What we've built, and what we've learned.

Customer projects, partnerships, research and technical deep-dives.

Deep dive

Getting started with ContainerLab

Spin up a whole network from a text file, test before you deploy, and throw it away. With a real MikroTik and OT lab.

Deep dive · ContainerLabRead →
Deep dive

The technologies we work with

The open, vendor-independent stack behind our products and projects, from Python and Go to ContainerLab and on-prem AI.

Deep dive · TechnologyRead →
Deep dive

SD-WAN design for district-heating networks

A secure, segmented, zero-touch connectivity architecture that scales to hundreds of sites.

Deep dive · OT ConnectRead →
Deep dive

Implementing the IKT-Minimalstandard

How lightweight tools map to the Swiss ICT minimum standard for critical infrastructure.

Deep dive · ComplianceRead →
Deep dive

Planning segmentation, interactively

Browser-based tools for zones, communication matrices and a realistic segmentation roadmap.

Deep dive · SegmentationRead →
Deep dive

Untangling a legacy firewall rule base

A method for analysing and cleaning IT/OT firewall rules without breaking production.

Deep dive · Segmentation ToolboxRead →
Deep dive

On-premises AI for sovereign network analysis

An AI assistant grounded in a live digital twin, running entirely on local hardware, no cloud.

Deep dive · On-premises AIRead →
Deep dive

Spanning tree, before it takes the plant down

Finding the broadcast-storm loop in an OT network you didn't design.

Deep dive · Network ExplorerRead →
Deep dive

When the IPAM spreadsheet stops working

Why address management quietly breaks down as an OT network grows.

Deep dive · IPAMRead →
Partnership

Garderos × narrowin

Industrial routers for Swiss critical infrastructure — sold and supported locally.

Partnership · ConnectivityRead →
Research

LLMs: data protection and security

Part of the "Cyber Regulatory Co-Pilot" project: using AI models without sending company data to the cloud.

Research · with FHNWRead →
Research

An OT-IDS that runs on the equipment you already have

Edge-distributed intrusion detection in a container — self-calibrating baselines, only 1–5% transmitted, on-prem LLMs for context. Pilot partners wanted.

Innosuisse · with FHNWRead →
Partnership

Network assessments with Axians and Actemium

Lightweight, Explorer-based network assessments, delivered with two integration partners.

Partnership · AssessmentRead →
Partnership

EnBW: collaboration and investment

A partnership with EnBW and Enpulse to help secure critical energy networks.

Partnership · EnergyRead →
Project

Secure IT & OT network architecture for Eniwa

A regional energy utility's network, rebuilt around clear zones with a realistic migration path.

Project · EnergyRead →
Research

The attacker's view: behind the perimeter

An Innosuisse research project with ZHAW on how attackers move once inside a flat network.

Research · with ZHAWRead →
Project

SIEM for Baselland Cantonal Hospital

Central security monitoring for a hospital IT network, on an open-source Elastic stack.

Project · HealthcareRead →
Community

print(joy)

Free hardware that connects nursing-home printers, so relatives can send greetings.

Community · OutreachRead →
Project

A future-proof network for sciCORE

Network design and build for the University of Basel's scientific computing centre.

Project · Research computingRead →
Project

Efficient network operations for the University of Basel

Automation and a self-service portal that let a small team run a large campus network.

Project · EducationRead →
Research

Micro-segmentation in healthcare

A research pilot validating practical micro-segmentation in hospital networks — implementation partners welcome.

Research · HealthcareRead →
Research

Lateral movement in heterogeneous networks

A qualitative study with universities and hospitals on protecting flat campus networks.

Research · StudyRead →
Community

Keys4Kids

A playful, hands-on first contact with cybersecurity, built for children.

Community · OutreachRead →