / Keepalive
180s / 60s
MD5 Auth
NO
Session Type
eBGP
Prefixes Received
0
Prefixes Advertised
0
Last Reset
No path to specified
Neighbor
Last Error
10.0.0.51 64009 eBGP ACTIVE 0 / 0 never
10.0.0.53 64009 eBGP ACTIVE 0 / 0 never
+ 29 more neighbors
Environment
Source: STATE_DB
Temperature
No sensor data (virtual platform)
Fans · 4 trays
fan-1 OK
fan-2 OK
fan-3 OK
fan-4 OK
Power Supplies

Port visualization · BGP neighbor state · configuration drift — all surfaced from a single agent running natively on SONiC.

How it works on SONiC.

The standard Linux agent runs natively on SONiC-based switches. No build variant required for the initial release — the same binary that runs on Ubuntu servers runs on SONiC.

📡
Native Linux agent on SONiC

SONiC is Linux — so the 15MB Versiera agent runs natively with zero porting. Agent communicates with SONiC's Redis-backed CONFIG_DB and STATE_DB over the local socket for port, BGP, LLDP, and interface telemetry.

CONFIG_DBSTATE_DBLocal socket
🔌
BGP state via vtysh

Live BGP neighbor state — session state, advertised/received prefixes, hold timers, MD5 auth status — surfaced from FRRouting via vtysh. No SNMP polling, no external LG server.

FRRoutingvtyshLive state
🔐
SSH CA + Vault-rotated SNMP

Switches get the same SSH CA as the rest of your fleet. SNMP community strings rotated via Vault using a SONiC-safe character set — consumers receive the new value via webhook to keep NMS tools in sync.

SSH CAVault rotationSONiC-safe charset
📏
Compliance across 5 services

DNS, NTP, Syslog, SNMP, and SSH compliance modules evaluated continuously on SONiC — same templates, same drift detection, same remediation workflow as your servers. Configuration drift detected with per-service granularity.

DNSNTPSyslogSNMPSSH
VALIDATED ON HARDWARE

And on Cisco Catalyst,
as an IOx container.

SONiC was the starting point because it is open. Cisco is where most enterprise campus and branch estates actually live — so the agent now ships as an IOx application, hosted by the platform's own application-hosting framework, reading the chassis through RESTCONF, NETCONF, SNMP and CLI.

Validated
Catalyst C9300L-24P-4X

IOS-XE 17.15.6. Every capability described here was measured on this chassis, not inferred from documentation. Upgrades run through app-hosting upgrade, preserving persistent application data.

Same procedure
Catalyst 9300X · 9400 · 9500 · 9500X

Expected to work through the identical IOx deployment path. The faceplate renderer is vendor-aware, so port count and uplink module render correctly per model.

Known blocked
ISR 4000 series

Requires 8 GB DRAM and internal mSATA or NIM-SSD storage. Without an SSD the IOx commands do not appear at all — the rear-slot USB SSD is not a substitute.

What the agent reads from the chassis

Not the container it runs in — the switch. The container model grants no host filesystem access, so the agent reads the device through its native management interfaces, exactly as the SONiC agent reads SONiC through Redis.

Surface Read via What you get
Chassis identityRESTCONFSerial number, model, software version, control-plane memory, flash storage.
InterfacesRESTCONF · SNMPAll interfaces with counters, speed, duplex, media type and VLAN membership. Live link state and per-port throughput, errors and queue drops.
Switchports & VLANsRESTCONFAccess and trunk configuration per port, VLAN membership and naming, rendered against a vendor-accurate faceplate.
Endpointsmatm-operMAC address table decoded into an endpoint inventory — what is plugged into which port, with offline OUI manufacturer resolution and move detection.
PoERESTCONFPer-port power draw against the chassis budget and allocation.
EnvironmentRESTCONFSensors carrying the vendor's own thresholds, rather than thresholds invented by the monitoring tool.
NeighboursLLDP · CDPDiscovered adjacencies, feeding topology and the endpoint location view.
Config divergenceRESTCONFIOS-XE's own running-vs-startup unsaved-config flag — a partial drift answer available today.
Not yet built — but reachable

NTP, syslog, SNMP, AAA and banner compliance are readable from the running config over RESTCONF and pushable back over NETCONF. IOS-XE local user management, ACL policy, SSH configuration and full config-drift hashing are designed and modelled in YANG. These need work, not a different platform — and they are not claimed as shipped.

