1. Platform Overview
The IoT Security Audit Tool by Novexis App is a comprehensive platform for discovering, auditing, and securing Internet of Things (IoT) devices on your network. It combines automated network scanning, CVE vulnerability database lookups, AI-powered analysis, and professional reporting into a single cross-platform solution.
Core Components
| Component | Type | Platform | Availability |
| Desktop Application | Native App | Windows, macOS, Linux | All plans |
| Web Portal | Website | Any browser | All plans |
| AI Agent | Integrated API | Embedded in desktop app | Pro & Enterprise |
| Mobile Companion | Native App | iOS, Android | Enterprise only |
| Admin Dashboard | Web Panel | Any browser | Novexis staff |
AI Model Architecture
The platform uses a dual-AI architecture for resilience:
- Primary Model: DeepSeek AI — handles vulnerability analysis, remediation planning, and configuration recommendations.
- Backup Model: Google Gemini 2.5 — automatically takes over if DeepSeek is unavailable or fails.
- Failover: The AI Agent automatically routes requests to the backup model if the primary call fails. No user intervention required.
2. Installation & System Requirements
System Requirements
| Requirement | Minimum | Recommended |
| Operating System | Windows 10, macOS 13, Ubuntu 22.04 | Latest OS version |
| RAM | 4 GB | 8 GB+ |
| Disk Space | 500 MB | 2 GB (for reports/logs) |
| Network | Ethernet or WiFi | Ethernet (for scanning accuracy) |
| Permissions | Standard user | Administrator/root (raw socket access) |
Windows users: Run as Administrator to enable full network scanning capabilities.
macOS/Linux users: Use sudo or grant appropriate network permissions for packet capture.
Installation Steps
- Download the installer for your operating system (Windows, macOS, or Linux) from the dashboard.
- Run the installer and follow the on-screen prompts.
- Launch the IoT Security Audit Tool from your applications menu or desktop shortcut.
- Sign in with your account email and license key.
3. Getting Started
First Launch
When you launch the application for the first time, you will see the Welcome/Login dialog:
- Enter your email address (required for license association).
- Enter a license key (optional — skips to free Starter plan if blank).
- Click "Start Free Trial" or "Continue with Free Starter Plan".
Recommended First Steps
1. Launch Desktop App
→
2. Click "Scan Network"
→
3. Review Devices
→
4. Run Vulnerability Assessment
→
5. Apply Fixes & Re-scan
4. Desktop Application
Main Window Layout
- Left Sidebar: Navigation menu with Dashboard, Device Discovery, Vulnerabilities, Firmware Advisor, Security Quiz, and Settings.
- Top Bar: Current page title and scan status indicator.
- Main Content Area: The active module's interface.
- Status Bar: System status, device count, and current operation feedback.
Sidebar Navigation
| Icon | Page | Function |
| 📊 | Dashboard | Summary cards, quick actions, recent devices |
| 📡 | Device Discovery | Network scanning, device table, QR scanner, scan log |
| 🔍 | Vulnerabilities | CVE assessment, AI analysis, findings table, export |
| ⚙️ | Firmware Advisor | Firmware checks, recommendations, AI config advice |
| 🎯 | Security Quiz | 7-question IoT risk assessment |
| ⚙️ | Settings | License, account, about, legal info |
5. Device Discovery & Profiling
Running a Network Scan
- Navigate to Device Discovery tab.
- Configure the target subnet (e.g.,
192.168.1.0/24).
- Customize port range if needed (default covers 40+ common IoT ports).
- Choose a scanning engine (default is recommended).
- Click "Scan Network".
What Gets Discovered
The scanner identifies for each device:
- IP Address & MAC Address — unique identifiers
- Vendor/Manufacturer — via MAC OUI lookup (250+ known IoT vendors)
- Device Type — classified into 20+ categories (IP Camera, Router, Smart Speaker, Industrial IoT, etc.)
- Open Ports & Services — scanned across common IoT ports
- Operating System — TTL-based OS fingerprinting
- Risk Score — calculated based on open ports, device type, and vulnerabilities (0-10 scale)
Device Detail Panel
Click any device row to view its full profile including CVE assessment, firmware status, threat port descriptions, and remediation tips — all in the right-side detail panel.
