New service · Citadel Audit 2.0.0 · by GRYHAT
See every device on your network.Signed proof in one meeting.
We plug into your network with your written approval. Fifteen seconds later we are reading your own devices back to you — every host, manufacturer and open port, mapped to CMMC, SOC 2, HIPAA and PCI-DSS controls — with a cryptographically signed evidence file that still holds up two years from now.
- Nothing leaves the building
- No agents, no credentials
- Ed25519-signed evidence

Evidence you can verify
Measured on a live /24 against the shipped 2.0.0 build
The on-site audit · about 20 minutes
How the meeting runs
- 01
Written authorisation first
You approve the scan — by email, written approval or contract — naming the subnet and the approver. Citadel will not start a scan without that record, refuses any target outside the approved range, and flags verbal approval in the report.
- 02
We plug in on your network
Citadel reads the live adapter and fills in the subnet we are actually on. Your IT contact confirms the range on screen before anything runs.
- 03
The sweep runs while we talk
Progress streams live — neighbour cache, ICMP sweep, port probing, name resolution. Your estate populates on screen in about fifteen seconds.
- 04
Your own devices, read back to you
Hostnames, manufacturers, open ports. The contractor laptop, the camera nobody inventoried, the test box with RDP open.
- 05
Findings mapped to your frameworks
Each finding names the device, the port and the literal observation, with the CMMC, SOC 2, PCI-DSS, HIPAA or GDPR control it implicates.
- 06
You keep a signed report
An executive PDF plus a signed evidence file you can verify yourself, months later, with stock tooling — and prove it was never altered.
Inside the app
What your team sees on screen
Real screens from the shipped 2.0.0 desktop build on macOS and Linux, captured on our own lab network. Names and hardware identifiers are blurred.











What it does
Discovery, evidence and a signed deliverable
Every capability runs on the consultant laptop, on your network — no agent to install, no credentials to hand over, and no data leaving the building.
Layer-2 device discovery
LiveReads the OS neighbour cache, sweeps with ICMP, and falls back to TCP for hosts that stay silent. Finds the machines nobody inventoried.
254 addresses · 10–16s · 12–15 hosts typical
Hardware attribution
LiveResolves the manufacturer from the hardware address against the IEEE registry. Randomised addresses are reported as unattributable, never guessed.
IEEE MA-L · 40,222 prefixes
NDAA Section 889 screening
LiveFlags equipment from entities named in Section 889, matched by registered organisation name so new prefixes are covered automatically.
2,701 covered prefixes · FAR 52.204-25
Shadow AI detection
LiveIdentifies locally hosted inference servers — Ollama, ComfyUI, Gradio, LM Studio — on the ports distinctive to each.
EU AI Act Art. 4 · ISO 42001 · IAiGACB-aligned
Host identification
LiveReverse DNS with a NetBIOS fallback, so Windows hosts that ignore DNS still arrive with a name your team recognises.
7–10 of 14 hosts named, typical
Framework mapping
LiveEach finding carries the controls it implicates across six frameworks, with the specific practice identifier — not a category label.
CMMC · SOC 2 · PCI-DSS · GDPR · HIPAA · EU AI Act
Cryptographically signed evidence
LiveEvery evidence file is signed. You verify it months later with stock tooling and nothing from us. Alter one byte and verification fails.
minisign · Ed25519 · verified vs reference binary
Enforced scan authorisation
LiveNo record of who approved it, no scan. A target outside the approved range is refused outright. The permission is signed with the evidence.
Refusal before any packet is sent
On-device AI analysis
LiveNarrative and Q&A run on a model loaded locally. No cloud SDK, no API key, and a non-private endpoint is refused outright.
Refused to invent CVEs or fines in testing
Compliance built from observed findings
LiveEvery framework row traces to a finding the scan actually raised — its evidence, remediation and citation. No re-written prose, and no invented "N of M controls passed" score for a scan that tests exposure.
The signed export attests only what was seen
Board-ready audit report
LiveExecutive report with the authorisation of record, framework-mapped findings and a remediation plan built from what was actually found.
Print / PDF · yours to keep
Fully offline operation
LiveEvery asset is bundled. No CDN, no webfonts. Renders identically on an isolated or air-gapped segment.
CSP permits no outbound destination
Protocol safe-checks
LiveOpt-in HTTP, TLS and SMB checks: cleartext login forms, missing HSTS, obsolete, self-signed or expired TLS, SMB signing and SMBv1. They observe a service’s own response — no credentials, no payloads, no exploitation.
