workspace_premium Premium Feature

Enterprise Endpoint Management
for Industrial Networks

The IEA Enterprise Suite gives Premium subscribers a complete, resilient endpoint management platform — from profile-evaluated patch compatibility to enterprise compliance reporting, all in a secure OT-friendly architecture.

workspace_premium Upgrade to Premium Learn About IEA
Everything You Need to Manage OT Endpoints at Scale

The Enterprise Suite integrates every layer of the patch lifecycle — from compatibility evaluation to deployment tracking and compliance evidence generation.

devices

Profile-Evaluated Patch Compatibility

Every Windows security update is evaluated against your software profiles before deployment. Compatibility verdicts are computed per-KB, per-endpoint class — not guessed.

  • Per-profile KB compatibility matrix
  • Crowd-sourced OT vendor compatibility data
  • Automatic "Incompatible" blocking before deployment
  • Unknown status escalation workflow
bar_chart_4_bars

Enterprise Compliance Reporting

Generate audit-ready reports that demonstrate patch currency, remediation timelines, and compliance posture across your entire OT fleet — per site, per asset class, or globally.

  • KB age tracking per profile (Yellow/Red thresholds)
  • Fleet-wide patch currency dashboard
  • CSV and structured export for GRC tools
  • NIS2, IEC 62443, and insurance-ready evidence
hub

ServiceNow OT VR Integration

Bidirectional integration with ServiceNow's OT Vulnerability Response module — planned for delivery in the next release. Patch findings flow directly into your existing ITSM workflow.

  • Auto-create VR records from IEA findings
  • Sync remediation status back to dashboard
  • Change request generation for OT patch windows
  • SLA tracking aligned to OT risk classification
account_tree

Resilient Relay Architecture

The Site Relay Server (SRS) is a self-contained Windows service that caches and proxies patch content on your OT LAN. No internet dependency. No single point of failure.

  • On-premise patch cache per industrial site
  • Automatic SRS ↔ CES synchronisation
  • Multi-site fleet management from one console
  • Offline-capable agent operation
admin_panel_settings

Role-Based Access Control

Granular RBAC with Admin, Contributor, Site Administrator, and Read-Only roles. Enforce least-privilege across both the CrowdCompatibility portal and the on-premise suite.

  • Admin / Contributor / Read-Only portal roles
  • Site Administrator scoped to site boundary
  • Per-profile agent API key management
  • Full audit log of role changes
api

Agent API & Automation

Premium users receive API key access to the IEA Agent API — enabling custom integrations, automated fleet queries, and programmatic patch orchestration.

  • REST API for fleet telemetry and patch status
  • Per-user API key generation with prefix tracking
  • Pre-configured config.json download
  • Webhook-ready event architecture (roadmap)
Secure by Design. OT-Friendly by Default.
Deployment Stack
cloud
CrowdCompatibility Cloud
Compatibility engine · Licensing · Portal
↕ TLS 1.3
dns
Central Enterprise Server (CES)
REST API · Web console · Firestore · Auth
↕ TLS 1.3 (mTLS optional)
router
Site Relay Server (SRS)
On-premise · Patch cache · Agent proxy
↕ TLS 1.3 · OT LAN only
computer
IEA Agents (Endpoints)
Windows service · Zero internet dependency

Enterprise Security at Every Layer

The suite is architected with OT network constraints and security requirements as first-class design constraints — not afterthoughts.

lock TLS 1.3 enforced on all communications. Auto-provisioned site certificates with built-in CA.
cloud_off Air-gap compatible — SRS operates entirely on the OT LAN. Agents never reach the internet.
key Rotating API keys with prefix tracking. Keys are hashed at rest. Full revocation support.
manage_accounts RBAC throughout — from cloud portal to on-premise services, every action is role-gated.
verified_user Self-signed CA per deployment — no dependency on public PKI in isolated OT segments.
schedule Coming Next Release

ServiceNow OT Vulnerability Response Integration

IEA's compatibility findings will flow directly into ServiceNow's OT VR module — closing the loop between patch intelligence and your enterprise ITSM change management workflow. No manual CSV exports. No spreadsheet reconciliation.

sync_alt

Bidirectional Sync

IEA findings create VR records automatically. Remediation status reflects back to the dashboard in real-time.

assignment

Change Request Generation

Approved patches trigger OT change requests with pre-populated compatibility evidence attached.

timer

OT-Aware SLA Tracking

SLAs are configured per OT risk class — critical infrastructure endpoints get tighter remediation windows.

security

CVE Correlation

Each KB is mapped to addressed CVEs, giving VR records full vulnerability context for risk prioritisation.

Hardened TLS for Industrial Networks

The IEA Suite enforces end-to-end encryption using TLS 1.3. To establish trust without external CA dependencies, we provide a dedicated Root CA management workflow.

Establishing the Trust Anchor

In isolated OT environments, endpoints cannot verify certificates against public authorities. IEA solves this by using a dedicated Root CA for your deployment.

verified_user Step 1: Download the CrowdCompatibility Root CA from your premium dashboard.
install_desktop Step 2: Install the certificate in the "Trusted Root Certification Authorities" store on your OT endpoints.
lock Step 3: Secure Agent-to-Relay (SRS) and Relay-to-Server (CES) communications via hardened HTTPS.
gpp_maybe

Why is this necessary?

Without a trusted Root CA, agents would have to use "insecure" or "ignore-certificate" modes — leaving your OT network vulnerable to man-in-the-middle attacks. By installing our Root CA, you enable Full Validation Mode, ensuring every command and patch comes from your authorized infrastructure.


download Download Root CA (.crt)
Audit-Ready Evidence, Built In

Stop building compliance evidence manually. The dashboard generates it continuously as your fleet is managed.

1

Fleet Patch Currency Dashboard

Live view of KB age per profile, colour-coded to configurable thresholds (yellow / red). One glance shows which machine classes are lagging — and by how many days.

2

Profile Compatibility Matrix Export

Export the full per-profile KB compatibility matrix as structured CSV — ready for import into GRC platforms, audit workpapers, or insurance questionnaires.

3

Deployment History & Evidence Trail

Every patch deployment, agent check-in, and compatibility verdict is timestamped and retained. Provides a defensible audit trail for ICS-CERT findings and NIS2 obligations.

4

Site-Level Isolation Reports

Multi-site deployments produce per-site compliance snapshots, ensuring that cross-site data leakage is architecturally prevented and independently verifiable per location.

Get the IEA Enterprise Suite

Premium subscribers can download the full CES + SRS bundle directly from the dashboard. No internet dependency on your OT endpoints — ever.

download
IEA-Enterprise-Suite-v1.0.zip CES.Api.exe · SRS.Service.exe · setup.ps1 · ~105 MB · Windows x64

workspace_premium Sign In to Download

Requires an active Premium subscription. Download links are signed and expire after 15 minutes.