6. Vulnerability Detection
CVE Database System
The platform uses a dual-database approach:
- Curated Local Database: 30+ hand-picked critical IoT CVEs (Log4Shell, EternalBlue, Mirai-related, Hikvision/Dahua backdoors, TP-Link command injection, and more). Available on all plans including Starter.
- Live NVD API: Real-time queries to the National Vulnerability Database at
services.nvd.nist.gov. Professional and Enterprise plans only.
Running a Vulnerability Assessment
- Ensure a network scan has been completed (devices must be in the discovery list).
- Navigate to Vulnerabilities tab.
- Click "Run Vulnerability Assessment".
- Review results in the table (CVE ID, Severity, CVSS Score, Description, Remediation).
- Click "AI Analysis" (Pro/Enterprise) for intelligent prioritization and analysis.
CVSS Severity Scale
| Severity | CVSS Range | Color | Action |
| Critical | 9.0 – 10.0 | Red | Immediate remediation required |
| High | 7.0 – 8.9 | Orange | Patch within 48 hours |
| Medium | 4.0 – 6.9 | Yellow | Patch within 30 days |
| Low | 0.1 – 3.9 | Green | Monitor and patch when available |
7. AI-Powered Analysis
AI Capabilities
| Feature | What It Does | Access |
| Vulnerability Analysis | Analyzes CVE data and device profiles to produce structured security assessments with risk summaries and prioritized fixes. | Pro & Enterprise |
| Remediation Planning | Generates comprehensive, prioritized remediation plans across all discovered vulnerabilities with effort estimation. | Pro & Enterprise |
| Configuration Advice | Provides device-type-specific hardening recommendations — firewall rules, port hardening, encryption settings. | Pro & Enterprise |
8. Firmware Management
Checking Firmware Versions
- Navigate to Firmware Advisor tab.
- Click "Check Firmware Updates".
- Review the table showing Current Version vs. Latest Version for each device.
- Devices with "OUTDATED" status require immediate attention.
Firmware Database Coverage
The tool includes a curated database covering popular IoT vendors:
- IP Cameras: Hikvision, Dahua, Axis
- Networking: Ubiquiti, TP-Link, Netgear, ASUS, D-Link, MikroTik
- Smart Home: Sonos, Philips Hue, Synology, QNAP
- Embedded: Raspberry Pi, ESP32/ESP8266
Custom firmware data: You can extend the local firmware database by editing src/core/firmware_checker.py or the JSON file saved in the app data directory.
Generating Configuration Recommendations
Click "Generate Recommendations" to produce a markdown-formatted list of device-type-specific and port-specific security recommendations. Click "AI Configuration Advice" for AI-generated hardening guidance.
9. QR & Barcode Scanning
Supported Barcode Types
The scanner supports QR Code, Code128, Code39, EAN-13, EAN-8, UPC-E, PDF417, Aztec, and Data Matrix formats.
Scanning Methods
- Live Camera Feed: Click "QR/Barcode Scan" → select "Live Camera" → point at a code.
- Image Import: Click "QR/Barcode Scan" → select "Import Image" → choose a file.
Parsing Scanned Data
The scanner automatically parses:
- Serial numbers (prefixed with
S/N: or SN:)
- URLs (starting with
http: or www.)
- Alphanumeric identifiers (used as serial numbers)
- Generic data (stored as raw text)
Mobile companion: Uses Expo's native barcode scanner (no additional setup).
10. Generating Reports
Report Formats
- HTML Report: Interactive, opens in your default browser. Includes executive summary cards, device inventory table, vulnerability details, and remediation plan.
- PDF Report: Professional document suitable for compliance submission. Generated using reportlab with branded styling.
How to Generate
- Complete a network scan and vulnerability assessment.
- From the Dashboard: Click "Generate Report".
- From the Vulnerability Report: Click "Export Report".
Report Contents
- Executive Summary: Total devices, vulnerabilities by severity, average CVSS, scan duration.
- Device Inventory: IP, MAC, vendor, device type, risk level, open ports for every discovered device.
- Vulnerability Details: CVE ID, CVSS score, description, affected devices, remediation steps.
- Remediation Plan: AI-generated prioritized action items with effort estimates.
PDF reports are available on Professional and Enterprise plans. HTML reports are viewable on all plans.
