Platform User Guide

Complete documentation for the IoT Security Audit Tool — desktop application, web portal, admin dashboard, and mobile companion.

Table of Contents

  1. Platform Overview
  2. Installation & System Requirements
  3. Getting Started
  4. Desktop Application
  5. Device Discovery & Profiling
  6. Vulnerability Detection
  7. AI-Powered Analysis
  8. Firmware Management
  9. QR & Barcode Scanning
  10. Generating Reports
  11. Web Portal & Account Management
  12. Admin Dashboard
  13. Mobile Companion App
  14. Subscription Plans & Billing
  15. API Key Configuration
  16. Security & Data Privacy
  17. Troubleshooting

1. Platform Overview

The IoT Security Audit Tool by Novexis App is a comprehensive platform for discovering, auditing, and securing Internet of Things (IoT) devices on your network. It combines automated network scanning, CVE vulnerability database lookups, AI-powered analysis, and professional reporting into a single cross-platform solution.

Core Components

ComponentTypePlatformAvailability
Desktop ApplicationNative AppWindows, macOS, LinuxAll plans
Web PortalWebsiteAny browserAll plans
AI AgentIntegrated APIEmbedded in desktop appPro & Enterprise
Mobile CompanionNative AppiOS, AndroidEnterprise only
Admin DashboardWeb PanelAny browserNovexis staff

AI Model Architecture

The platform uses a dual-AI architecture for resilience:

2. Installation & System Requirements

System Requirements

RequirementMinimumRecommended
Operating SystemWindows 10, macOS 13, Ubuntu 22.04Latest OS version
Python3.11+3.13+
RAM4 GB8 GB+
Disk Space500 MB2 GB (for reports/logs)
NetworkEthernet or WiFiEthernet (for scanning accuracy)
PermissionsStandard userAdministrator/root (raw socket access)
Windows users: Run as Administrator for raw socket access required by Scapy for ARP scanning.
macOS/Linux users: Use sudo or grant appropriate network permissions for packet capture.

Installation Steps

  1. Ensure Python 3.11+ is installed: python --version
  2. Download or clone the repository:
    git clone https://github.com/JohnWW11/iotsecurityaudittool.git
    cd iotsecurityaudittool
  3. Install dependencies:
    pip install -r requirements.txt
  4. Initialize the application:
    python src/main.py

Optional Dependencies

PackagePurposeInstall Command
OpenCV + pyzbarQR/barcode webcam scanningpip install opencv-python pyzbar
python-nmapAdvanced Nmap-based scanningpip install python-nmap
netifacesNetwork interface detectionpip install netifaces

3. Getting Started

First Launch

When you launch the application for the first time, you will see the Welcome/Login dialog:

  1. Enter your email address (required for license association).
  2. Enter a license key (optional — skips to free Starter plan if blank).
  3. Click "Start Free Trial" or "Continue with Free Starter Plan".

Recommended First Steps

1. Launch Desktop App
→
2. Click "Scan Network"
→
3. Review Devices
→
4. Run Vulnerability Assessment
→
5. Apply Fixes & Re-scan

4. Desktop Application

Main Window Layout

Sidebar Navigation

IconPageFunction
📊DashboardSummary cards, quick actions, recent devices
📡Device DiscoveryNetwork scanning, device table, QR scanner, scan log
🔍VulnerabilitiesCVE assessment, AI analysis, findings table, export
⚙️Firmware AdvisorFirmware checks, recommendations, AI config advice
🎯Security Quiz7-question IoT risk assessment
⚙️SettingsLicense, API keys, about, legal info

5. Device Discovery & Profiling

Running a Network Scan

  1. Navigate to Device Discovery tab.
  2. Configure the target subnet (e.g., 192.168.1.0/24).
  3. Customize port range if needed (default covers 40+ common IoT ports).
  4. Select scanning engine: Scapy (pure Python) or Nmap (external).
  5. Click "Scan Network".

What Gets Discovered

The scanner identifies for each device:

Device Detail Panel

Click any device row to view its full profile including CVE assessment, firmware status, threat port descriptions, and remediation tips — all in the right-side detail panel.

6. Vulnerability Detection

CVE Database System

The platform uses a dual-database approach:

Running a Vulnerability Assessment

  1. Ensure a network scan has been completed (devices must be in the discovery list).
  2. Navigate to Vulnerabilities tab.
  3. Click "Run Vulnerability Assessment".
  4. Review results in the table (CVE ID, Severity, CVSS Score, Description, Remediation).
  5. Click "AI Analysis" (Pro/Enterprise) for intelligent prioritization and analysis.