Deliberately compiled out

Security patch management and internet speed testing are excluded from the network build. Left in, they would report the container's Debian package posture and the container's route to the internet, and present both as facts about a Cisco switch. Declining to answer is more honest than answering wrongly.

One genuine constraint worth stating. NETCONF on this platform advertises writable-running, validation and rollback-on-error — but not candidate and not confirmed-commit. Timer-based self-rollback has to be built rather than relied upon. An agent inside the chassis is better placed to provide it than any external NMS, precisely because it does not lose its arm when reachability breaks.

One security model.
Different network operating systems.

This is the point of the whole exercise. The two platforms could hardly be more different — one is open-source Linux with a Redis state store, the other is proprietary IOS-XE reached through YANG-modelled APIs. Everything above the collection layer is identical. Versiera is not a SONiC product that also happens to read Cisco. It is a network infrastructure control plane.

Layer SONiC Cisco IOS-XE
Agent form Native Linux binary IOx application container
Device state read via Redis CONFIG_DB · STATE_DB · vtysh RESTCONF · NETCONF · SNMP · CLI
Agent identity mTLS · x509 leaf CN = UUID mTLS · x509 leaf CN = UUID
Telemetry & inventory Ports · BGP · LLDP · sensors Ports · VLANs · endpoints · PoE · sensors
Compliance templates DNS · NTP · Syslog — live Readable; push not yet built
SSH CA Supported N/A — IOS-XE SSH is not OpenSSH
Config enforcement Live In development (NETCONF)
Central policy Versiera Versiera
Jobs · tags · groups · alerts Versiera Versiera
Audit trail Versiera Versiera
Validated on sonic-vs (QEMU) Catalyst C9300L-24P-4X hardware
What is genuinely shared

Identity, policy, jobs, tags, groups, alerting and audit. A switch is an ordinary fleet member — it appears in the same inventory, obeys the same dynamic group rules, and writes to the same audit log as a Linux host. There is no second console and no export step between the network team's tooling and the security team's.

What differs, and why

The enforcement rows differ because IOS-XE's write path is newer work, not because the architecture cannot reach it — the configuration is modelled in YANG and pushable over NETCONF. SSH CA is the one honest structural gap: IOS-XE SSH is not OpenSSH on a filesystem, so host and user certificates do not apply there the way they do on SONiC.

SONiC and Cisco today.
More network platforms ahead.

SONiC was the starting point — the most open, extensible network OS in the industry — and Cisco IOS-XE followed because that is where most enterprise campus estates actually live. From these two, Versiera's network device support expands to further platforms along clear paths.

EARLY ACCESS · VALIDATED ON SONiC-VS
SONiC

Native agent reading device state from the SONiC Redis socket. Three-pillar support with DNS, NTP and Syslog adapters. Validated on sonic-vs; outreach underway to Celestica and EdgeCore for physical-hardware collaboration.

EARLY ACCESS · HARDWARE VALIDATED
Cisco IOS-XE

IOx container agent validated on a Catalyst C9300L running IOS-XE 17.15.6. Chassis, interfaces, switchports, VLANs, MAC endpoints, PoE and sensors are live. Write-side enforcement over NETCONF is next.

IN DEVELOPMENT
Juniper vJunosEvolved

Lab environment standing up now. Target: same three-pillar agent support on Juniper's evolved Junos platform.

PLANNED
Further platforms

Closed platforms that cannot host an agent are reachable through agentless API integration — the same observability surface, delivered without a local binary. The control plane does not change; only the collection method does.

DESIGN PARTNER PROGRAM Open · limited cohort

Working with early adopters
and equipment vendors.

We are working with a small number of early SONiC adopters to validate unified security across network and compute. If you're running — or building — SONiC-based infrastructure, we want to hear from you.

