New service · Citadel Audit 2.0.0 · by GRYHAT

See every device on your network.Signed proof in one meeting.

We plug into your network with your written approval. Fifteen seconds later we are reading your own devices back to you — every host, manufacturer and open port, mapped to CMMC, SOC 2, HIPAA and PCI-DSS controls — with a cryptographically signed evidence file that still holds up two years from now.

  • Nothing leaves the building
  • No agents, no credentials
  • Ed25519-signed evidence
Citadel Audit emblem: circuit-traced castle shield

Evidence you can verify

15s254 addresses swept end to end
40,222IEEE vendor prefixes on board
2,701NDAA-covered prefixes flagged
7CMMC practices cited on a live scan
0outbound connections, by design
2platforms verified on real hardware

Measured on a live /24 against the shipped 2.0.0 build

The on-site audit · about 20 minutes

How the meeting runs

  1. 01

    Written authorisation first

    You approve the scan — by email, written approval or contract — naming the subnet and the approver. Citadel will not start a scan without that record, refuses any target outside the approved range, and flags verbal approval in the report.

  2. 02

    We plug in on your network

    Citadel reads the live adapter and fills in the subnet we are actually on. Your IT contact confirms the range on screen before anything runs.

  3. 03

    The sweep runs while we talk

    Progress streams live — neighbour cache, ICMP sweep, port probing, name resolution. Your estate populates on screen in about fifteen seconds.

  4. 04

    Your own devices, read back to you

    Hostnames, manufacturers, open ports. The contractor laptop, the camera nobody inventoried, the test box with RDP open.

  5. 05

    Findings mapped to your frameworks

    Each finding names the device, the port and the literal observation, with the CMMC, SOC 2, PCI-DSS, HIPAA or GDPR control it implicates.

  6. 06

    You keep a signed report

    An executive PDF plus a signed evidence file you can verify yourself, months later, with stock tooling — and prove it was never altered.

Inside the app

What your team sees on screen

Real screens from the shipped 2.0.0 desktop build on macOS and Linux, captured on our own lab network. Names and hardware identifiers are blurred.

Citadel Audit first-meeting audit setup screen
First-meeting audit setup. The scan stays locked until the approver, their role, the method and the approved scope are recorded.
Citadel Audit executive audit report screen
Executive audit report. Findings and implicated frameworks, produced in the meeting — findings only, not a certification.
Citadel Audit compliance heatmap screen
Compliance heatmap. Every discovered device against every framework, coloured by the exposure actually seen.
Citadel Audit vendor risk matrix screen
Vendor risk matrix. Hardware attribution, NDAA status and the flaws each vendor’s equipment introduced.
Citadel Audit control deficiencies screen
Control deficiencies. Each finding carries its practice ID, the literal observation and the remediation.
Citadel Audit framework overview screen
Framework overview. CMMC, SOC 2, PCI-DSS, GDPR, HIPAA and AI governance, built only from observed findings.
Citadel Audit rules of engagement screen
Rules of engagement. Active testing needs its own signed permission — separate from discovery consent — and it is written into the evidence.
Citadel Audit authorised active test screen
Authorised active test. Every run is logged with who authorised and signed it. Checks that do not apply are skipped and said so, not counted as passes.
Citadel Audit native on linux screen
Native on Linux. The same app on Ubuntu (x64): 14 devices enumerated in 10.9 seconds, with the authorisation recorded before the sweep.
Citadel Audit local ai, on linux screen
Local AI, on Linux. Asked for an analysis, the on-device model summarised only what the scan saw — and said what it did not assess.
Citadel Audit no data is not a clean bill screen
No data is not a clean bill. Before a scan runs, the dashboard says there is nothing to report — it never shows a reassuring default.

What it does

Discovery, evidence and a signed deliverable

Every capability runs on the consultant laptop, on your network — no agent to install, no credentials to hand over, and no data leaving the building.

Layer-2 device discovery

Live

Reads the OS neighbour cache, sweeps with ICMP, and falls back to TCP for hosts that stay silent. Finds the machines nobody inventoried.

254 addresses · 10–16s · 12–15 hosts typical

Hardware attribution

Live

Resolves the manufacturer from the hardware address against the IEEE registry. Randomised addresses are reported as unattributable, never guessed.

IEEE MA-L · 40,222 prefixes

NDAA Section 889 screening

Live

Flags equipment from entities named in Section 889, matched by registered organisation name so new prefixes are covered automatically.

2,701 covered prefixes · FAR 52.204-25

Shadow AI detection

Live

Identifies locally hosted inference servers — Ollama, ComfyUI, Gradio, LM Studio — on the ports distinctive to each.

EU AI Act Art. 4 · ISO 42001 · IAiGACB-aligned

Host identification

Live

Reverse DNS with a NetBIOS fallback, so Windows hosts that ignore DNS still arrive with a name your team recognises.

7–10 of 14 hosts named, typical

Framework mapping

Live

Each finding carries the controls it implicates across six frameworks, with the specific practice identifier — not a category label.