CVSS Severity Scale

SeverityCVSS RangeColorAction
Critical9.0 – 10.0RedImmediate remediation required
High7.0 – 8.9OrangePatch within 48 hours
Medium4.0 – 6.9YellowPatch within 30 days
Low0.1 – 3.9GreenMonitor and patch when available

7. AI-Powered Analysis

Configuring AI Models

  1. Navigate to Settings → API Keys & AI.
  2. Enter your DeepSeek API Key (get from platform.deepseek.com).
  3. Enter your Google Gemini API Key (get from aistudio.google.com).
  4. Click "Save API Keys". Keys are encrypted at rest using Fernet encryption.

AI Capabilities

FeatureWhat It DoesAccess
Vulnerability AnalysisAnalyzes CVE data and device profiles to produce structured security assessments with risk summaries and prioritized fixes.Pro & Enterprise
Remediation PlanningGenerates comprehensive, prioritized remediation plans across all discovered vulnerabilities with effort estimation.Pro & Enterprise
Configuration AdviceProvides device-type-specific hardening recommendations — firewall rules, port hardening, encryption settings.Pro & Enterprise

Failover Behavior

The AI Agent first attempts to use DeepSeek. If the call fails (network error, rate limit, API outage), it automatically retries with Gemini 2.5. Both attempts must fail for the system to report an error.

8. Firmware Management

Checking Firmware Versions

  1. Navigate to Firmware Advisor tab.
  2. Click "Check Firmware Updates".
  3. Review the table showing Current Version vs. Latest Version for each device.
  4. Devices with "OUTDATED" status require immediate attention.

Firmware Database Coverage

The tool includes a curated database covering popular IoT vendors:

Custom firmware data: You can extend the local firmware database by editing src/core/firmware_checker.py or the JSON file saved in the app data directory.

Generating Configuration Recommendations

Click "Generate Recommendations" to produce a markdown-formatted list of device-type-specific and port-specific security recommendations. Click "AI Configuration Advice" for AI-generated hardening guidance.

9. QR & Barcode Scanning

Supported Barcode Types

The scanner supports QR Code, Code128, Code39, EAN-13, EAN-8, UPC-E, PDF417, Aztec, and Data Matrix formats.

Scanning Methods

  1. Live Camera Feed: Click "QR/Barcode Scan" → select "Live Camera" → point at a code.
  2. Image Import: Click "QR/Barcode Scan" → select "Import Image" → choose a file.

Parsing Scanned Data

The scanner automatically parses:

Desktop: Requires opencv-python and pyzbar. Mobile companion: Uses Expo's native barcode scanner (no additional setup).

10. Generating Reports

Report Formats

How to Generate

  1. Complete a network scan and vulnerability assessment.
  2. From the Dashboard: Click "Generate Report".
  3. From the Vulnerability Report: Click "Export Report".

Report Contents

PDF reports are available on Professional and Enterprise plans. HTML reports are viewable on all plans.

11. Web Portal & Account Management

Website Sections

PageURLPurpose
Home/Product landing, features, pricing
Get Started / Quiz/quiz7-question IoT risk assessment
Advertorial/advertorialEducational: "Why IoT Security Matters"
Mobile App/mobileiOS/Android companion info + store badges
FAQ/faqFrequently asked questions
Testimonials/testimonialsCustomer reviews and ratings
Contact/contactSupport form, phone, email
Legal/legalPrivacy, Terms, GDPR

Account Registration & Login

  1. Navigate to Sign Up (/signup).
  2. Enter your full name and email address.
  3. Choose a password (min. 8 characters, include a number).
  4. Accept the Terms of Service and Privacy Policy.
  5. Click "Create Account" — a verification email is sent to your registered email.
  6. After verification, Log In (/login) with your credentials.
Registration via registered email only. Password reset links are sent exclusively to the email address associated with your account. Check your spam folder if not received within 5 minutes.

Onboarding Flow

Risk Quiz
→
Advertorial
→
Sign Up
→
Verification
→
Log In
→
Dashboard

Logging Out

Once signed in, a "Log Out" button appears in the navigation bar on all pages. Clicking it:

  1. Clears the local session (sessionStorage).
  2. Updates the navigation bar to show "Log In" and "Sign Up" again.
  3. Redirects to the Home page.