🏢
SONiC operators
Running SONiC in production or lab. Direct input into compliance modules and roadmap priority.
🔧
Hardware vendors
SONiC-based switch manufacturers & ODMs. Joint validation, co-marketing, OEM opportunities.
🧪
Integration partners
NMS vendors, CI/CD platforms, SIEMs. Help validate unified security across network & compute.

Bring your network into the control plane.

Request a technical deep-dive on Versiera for SONiC — we'll walk through the architecture, demo the Network Device page, and discuss integration with your specific switch fleet.

Built for the infrastructure
everyone else ignores.

From Raspberry Pi blade clusters to BSD-hardened financial infrastructure — Versiera's 15MB agent and native ARM64 support make it the only enterprise security platform that scales from a $35 compute module all the way to a 100,000-node global fleet.

The Software-Defined
Industrial Edge.

In 2026, the Raspberry Pi is no longer a hobbyist board — it is the edge gateway for the Software-Defined Factory. High-density blade clusters (Turing Pi, BitScope, Compute Blade) are running K3s, managing PLCs, and processing computer vision at the far edge of enterprise networks. Versiera is the only platform built to secure and govern them at scale.

🍓
Raspberry Pi & Compute Module Clusters

Pi CM4/CM5 modules power everything from Heathrow Airport's digital signage to industrial PLCs and medical devices. Unlike consumer boards, these system-on-modules are deployed in DIN-rail housings, PoE-powered blade enclosures, and factory carrier boards — with no keyboard, no monitor, and no traditional management plane.

Versiera reads hardware identity from /proc/device-tree/serial-number, maps it to fleet inventory, and provides the single-pane-of-glass view IT managers demand — without requiring BIOS/UEFI/SMBIOS.

  • ARM64 native agent — 15MB, zero runtime dependencies
  • Device Tree serial → fleet inventory mapping
  • PoE budget and thermal throttle monitoring
  • eMMC / SD-card wear level observation via sysfs
High-Density K3s & MicroK8s Clusters

The "blade" clusters you see on YouTube are running K3s or MicroK8s. The core problem: most observability agents are too heavy. A 100MB agent on a 2GB RAM node kills the cluster's utility. Versiera's 15MB agent is the Goldilocks solution — providing eBPF pod-to-pod traffic visibility and TCP RTT measurement without the overhead of a service mesh like Istio.

For "bare metal ARM cloud" providers (MiniNodes, Ampere-based hosters) offering low-cost CI/CD environments, Versiera provides the compliance and security layer that makes shared ARM infrastructure enterprise-ready.

  • eBPF east-west traffic visibility — no sidecar required
  • Per-connection TCP RTT at the kernel level
  • Lateral movement detection within the cluster
  • Fleet-wide compliance from a single policy template
INDUSTRIAL COMPLIANCE
IEC 62443
Security Level 2

Industrial cybersecurity standard IEC 62443 is now being enforced on edge devices deployed in manufacturing, energy, and logistics environments. Standard Raspberry Pi OS is "loose" by default — open SSH, no firewall policy, no account governance.

Versiera's enforcement engine — SSHD hardening, NTP policy, firewall template, prohibited account detection — takes a standard Pi and hardens it to IEC 62443 Security Level 2 (SL2) automatically. A $100 board becomes a compliant industrial asset from first agent check-in.

The Companies Building the Edge.

These manufacturers build the physical infrastructure — but their customers need enterprise-grade management, compliance, and security to make it viable at scale. Versiera is the management fabric that makes their hardware enterprise-ready.

CLUSTER BOARDS
Turing Pi

The Turing Pi 2.5 holds four CM4/CM5 or NVIDIA Jetson modules. Moving into "Edge Cloud" — they need management software that handles multi-node clusters elegantly. Versiera's SSH CA and Vault turn a Turing Pi rack into a secure, ephemeral compute cluster.

LARGE-SCALE RACKING
BitScope

Built the Los Alamos National Laboratory Pi cluster — thousands of nodes, the gold standard for industrial Pi racking. Their customers are national labs and research institutions who need the exact compliance audit trail and policy enforcement Versiera provides.