11. Web Portal & Account Management
Website Sections
| Page | URL | Purpose |
| Home | / | Product landing, features, pricing |
| Get Started / Quiz | /quiz | 7-question IoT risk assessment |
| Advertorial | /advertorial | Educational: "Why IoT Security Matters" |
| Mobile App | /mobile | iOS/Android companion info + store badges |
| FAQ | /faq | Frequently asked questions |
| Testimonials | /testimonials | Customer reviews and ratings |
| Contact | /contact | Support form, phone, email |
| Legal | /legal | Privacy, Terms, GDPR |
Account Registration & Login
- Navigate to Sign Up (
/signup).
- Enter your full name and email address.
- Choose a password (min. 8 characters, include a number).
- Accept the Terms of Service and Privacy Policy.
- Click "Create Account" — a verification email is sent to your registered email.
- After verification, Log In (
/login) with your credentials.
Registration via registered email only. Password reset links are sent exclusively to the email address associated with your account. Check your spam folder if not received within 5 minutes.
Onboarding Flow
Risk Quiz
→
Advertorial
→
Sign Up
→
Verification
→
Log In
→
Dashboard
Logging Out
Once signed in, a "Log Out" button appears in the navigation bar on all pages. Clicking it:
- Clears the local session (sessionStorage).
- Updates the navigation bar to show "Log In" and "Sign Up" again.
- Redirects to the Home page.
12. Mobile Companion App
Availability
The mobile companion app is available to Enterprise plan subscribers only on both iOS and Android platforms. It is built with React Native (Expo) and provides field technician tools for on-site device inventory.
Key Mobile Features
- QR/Barcode Scanning: Native camera scanning of device serial numbers, MAC addresses, and asset tags.
- Desktop Sync: Scanned devices automatically sync to the desktop application over the local network.
- Location Tagging: Assign physical locations to devices as you scan them.
- Offline Mode: Scan history stored locally; syncs when reconnected.
- 3-Tab Interface: Scanner (live camera), History (past scans), Info (app settings).
Mobile Logout
The mobile companion includes a logout function accessible from the Info/Settings tab. This clears the local session and returns the user to the startup screen.
Note: The mobile companion is a companion app, not a standalone product. It requires an active Enterprise license on the desktop application for full sync functionality.
13. Subscription Plans & Billing
| Feature | Starter | Professional | Enterprise |
| Monthly Price | Free | $29.99 | $99.99 |
| Max Devices | 10 | 200 | 10,000 |
| Scans / Day | 2 | 50 | Unlimited |
| CVE Lookup | Curated DB only | Live NVD + Curated | Live NVD + Curated |
| AI Agent | — | Yes | Yes |
| PDF Reports | — | Yes | Yes |
| QR Scanner | Yes | Yes | Yes |
| Mobile App | — | — | Yes |
| Support | Community | Priority Email | Dedicated |
14. Security & Data Privacy
Data Storage
- Scan data: Stored locally on your own device. No scan results are transmitted to our servers.
- Account credentials: Encrypted at rest.
- License data: Encrypted at rest.
- Reports: Generated and stored locally on your device.
What We Never Collect
- Your network scan results or device information
- IP addresses, MAC addresses, or hostnames
- Vulnerability assessment data
- Network topology or configuration
- Firmware versions or serial numbers
Third-Party Data Sharing
When using AI analysis or live CVE lookups, vulnerability-related queries (not raw scan data) are sent to our AI and vulnerability database providers. No device identifiers or network topology data is shared with third parties.
15. Troubleshooting
Common Issues
Network scan finds no devices
- Run the application as Administrator (Windows) or with elevated privileges (macOS/Linux).
- Verify the subnet is correct (run
ipconfig / ifconfig to check).
- Ensure your firewall allows outbound network discovery traffic.
QR scanner not working
- Ensure your webcam is connected and not in use by another application.
- Grant camera permissions to the application when prompted.
AI analysis fails
- Check your internet connection.
- Ensure your subscription plan includes AI access (Pro or Enterprise).
- Contact support if the issue persists.
Cannot log in to web portal
- Ensure you've verified your email address (check spam folder).
- Use the Forgot Password link on the login page — reset is sent to registered email only.
- Contact support@cs-e-shop.com if issues persist.
License not activating
- Verify the license key matches your plan tier.
- Contact support for license reset or reissue.
Support Channels
Email: support@cs-e-shop.com
Phone: 800-414-1059 (Mon–Fri, 9 AM–6 PM EST)
Web: Contact Form