Frequently Asked Questions

Everything you need to know about the IoT Security Audit Tool.

What is the IoT Security Audit Tool?

The IoT Security Audit Tool is an enterprise-grade desktop application that scans your network to discover connected IoT devices, profiles them, detects security vulnerabilities using CVE databases, and provides AI-powered remediation recommendations. It supports Windows, macOS, and Linux, with optional mobile companion for field technicians.

How does device discovery work?

The tool uses Scapy and Nmap-based network scanning to discover all devices connected to your network. It identifies IP addresses, MAC addresses, open ports, operating systems, and vendor information through MAC OUI lookup. The QR scanner feature also allows field technicians to quickly add devices by scanning serial numbers and barcodes.

Can it detect IoT-specific vulnerabilities?

Yes. The tool cross-references discovered device firmware versions and open ports against the NVD CVE database (National Vulnerability Database). It provides live CVE lookups for Professional and Enterprise subscribers, and maintains a local curated vulnerability subset for offline analysis. Remediation recommendations are generated by our AI agent powered by DeepSeek and Google Gemini models.

What AI models are used and how do they work?

We use DeepSeek AI as the primary resident AI model for vulnerability analysis, remediation planning, and configuration recommendations. Google Gemini 2.5 serves as an automatic fallback if DeepSeek is unavailable. The AI agent provides intelligent, context-aware security assessments tailored to your specific device ecosystem.

Which platforms are supported?

The desktop application runs on Windows, macOS, and Linux. The mobile companion app for field technicians supports iOS and Android (Enterprise plan only).

What does the free tier include?

The free Starter plan supports up to 10 devices with 2 scans per day, basic device profiling, offline vulnerability assessment using our curated CVE database, QR/barcode scanning, and community support. It's perfect for home users and small networks.

Is there a mobile companion app for technicians?

Yes, Enterprise subscribers have access to the mobile companion app (iOS and Android). It includes QR/barcode scanning for rapid device inventory, physical location tagging, power source mapping, and syncing with the desktop application. This is designed specifically for field technicians working across multiple sites.

How does the QR/barcode scanning work?

You can scan QR codes and barcodes using your computer's webcam (live feed) or by importing an image file. The scanner decodes device serial numbers, MAC addresses, and other identifiers, automatically adding them to your device inventory. All subscription plans include QR scanning.

Is the tool suitable for enterprise and industrial networks?

Absolutely. The Enterprise plan supports up to 10,000 devices with unlimited scanning, full AI agent analysis, live CVE database integration, PDF report generation, mobile companion access for field technicians, dedicated priority support, and historical scan tracking. It includes specific detection for industrial protocols (BACnet, Modbus, OPC-UA) and OT/ICS security recommendations.

Can I use Nmap with the tool?

Yes. The tool supports both pure-Python Scapy scanning (no external dependencies) and optional Nmap integration for advanced scanning capabilities. Nmap support can be enabled in the settings for users who have it installed and comply with Nmap's redistribution license.

How is my data secured?

All scan data is stored locally on your machine in an encrypted SQLite database. API keys are encrypted at rest using Fernet symmetric encryption. License data is also encrypted. No scan data is transmitted to our servers. Reports are generated on your local machine.

Do I need an internet connection?

An internet connection is required for live CVE lookups (Professional/Enterprise plans), AI agent analysis, and firmware update URL verification. However, basic device discovery and curated vulnerability assessment work fully offline. The Starter plan functions with minimal internet requirements.