DENSITY + PoE
Uptime Lab (Compute Blade)

Extremely high-density, PoE-powered blade enclosures. Caters to professional DevOps engineers who are exactly the people who would deploy Versiera at work. Fleet-wide SSH CA and eBPF visibility are natural fits for their customers.

INDUSTRIAL DIN-RAIL
OnLogic (Factor Series)

Uses Pi Compute Modules in DIN-rail industrial PCs. Sells to manufacturing, energy, and logistics. Their customers need compliance and NTP/Firewall enforcement to meet IEC 62443 — exactly what Versiera delivers out of the box.

MODULAR PLC
Kunbus (Revolution Pi)

Modular, industrial-grade Pi in a PLC form factor. Their customers are OT engineers building factory automation systems who need firewall policy, NTP sync verification, and SSHD hardening on every deployed node — without touching each one manually.

AI GATEWAY
EDATEC

"Powered by Raspberry Pi" accredited. Builds robust AI gateways for edge vision and anomaly detection. With the Pi AI HAT+ (NPU), these run computer vision at the far edge of factories and cell towers — places where Versiera's lightweight agent is the only viable security option.

PARTNERSHIP MODEL
"Bundle" Pitch

You provide the blade hardware. Versiera provides the enterprise management layer — SSH CA, Vault, compliance enforcement — that makes your hardware enterprise ready out of the box. OEM licensing available for hardware partners.

"Edge Security" Pitch

Industrial devices are vulnerable once deployed in the field. Versiera's eBPF network observability detects east-west lateral movement within a cluster that traditional perimeter firewalls can't see — the killer feature for securing deployed edge hardware.

Designed for Enterprise Infrastructure.

🏦
Financial Institutions

Banks, trading platforms, and payment processors run BSD-based firewalls and strict SSHD policies for PCI-DSS compliance. Versiera's pf template management, SSH CA, and cryptographic enforcement provide audit-ready compliance posture across mixed Linux/BSD infrastructure — without a team of engineers maintaining it manually.

PCI-DSSSOC2BSD pfSSH PKI
🛒
Retail Infrastructure

Thousands of point-of-sale systems, back-office servers, and loss-prevention edge nodes — across hundreds of locations — running on ARM-based hardware with no on-site IT. Versiera enforces consistent firewall policy, NTP sync, and account governance across every location from a single console. Zero per-site overhead.

PCI-DSSARM64Fleet-scaleZero touch
🚚
Logistics & Supply Chain

Distribution hubs, cold-chain monitoring nodes, and fleet telematics gateways spread across geographic regions. Versiera's agent handles remote configuration enforcement and compliance reporting for ARM nodes deployed at 3PL facilities, customs depots, and last-mile hubs — without VPN access to each site.

Remote enforcementEdge nodesGeo-distributed
🏭
Industrial OT & Manufacturing

Factory-floor edge compute, PLCs with Linux or BSD embedded OS, and SCADA-adjacent systems that are increasingly networked but rarely governed. Versiera brings IEC 62443-aligned compliance enforcement, firewall hardening, and privileged credential management to OT environments that have historically had no security tooling at all.

IEC 62443OT securityVault PAMFirewall

From a Raspberry Pi cluster
to 100,000 nodes.

Tell us about your infrastructure — the OS, the scale, the hardware. We'll show you exactly how Versiera fits.

Simple pricing.
No barriers to entry.

Start free. Scale when you're ready. Node-based pricing means you pay for what you actually run — and the edge class rate makes securing Raspberry Pi clusters and ARM64 infrastructure economically viable for the first time.

💡 Annual prepay saves 20% — prices shown monthly
Tier 1
Community
Get the agent deployed and prove the value — before spending a dollar.
Free
forever · up to 25 nodes

  • Fleet inventory & monitoring
  • Real-time telemetry — CPU, memory, storage, network
  • Agent deployment GUI
  • All 6 OS platforms (Linux, macOS, Windows, FreeBSD, OpenBSD, NetBSD)
  • ARM64 native support
  • Basic alerting (email)
  • 7-day metric retention
Tier 2
Standard
Full compliance and SSH PKI for growing infrastructure teams.
$3
per node / month · 1–250 nodes
Edge class (ARM64 / ≤4GB): $1.50/node