CMMC · SOC 2 · PCI-DSS · GDPR · HIPAA · EU AI Act

Cryptographically signed evidence

Live

Every evidence file is signed. You verify it months later with stock tooling and nothing from us. Alter one byte and verification fails.

minisign · Ed25519 · verified vs reference binary

Enforced scan authorisation

Live

No record of who approved it, no scan. A target outside the approved range is refused outright. The permission is signed with the evidence.

Refusal before any packet is sent

On-device AI analysis

Live

Narrative and Q&A run on a model loaded locally. No cloud SDK, no API key, and a non-private endpoint is refused outright.

Refused to invent CVEs or fines in testing

Compliance built from observed findings

Live

Every framework row traces to a finding the scan actually raised — its evidence, remediation and citation. No re-written prose, and no invented "N of M controls passed" score for a scan that tests exposure.

The signed export attests only what was seen

Board-ready audit report

Live

Executive report with the authorisation of record, framework-mapped findings and a remediation plan built from what was actually found.

Print / PDF · yours to keep

Fully offline operation

Live

Every asset is bundled. No CDN, no webfonts. Renders identically on an isolated or air-gapped segment.

CSP permits no outbound destination

Protocol safe-checks

Live

Opt-in HTTP, TLS and SMB checks: cleartext login forms, missing HSTS, obsolete, self-signed or expired TLS, SMB signing and SMBv1. They observe a service’s own response — no credentials, no payloads, no exploitation.

SMB parsed by negotiated dialect · never fabricates SMBv1

Authorised active testing (Pro)

Live

Anonymous and null-session access checks on FTP and SMB, plus an authentication-presence review — per host, and only after a separate rules-of-engagement record: who authorised it, who signed it, the scope and the tests allowed.

Non-destructive · no brute force, exploit payloads or writes

Offline licensing

Live

Each install carries a machine serial and runs only with a signed license, verified locally against an embedded key. No license server — activation works air-gapped.

Ed25519 · machine-bound · tamper/expiry rejected

Tamper-resistant build

Live

The shipped binary cannot be run as a general Node runtime and loads only its own verified app bundle. Signed and notarized on macOS.

Electron Fuses · asar integrity · Developer ID

Runs on macOS and Linux

Live

Verified on real hardware on both: universal macOS DMG, Linux AppImage and .deb for x64 and arm64. Windows is configured but not yet verified.

Ubuntu 26.04 full scan · macOS notarized

Continuous monitoring appliance

Next

The same engine runs headless and writes signed evidence to disk. The scheduler and evidence archive that make it a managed service are in build.

Headless engine runs today · scheduler in build

Detection rules

What it flags, and why

33 audit-relevant ports, ten rules. Severity reflects exposure observed on the segment — the scanner cannot tell whether a service is patched, and the rules do not pretend otherwise. Ports 5000 and 8000 are deliberately not treated as AI services: on macOS, 5000 is AirPlay, and flagging it would be a false finding.

ExposurePortsSeverityBasis
Telnet23CriticalCredentials cross the network in cleartext.
Open datastores (Redis, MongoDB, Elasticsearch, Memcached)6379 · 27017 · 9200 · 11211CriticalHistorically default to no authentication.
NDAA Section 889 vendor—CriticalRegistered manufacturer matches a covered entity.
FTP21HighCredentials and payloads unencrypted.
Remote Desktop (RDP)3389HighThe dominant ransomware initial-access vector.
VNC5900–5901HighFrequently weak or absent authentication.
Databases (MySQL, PostgreSQL, SQL Server, Oracle)3306 · 5432 · 1433 · 1521HighReachable from a general-access segment.
Shadow AI (Ollama, ComfyUI, Gradio, LM Studio)11434 · 8188 · 7860 · 1234HighUnsanctioned model servers, uninventoried.
Windows file sharing (SMB)139 · 445MediumLateral movement and ransomware propagation.
Cleartext admin interface80MediumManagement over HTTP (Low on the gateway).

What you walk away with

Findings that cite their evidence

Every finding names the device, the manufacturer, the literal observation and the control it implicates. No editorialising, no fear. Illustrative excerpt from a lab network:

HostManufacturer (IEEE)ObservationControlsRating
finance-ws-0410.0.0.158Intel CorporateTCP 3389 (RDP) accepted a connection from the scanning host.CMMC AC.L2-3.1.12 · SOC 2 CC6.6High
Unnamed host (.170)10.0.0.170GIGA-BYTE TECHNOLOGYTCP 139, 445 (SMB) accepted a connection from the scanning host.CMMC SC.L1-3.13.1 · PCI-DSS 1.3Medium
gateway10.0.0.1ASKEY COMPUTERTCP 80 (HTTP) accepted a connection from the scanning host.CMMC SC.L2-3.13.8 · HIPAA §164.312(e)(1)Low
Citadel Audit seal: signed, observed, evidence you can verify

Proof

Verify the evidence without us

The signature covers the findings and the authorisation together, so permission and evidence cannot be separated or back-dated. You verify it with the open-source minisign tool — no GRYHAT software, no account, no phone call. The export hands you the evidence, its signature and the public key together. Alter a single record and verification fails.