SMB parsed by negotiated dialect · never fabricates SMBv1
Authorised active testing (Pro)
LiveAnonymous and null-session access checks on FTP and SMB, plus an authentication-presence review — per host, and only after a separate rules-of-engagement record: who authorised it, who signed it, the scope and the tests allowed.
Non-destructive · no brute force, exploit payloads or writes
Offline licensing
LiveEach install carries a machine serial and runs only with a signed license, verified locally against an embedded key. No license server — activation works air-gapped.
Ed25519 · machine-bound · tamper/expiry rejected
Tamper-resistant build
LiveThe shipped binary cannot be run as a general Node runtime and loads only its own verified app bundle. Signed and notarized on macOS.
Electron Fuses · asar integrity · Developer ID
Runs on macOS and Linux
LiveVerified on real hardware on both: universal macOS DMG, Linux AppImage and .deb for x64 and arm64. Windows is configured but not yet verified.
Ubuntu 26.04 full scan · macOS notarized
Continuous monitoring appliance
NextThe same engine runs headless and writes signed evidence to disk. The scheduler and evidence archive that make it a managed service are in build.
Headless engine runs today · scheduler in build
Detection rules
What it flags, and why
33 audit-relevant ports, ten rules. Severity reflects exposure observed on the segment — the scanner cannot tell whether a service is patched, and the rules do not pretend otherwise. Ports 5000 and 8000 are deliberately not treated as AI services: on macOS, 5000 is AirPlay, and flagging it would be a false finding.
| Exposure | Ports | Severity | Basis |
|---|---|---|---|
| Telnet | 23 | Critical | Credentials cross the network in cleartext. |
| Open datastores (Redis, MongoDB, Elasticsearch, Memcached) | 6379 · 27017 · 9200 · 11211 | Critical | Historically default to no authentication. |
| NDAA Section 889 vendor | — | Critical | Registered manufacturer matches a covered entity. |
| FTP | 21 | High | Credentials and payloads unencrypted. |
| Remote Desktop (RDP) | 3389 | High | The dominant ransomware initial-access vector. |
| VNC | 5900–5901 | High | Frequently weak or absent authentication. |
| Databases (MySQL, PostgreSQL, SQL Server, Oracle) | 3306 · 5432 · 1433 · 1521 | High | Reachable from a general-access segment. |
| Shadow AI (Ollama, ComfyUI, Gradio, LM Studio) | 11434 · 8188 · 7860 · 1234 | High | Unsanctioned model servers, uninventoried. |
| Windows file sharing (SMB) | 139 · 445 | Medium | Lateral movement and ransomware propagation. |
| Cleartext admin interface | 80 | Medium | Management over HTTP (Low on the gateway). |
What you walk away with
Findings that cite their evidence
Every finding names the device, the manufacturer, the literal observation and the control it implicates. No editorialising, no fear. Illustrative excerpt from a lab network:
| Host | Manufacturer (IEEE) | Observation | Controls | Rating |
|---|---|---|---|---|
| finance-ws-0410.0.0.158 | Intel Corporate | TCP 3389 (RDP) accepted a connection from the scanning host. | CMMC AC.L2-3.1.12 · SOC 2 CC6.6 | High |
| Unnamed host (.170)10.0.0.170 | GIGA-BYTE TECHNOLOGY | TCP 139, 445 (SMB) accepted a connection from the scanning host. | CMMC SC.L1-3.13.1 · PCI-DSS 1.3 | Medium |
| gateway10.0.0.1 | ASKEY COMPUTER | TCP 80 (HTTP) accepted a connection from the scanning host. | CMMC SC.L2-3.13.8 · HIPAA §164.312(e)(1) | Low |

Proof
Verify the evidence without us
The signature covers the findings and the authorisation together, so permission and evidence cannot be separated or back-dated. You verify it with the open-source minisign tool — no GRYHAT software, no account, no phone call. The export hands you the evidence, its signature and the public key together. Alter a single record and verification fails.
That is the difference between a PDF someone could have edited and an artifact that stands up in an audit.
$ minisign -Vm evidence.json -p citadel.pub Signature and comment signature verified Trusted comment: scan:scan-1790206388456 scope:10.0.0.0/24 hosts:14 authorised-by:Jane_Doe org:Acme_Global method:EMAIL # after altering a single record $ minisign -Vm evidence.json -p citadel.pub Signature verification failed
Why it is different
It refuses to claim what it did not observe
Security tooling routinely asserts findings it never made. Citadel is built on the opposite discipline — enforced in code, not in a style guide.