  • Everything in Community
  • + Compliance engine — Firewall, SSHD, DNS, NTP, Syslog, Users, Sudo
  • + Drift detection & auto-remediation
  • + SSH Certificate Authority (host + user certs)
  • + Key Revocation Lists (KRL) auto-distribution
  • + Account enforcement (3-layer)
  • + Multi-channel alerts — Email · Webhook · Slack
  • + 90-day metric retention
  • + Config snapshots & audit log
Tier 4
Enterprise
Custom contracts for large-scale, mission-critical, or regulated environments.
Custom
2,500+ nodes · annual contract
OEM & reseller programs available

  • Everything in Professional
  • + Negotiated volume pricing
  • + Dedicated support & SLA
  • + On-premise deployment option
  • + Custom compliance modules
  • + Security architecture review
  • + Integration & onboarding assistance
  • + OEM / hardware partner licensing
  • + Multi-region / air-gapped deployment

ARM64 & IoT nodes
at half price.

A 500-node Raspberry Pi cluster cost $17,500 to build. Charging server rates for those nodes is a barrier that kills adoption. The Edge Class rate exists because we believe infrastructure security should be economically viable everywhere — not just in the data centre.

Any node that is ARM64 architecture and ≤4GB RAM automatically qualifies. Versiera detects this at agent registration — no manual classification, no support ticket.

EXAMPLE: 500-NODE PI CLUSTER (PROFESSIONAL)
Standard server rate ($2.00 × 500) $1,000/mo
Edge class rate ($1.00 × 500) $500/mo
Annual prepay (−20%) $4,800/yr
QUALIFIES AS EDGE CLASS
🍓 Raspberry Pi 4/5 🍓 Pi Compute Module 4/5 ⚡ Turing Pi nodes 🔲 Compute Blade 🏭 OnLogic Factor ⚙️ Jetson Nano / Orin

Pricing FAQ

How is a "node" counted?

A node is any host running the Versiera agent that checks in during a given billing month. Agents that are decommissioned or offline for the full month are not counted. There is no per-CPU or per-core pricing.

What happens if I exceed my tier's node band?

Versiera uses graduated bands, not cliff pricing. If you grow from 240 to 260 nodes, only the incremental nodes above 250 move to the Professional rate — you are not retroactively billed at the higher rate for all nodes. You will receive a notification well before approaching a boundary.

How does the Community free tier work for investors and evaluators?

The 25-node free tier is fully functional — not a time-limited trial. It is designed to let organizations deploy real agents into a real environment, see real value, and make a purchasing decision based on evidence. For investor due diligence, a sandbox environment with full feature access can be provisioned on request.

Is the Versiera Vault included in Standard?

Vault (privileged access management, automated credential rotation, time-limited checkout) is a Professional tier feature and above. This is intentional — it is the capability that competes directly with CyberArk and HashiCorp Vault, and its inclusion in the Professional tier is a significant cost advantage over purchasing those products separately.

What is the OEM / hardware partner program?

Hardware manufacturers (blade cluster vendors, industrial compute makers) can license Versiera Community as a bundled management layer in their firmware. End customers then upgrade to Standard or Professional. OEM partners receive a reseller margin and co-marketing support. Contact sales to discuss program terms.

Can Versiera be deployed on-premise with no cloud dependency?

Yes. Versiera is a self-hosted platform — the collector, web console, and database all run on infrastructure you control. There is no Versiera cloud service, no telemetry phone-home, and no dependency on external SaaS. Air-gapped deployment is supported at the Enterprise tier.

A pricing model built for scale.

Node-based subscription pricing provides predictable, recurring revenue that scales linearly with customer fleet growth. The free Community tier is the lowest-friction entry point in the market — once an agent is deployed, the platform's value is self-evident and the upgrade path is natural.

The Edge Class rate opens an addressable market that no competitor has priced for: millions of ARM64 nodes in retail, logistics, industrial, and edge AI environments currently running with zero security governance because enterprise pricing made it uneconomical.

