Critical environments

The difference between being secure and being able to prove it.

Security engineering, auditable artificial intelligence, IT/OT convergence and process innovation, from la Ràpita in the province of Tarragona, Spain. Beside every claim on this site you will find the standard that backs it.

Start a technical conversation We reply within two working days · Encrypted channel available
Exposure surface 106reachable assets of 106

A five-zone model in the IEC 62443 style. Choose where the attacker gets in and how the network is segmented; the blast radius is computed by traversing the connections each stage allows.

5/5
zones reached
undetermined
time to detection
Reached by the attackerOut of reachEntry pointDeclared conduit
Entry vector

Lands on an office workstation after an attachment or a set of stolen credentials.

Segmentation stage

A single broadcast domain for the whole plant. No filtering between levels.

Compromising any point means compromising everything. Propagation runs both ways: from the plant you reach the office just as easily as the reverse.

Select a vector and a stage. Everything works from the keyboard: Tab and arrow keys.

Capabilities

Security and compliance

The Spanish National Security Framework for contracting with government, ISO/IEC 27001 and IEC 62443 for private business and industry, GDPR and NIS2 readiness.

RD 311/2022 · ISO/IEC 27001 · IEC 62443

Auditable artificial intelligence

Inventory, risk classification, staff AI literacy and documented human oversight.

EU 2024/1689 · ISO/IEC 42001

IoT, OT and Industry 4.0

Industrial zoning, asset inventory and visibility without stopping the line.

IEC 62443 · ISA-95

Process innovation and smart territory

Process redesign with technology, automation, digital twins and urban sensing with data under public control.

ISO 37122 · UNE 178104

Automation and workflows

Bespoke software built on a process already measured: system integration, document workflows with full traceability and explicit handling of exceptions.

BPMN 2.0 · ISO/IEC 25010

See in detail

Criterion

What we will not do

01

Frighten you

The catalogue of threats is already in every headline. What you will find here is a measured surface before and after, with the method spelled out so you can repeat the measurement without us.

02

Promise what we do not have

Only what we can evidence appears here. Anything still in progress is flagged as such, with its date, and no certification is shown before it has been obtained.

03

Raise barriers

This site meets EN 301 549 at level AA, and you can verify that by navigating it with the keyboard alone. Anyone selling compliance ought to comply first.

04

Track you

There are no cookies here, no tracking pixels and no consent banner. We ask only for what we need in order to reply.