That is the difference between a PDF someone could have edited and an artifact that stands up in an audit.

$ minisign -Vm evidence.json -p citadel.pub
Signature and comment signature verified
Trusted comment: scan:scan-1790206388456 scope:10.0.0.0/24
hosts:14 authorised-by:Jane_Doe org:Acme_Global method:EMAIL

# after altering a single record
$ minisign -Vm evidence.json -p citadel.pub
Signature verification failed

Why it is different

It refuses to claim what it did not observe

Security tooling routinely asserts findings it never made. Citadel is built on the opposite discipline — enforced in code, not in a style guide.

  1. 01

    Observed or absent

    Every host, port, vendor and finding traces to a specific observation. Nothing is inferred to fill a gap, and every finding is shown with the literal evidence that raised it.

  2. 02

    Unknown is a result

    An unattributable hardware address renders as unknown. A host with no open ports renders as unclassified. Neither is quietly upgraded to something more reassuring.

  3. 03

    Silence is failure, not success

    A scan that enumerates nothing raises an error. A quiet zero-host result is indistinguishable from a clean network — the most dangerous output an audit tool can produce.

  4. 04

    Not assessed is never none

    Citadel does not correlate CVEs, and the report says so. An empty vulnerability list means the question was not asked — a distinction that matters when you rely on the document.

  5. 05

    The auditor's laptop is excluded

    The scanning machine stays in the inventory for transparency but raises no findings against you — and the exclusion is recorded, not hidden.

Frameworks

Findings carry the practice, not just the framework

CMMC 2.0 AC.L2-3.1.12 · SC.L2-3.13.8 · CM.L2-3.4.9 · SC.L1-3.13.1SOC 2 CC6.1 · CC6.6 · CC6.8PCI-DSS v4.0 Req 1.3 · 2.2.5 · 4.1 · 8.3GDPR Art. 32(1)(a) · 32(1)(b)HIPAA §164.312(a)(1) · (e)(1)EU AI Act Art. 4ISO 27001 · 42001IAiGACB-aligned Evidence · Controls · OversightNDAA Sec. 889 · FAR 52.204-25DFARS 252.204-7012 · 7019

Working toward a specific framework? See CMMC 2.0 readiness, SOC 2 readiness, HIPAA and PCI-DSS.

Engagements

Start with one meeting. Grow from there.

On-site discovery audit

Live scan of one subnet, signed evidence file, executive PDF — produced in the meeting.

The first conversation. See your network before you commit to anything.

Scoped assessment

Multi-subnet discovery, CVE correlation, credentialed review and a remediation plan.

When the discovery audit surfaces real exposure.

Continuous monitoring

In build

On-site sensor, scheduled scans, a signed evidence archive and change alerting.

Organisations with an audit cycle to satisfy.

Framework deployment

Findings mapped and managed against your framework — CMMC, SOC 2, HIPAA, PCI-DSS.

Regulated or contract-bound organisations.

Scope

What it deliberately does not do

Stated plainly, because a tool that hides its limits cannot be trusted about anything else.

  • No CVE correlation. An empty vulnerability list means not assessed, never none present. A full vulnerability assessment is a separate engagement.
  • No credentialed or agent-based inspection. Nothing is installed and nothing is authenticated to.
  • No cloud or SaaS estate. On-premises network discovery only, one subnet per scan.
  • No exploitation. Safe-checks send only the requests a browser or client would. The Pro active test goes one step further — anonymous-access attempts — and only under a signed rules of engagement. Nothing brute-forces credentials, sends exploit payloads or writes to a host; heavier testing is a separately scoped engagement.
  • No traffic analysis. Discovery, not monitoring. Citadel observes what is reachable, not what is being sent.
  • Exposure, never compromise. Citadel reports what a host exposes on the segment. It cannot and does not detect a breach.
  • Findings are not an audit opinion. They map to controls. Only an auditor passes or fails an organisation.
  • Windows not yet verified. macOS and Linux are built and run on real hardware. We do not claim a platform we have not shipped on.

Questions

The questions we get first

Those are assessment platforms you deploy after a contract is signed — weeks of scoping, agents and credentials. Citadel is a twenty-minute on-site instrument for the conversation before that. If you already run one, good: compare what it told you about the unmanaged devices Citadel lists.

Find out what is really on your network.

Citadel Audit by GRYHAT. One meeting, one subnet, a signed report you keep. Orange County and Southern California on site; elsewhere by arrangement.

Let's Connect

Get Your Free Security Assessment

Drop your info below and we'll reach out with a personalized security roadmap for your business.
You may also opt in to receive secure 2FA login codes via SMS from GRYHAT CYBERSECURITY LLC.

or