REVENUE MODEL
Monthly recurring · node-based
Scales with customer fleet growth
EXPANSION REVENUE
Tier upgrades + node growth
Net revenue retention > 120% target
OEM CHANNEL
Hardware partner licensing
Pre-installed fleet = qualified leads

Start free. No credit card.
No commitment.

Deploy the agent on up to 25 nodes and see exactly what Versiera discovers about your fleet — before you spend a dollar.

Industrial Stability.

Versiera is designed to solve the management chaos of large-scale distributed infrastructure. Not a research project, not a pivot — a purpose-built platform engineered to production standards from day one, tested against real enterprise environments running thousands of nodes across mixed OS estates.

Category
Infrastructure Security Control Plane
Most companies build one pillar: Datadog (observability) or Puppet (config mgmt) or CyberArk (PAM) or StepCA (SSH PKI). Versiera is building all of them, unified on a single agent and a single enforcement engine. This is a category that doesn't exist yet — and Versiera is defining it.
REPLACES
Datadog / Zabbix (monitoring) CyberArk / HashiCorp Vault (PAM) StepCA / Vault SSH (SSH PKI) Ansible / Puppet (config enforcement) SolarWinds / LibreNMS (firewall compliance)
Infrastructure Security for the Modern Fleet.
Unified monitoring · Compliance enforcement · SSH PKI · Account governance · Privileged access management

Built by practitioners,
for enterprise infrastructure.

Versiera was designed from the ground up to solve the operational and security challenges that practitioners encounter running real-world mixed-OS infrastructure. Not a research project. Not a pivot. A purpose-built platform engineered to production standards from day one.

Mission

Infrastructure security should be unified, automated, and accessible — not fragmented across a dozen expensive specialized tools. Versiera is the single platform that covers fleet monitoring, compliance enforcement, SSH PKI, mTLS agent identity, privileged session audit, account governance, and vulnerability management together — across servers, edge devices, and the network itself.

We believe the best security tooling is the kind that runs quietly in the background, continuously, without requiring an army of engineers to maintain it.

Technical Principles

Go everywhere. Agents are written in pure Go, compiled to single binaries with no runtime dependency. Platform-specific code is isolated via build tags, not if-trees.

Defense in depth. Every security-critical path has multiple independent safety layers. Compliance is verified, not trusted.

Templates over scripts. Policy is declarative, versioned, and auditable. No runbooks, no ad-hoc commands.

Architecture Philosophy

Versiera is designed as a distributed system from the start. The agent, collector, web console, and database are independently deployable — a single server for small environments, fully separated for large ones.

TimescaleDB hypertables handle time-series metrics at scale. PostgreSQL JSONB stores flexible inventory without schema churn. All API paths are stateless.

BSD-First Commitment

Versiera is one of the only enterprise infrastructure platforms with first-class support for FreeBSD, OpenBSD, and NetBSD. This includes native pf template management, NPF compliance, BSD-specific POSIX installer compatibility, and rc.d service integration.

This isn't an afterthought — it's a deliberate focus on an underserved segment of financial infrastructure and security-focused environments.

How Versiera Works

Agents make outbound HTTPS connections only — no inbound firewall rules required. The collector orchestrates everything: telemetry, compliance, enforcement, signing, and Vault operations.

AGENT Linux / macOS 15MB · amd64 + ARM64 AGENT FreeBSD / NetBSD pf · NPF firewall AGENT Windows · ARM64 WinSCM · edge node mTLS outbound jobs / certs COLLECTOR Policy Engine Compliance Scheduler drift detect · remediate · alert SSH CA · x509 CA · KRL sign · renew · revoke · deploy Vault + Rotation Engine rotate · checkout · verify token Enforcement Engine 3-layer · API gate · agent verify read / write DATABASE PostgreSQL + TimescaleDB ──────────────── Fleet state · telemetry Vault credentials (AES-256) SSH certs · KRL · audit log Policy templates · jobs 100K+ agent capacity WEB CONSOLE Operator UI HTMX · Nginx TLS port 8443 · :8081 internal Dashboards · Vault · SSH CA REST API Collector API :8080 · Nginx :443 /api/collect · /api/sshca · /api/vault 🔒 Outbound-only, mutually authenticated (mTLS) · Servers, edge nodes and network devices · No inbound connections · No cloud dependency · Air-gap compatible
Network Trust Model
Outbound Only
Agents make outbound HTTPS connections to the collector. No inbound firewall rules are required on any agent host. Agents behind NAT and firewalls work without special network configuration.
Cryptographic Security
Verified at Every Step
Agent identity is verified by mutual TLS — each agent presents an x509 certificate issued by the built-in Identity CA, with the leaf CN bound to its agent UUID, and revocation enforced against a published CRL. Enforcement jobs carry crypto verification tokens with 2-hour freshness windows. CA private keys are encrypted at rest with AES-256-GCM — never stored plaintext, never transmitted.
Data Sovereignty
Your Network, Your Data
All components run on your infrastructure. The collector, database, and web console are fully self-hosted. No telemetry leaves your environment. Air-gapped deployment is natively supported — collector and agents operate entirely on your internal network.