- 01
Observed or absent
Every host, port, vendor and finding traces to a specific observation. Nothing is inferred to fill a gap, and every finding is shown with the literal evidence that raised it.
- 02
Unknown is a result
An unattributable hardware address renders as unknown. A host with no open ports renders as unclassified. Neither is quietly upgraded to something more reassuring.
- 03
Silence is failure, not success
A scan that enumerates nothing raises an error. A quiet zero-host result is indistinguishable from a clean network — the most dangerous output an audit tool can produce.
- 04
Not assessed is never none
Citadel does not correlate CVEs, and the report says so. An empty vulnerability list means the question was not asked — a distinction that matters when you rely on the document.
- 05
The auditor's laptop is excluded
The scanning machine stays in the inventory for transparency but raises no findings against you — and the exclusion is recorded, not hidden.
Frameworks
Findings carry the practice, not just the framework
Working toward a specific framework? See CMMC 2.0 readiness, SOC 2 readiness, HIPAA and PCI-DSS.
Engagements
Start with one meeting. Grow from there.
On-site discovery audit
Live scan of one subnet, signed evidence file, executive PDF — produced in the meeting.
The first conversation. See your network before you commit to anything.
Scoped assessment
Multi-subnet discovery, CVE correlation, credentialed review and a remediation plan.
When the discovery audit surfaces real exposure.
Continuous monitoring
In buildOn-site sensor, scheduled scans, a signed evidence archive and change alerting.
Organisations with an audit cycle to satisfy.
Framework deployment
Findings mapped and managed against your framework — CMMC, SOC 2, HIPAA, PCI-DSS.
Regulated or contract-bound organisations.
Scope
What it deliberately does not do
Stated plainly, because a tool that hides its limits cannot be trusted about anything else.
- No CVE correlation. An empty vulnerability list means not assessed, never none present. A full vulnerability assessment is a separate engagement.
- No credentialed or agent-based inspection. Nothing is installed and nothing is authenticated to.
- No cloud or SaaS estate. On-premises network discovery only, one subnet per scan.
- No exploitation. Safe-checks send only the requests a browser or client would. The Pro active test goes one step further — anonymous-access attempts — and only under a signed rules of engagement. Nothing brute-forces credentials, sends exploit payloads or writes to a host; heavier testing is a separately scoped engagement.
- No traffic analysis. Discovery, not monitoring. Citadel observes what is reachable, not what is being sent.
- Exposure, never compromise. Citadel reports what a host exposes on the segment. It cannot and does not detect a breach.
- Findings are not an audit opinion. They map to controls. Only an auditor passes or fails an organisation.
- Windows not yet verified. macOS and Linux are built and run on real hardware. We do not claim a platform we have not shipped on.
Questions
The questions we get first
Those are assessment platforms you deploy after a contract is signed — weeks of scoping, agents and credentials. Citadel is a twenty-minute on-site instrument for the conversation before that. If you already run one, good: compare what it told you about the unmanaged devices Citadel lists.
Nowhere. Discovery and analysis both run on the laptop in the room. There is no cloud SDK in the build, no API key, and the Content Security Policy permits no outbound destination. The AI narrative runs on a model loaded locally.
It is a TCP connect scan with bounded concurrency — the same traffic pattern as a workstation opening a web page a few hundred times. No exploitation, no credentials, no writes. Your EDR should notice the reconnaissance; if it does not, that is a finding too. Anonymous-access tests run only if you sign a separate rules of engagement for them.
In practice the interesting result is never the managed fleet — it is the contractor laptop, the IoT camera nobody inventoried, the test box with RDP open. If we genuinely find nothing, you have spent twenty minutes and gained a verified inventory.
Each evidence file is signed with Ed25519 in minisign format. The export includes the matching public key, so you verify it with the free, open-source minisign tool — no GRYHAT software required. Change a single byte and verification fails.
No scan does. Citadel produces evidence mapped to specific controls, which feeds a readiness program. Certification and attestation come from an accredited assessor or licensed CPA firm.
Find out what is really on your network.
Citadel Audit by GRYHAT. One meeting, one subnet, a signed report you keep. Orange County and Southern California on site; elsewhere by arrangement.


