Skip to content
Cyber-physical security for critical infrastructure

Know when the process is failing. Know when it is under attack.

Vardar is an on-site Edge AI system that verifies OT network activity against the physical process—then gives Operations and Security one evidence-backed decision.

Raw OT data and learned site context remain inside the customer environment.
LIVE PROCESS MODELSITE-04 / LINE-03
NETWORK SOURCEEngineering stationNew write sequence
CONTROLLERPLC-07Changed
PHYSICAL ASSETPump P-101Commanded on
PROCESS RESPONSEPressure PT-22Mismatch
CLASSIFICATIONCYBER
SUSPECTED
NETWORK ✓PROCESS ✓
Two evidence paths agreeVerify identity before escalation
01

ON-SITECustomer-controlled edge hardware

02

AIR-GAP READYNo cloud dependency for site operation

03

READ-ONLY STARTSPAN / TAP and approved evidence

04

LOCAL DATARaw plant data remains inside the site

One process. Two teams.
One version of the truth.

Vardar brings cyber context into the control room and operational context into the SOC, so both teams investigate the same process relationship instead of separate alert queues.

01 / CONTROL ROOM

For Operations

See whether a deviation points to wear, drift, instrumentation or an external command.

SHARED
PROCESS
MODEL
OPERATIONS SECURITY
02 / SECURITY OPERATIONS

For Security

See whether a valid-looking network action produced a physical consequence that does not make sense.

Corroborate before
you escalate.

Vardar compares two independent evidence paths. Agreement raises confidence. A single path remains under investigation instead of becoming another confirmed cyber alert.

EVIDENCE PATH A

Network evidence

A new engineering-station write reached PLC-07 outside the learned sequence.

ABNORMAL
EVIDENCE PATH B

Process evidence

The valve command changed, but pressure and flow did not respond consistently.

ABNORMAL
DECISIONCyber manipulation suspected

NEXT CHECKVerify operator identity and physical valve state before escalation.

THE OUTPUT

When it isn't cyber,
it still isn't noise.

  1. 01Operational

    Equipment, process or instrumentation evidence explains the event.

  2. 02Cyber

    Network behavior and physical consequence support manipulation.

  3. 03Mixed

    A cyber event and an operational condition are interacting.

  4. 04Unknown

    Evidence is incomplete; the next check is explicit.

The intelligence stays where
the process lives.

Decoding, correlation, model inference and investigation run on the Vardar appliance inside the site boundary, including disconnected air-gapped environments.

LOCAL EVIDENCE

01SPAN / TAP traffic

02Approved historian context

03HMI and system events

VARDAR EDGE NODE
LOCAL AI CORE
  • Protocol decoding
  • Process relationships
  • Local AI analyst
RAW OT DATASTAYS LOCAL
CONTROLLED OUTPUTS

01Classified finding

02Evidence trail

03Governed next step

READ-ONLY STARTSIGNED OFFLINE UPDATESRETENTION UNDER SITE POLICY

Ask the plant. Get an answer
with evidence.

The local AI analyst explains detector findings, traces approved site evidence and recommends the next check. State-changing integrations remain under customer policy and approval.

VARDAR ANALYSTLOCAL / AIR-GAPPED
CONTROL ROOM

Is Alert 142 operational or cyber?

CLASSIFICATION

UNKNOWN — CYBER SUSPECTED

Both evidence paths confirm abnormal behavior. Cyber is suspected, but operator identity is still missing. Verify the write source and physical valve state before escalation.

NETWORKPLC-07 write / 03:14:22
PROCESSPressure and flow mismatch / +8.2s
05 / Public benchmark evidence

Evidence before promises.

Measured on the public SWaT 2015 dataset. This is a reproducible technical reference, not a claim about site performance before commissioning.

Explore the benchmark gallery
32 / 36labelled attacks detected
99.1%precision
0.55%holdout false-positive rate
85.5%point-adjusted recall
SWaT 2015 · PUBLIC DATASET · RUN 2026-06-11 · COMMIT 97752838
06 / TECHNICAL EVALUATION

Start with one process
that matters.

Bring three to five questions your Operations and Security teams currently answer in separate tools. We will map the evidence, success criteria and governance boundary together.

  • One critical process
  • Shared OT and security questions
  • Success criteria agreed in advance
contact@vardar.ai
SCOPE A CRITICAL-PROCESS EVALUATION

Tell us which operational question your teams need to answer with confidence.

By submitting, you agree to our Privacy Policy and Terms.