Defense-in-Depth Architecture.

Every security-critical feature in Versiera is built with multiple independent enforcement layers. The platform is designed so that no single point of failure — not a compromised API, not a rogue DB connection, not a malicious job — can produce an unauthorized outcome.

⚙️
Enforcement Engine

3-layer cryptographic enforcement for account policy: API gate blocks unauthorized job types, DB constraints enforce creator identity, and agent verification callbacks validate token authenticity and freshness before any action executes.

🔍
Drift Detection

Dual-hash drift detection distinguishes structural config changes from dynamic state (firewall counters, bruteforce tables). False-positive-free auto-remediation — the system only acts on genuine configuration drift.

📋
Policy Templates

Declarative, versioned templates for Firewall, SSHD, DNS, NTP, Syslog, Users, Sudo, service-account governance, service baselines, and the agent's own configuration. Assigned to static or dynamic inventory groups. Full snapshot and backup history for every template version.

🔐
Versiera Vault (PAM)

AES-256-GCM encrypted credential storage with automated rotation across all 6 platforms. Time-limited checkout, break-glass access, and immutable audit trail. Encryption key never stored in the database.

🛡️
BSD High-Security Deployments

FreeBSD pf, OpenBSD pf, and NetBSD NPF template management with platform-specific compliance enforcement. OpenBSD's security-hardened defaults are preserved and reinforced, not overridden.

🔑
SSH PKI at Fleet Scale

Cryptographic verification at every step of the certificate lifecycle. Ed25519 by default. KRL auto-distribution ensures compromised credentials are blocked within 15 minutes. All CA private keys encrypted at rest.

What Versiera is built with

AGENT
  • Go — single binary, no runtime
  • Build-tag platform isolation
  • eBPF via gopacket (Linux)
  • x509 client certs · mTLS transport
  • IOx container (Cisco) · SONiC Redis
  • RESTCONF · NETCONF · SNMP · CLI
  • systemd · launchd · WinSCM
  • POSIX sh installer (BSD compat)
COLLECTOR + WEB
  • Go — stateless REST API
  • HTMX-driven web console
  • Nginx TLS reverse proxy
  • AES-256-GCM key encryption
  • golang.org/x/crypto/ssh PKI
  • x509 Identity CA + CRL distribution
  • Session correlation schedulers
DATA LAYER
  • PostgreSQL + TimescaleDB
  • Hypertables for time-series
  • JSONB for flexible inventory
  • Versioned migrations
  • 100,000+ agent capacity

Let's talk infrastructure security.

Whether you're evaluating Versiera for your organization, exploring investment opportunities, or want to discuss an acquisition — we'd love to connect.

🎥
Platform Demo
Live walkthrough of the full Versiera console with real agent telemetry
🔧
Technical Deep-Dive
Architecture review, code access, and deployment walkthrough for evaluators
💼
Acquisition Discussion
Valuation, IP ownership, team structure, and integration planning
📈
Investment Inquiry
Growth capital, strategic partnership, and go-to-market acceleration
WEBSITE
www.versiera.com
EMAIL
ADDRESS
312 Dolomite Drive, Suite 212
Toronto, Ontario M3J 2N2
Canada
SEND A MESSAGE