12. Admin Dashboard

Purpose

The Admin Dashboard (/admin) provides Novexis App staff with tools for:

Admin Authentication

The Admin Dashboard uses two environment variables for secure access:

# .env file — located in the application data directory

ADMIN_API_KEY=admin-secret-api-key-for-dashboard-access
ADMIN_SESSION_SECRET=your-admin-session-secret-here
ADMIN_API_KEY
This key authenticates administrative API requests from the dashboard to the backend. When an admin performs an action (e.g., "Suspend Account", "Extend Trial"), the dashboard includes this key in the request header. The backend validates it against the stored value before processing the action. Generate a strong, unique key — treat it like a root password.
ADMIN_SESSION_SECRET
This secret is used to sign and verify admin session tokens. When an administrator logs into the dashboard, a session token is created and signed with this secret using HMAC. Every subsequent request includes this token, and the backend verifies the signature to confirm the admin is authenticated. Generate a random, high-entropy secret — if compromised, all admin sessions must be invalidated.
Security Note: Never commit these values to version control. They are stored in .env, which is excluded by .gitignore. Rotate them periodically and after any staff departure.

How to Configure Admin Access

  1. Open the .env file in the application data directory.
  2. Set a strong ADMIN_API_KEY — minimum 32 characters, random string:
    ADMIN_API_KEY=xK9mP2vL7nQ4wR8tY1bN6aD3fH5jU0sG
  3. Set a strong ADMIN_SESSION_SECRET — minimum 32 characters, random string:
    ADMIN_SESSION_SECRET=cM8wR2tY5nA1bD6fH3jU0sK9mP4vL7qX
  4. Restart the application for changes to take effect.

Admin Logout

The Admin Dashboard includes a distinct "Log Out" button in the top navigation. When clicked, it destroys the admin session token and redirects to the login page. Admin sessions automatically expire after 2 hours of inactivity. On logout, the following occurs:

13. Mobile Companion App

Availability

The mobile companion app is available to Enterprise plan subscribers only on both iOS and Android platforms. It is built with React Native (Expo) and provides field technician tools for on-site device inventory.

Key Mobile Features

Mobile Logout

The mobile companion includes a logout function accessible from the Info/Settings tab. This clears the local session and returns the user to the startup screen.

Note: The mobile companion is a companion app, not a standalone product. It requires an active Enterprise license on the desktop application for full sync functionality.

14. Subscription Plans & Billing

FeatureStarterProfessionalEnterprise
Monthly PriceFree$29.99$99.99
Max Devices1020010,000
Scans / Day250Unlimited
CVE LookupCurated DB onlyLive NVD + CuratedLive NVD + Curated
AI Agent—YesYes
PDF Reports—YesYes
QR ScannerYesYesYes
Mobile App——Yes
SupportCommunityPriority EmailDedicated

Payment Processing

The platform supports payments via Stripe and PayPal. Configure your payment credentials in the .env file:

STRIPE_PUBLISHABLE_KEY=pk_live_...
STRIPE_SECRET_KEY=sk_live_...
STRIPE_WEBHOOK_SECRET=whsec_...

PAYPAL_CLIENT_ID=your-client-id
PAYPAL_CLIENT_SECRET=your-client-secret
PAYPAL_MODE=live

15. API Key Configuration

Required Keys (for full functionality)

KeySourcePlan RequirementPurpose
DEEPSEEK_API_KEYDeepSeek PlatformPro & EnterprisePrimary AI model
GEMINI_API_KEYGoogle AI StudioPro & EnterpriseBackup AI model
NVD_API_KEYNIST NVDPro & EnterpriseLive CVE lookups
STRIPE_SECRET_KEYStripe DashboardAll (for payments)Subscription billing
PAYPAL_CLIENT_IDPayPal DeveloperAll (for payments)Alternative payment method
SMTP_PASSWORDEmail providerAllVerification/reset emails
Important: Never share your API keys. They are encrypted at rest using Fernet symmetric encryption. The .env file is excluded from version control by .gitignore.

16. Security & Data Privacy

Data Storage

What We Never Collect

Third-Party Data Sharing

When using AI analysis or live CVE lookups, vulnerability-related queries (not raw scan data) may be sent to DeepSeek, Google, or NVD APIs. No device identifiers or network topology data is shared with third parties.

17. Troubleshooting

Common Issues

App crashes on startup

Network scan finds no devices

QR scanner not working

AI analysis fails

Cannot log in to web portal

License not activating

Admin Dashboard access denied

Support Channels

Email: support@cs-e-shop.com
Phone: 800-414-1059 (Mon–Fri, 9 AM–6 PM EST)
Web: Contact Form