01
Incumbents have a data moat
Vendors with a large installed base sit on years of real telemetry from customer sites. Everyone building against them starts with nothing and has no route to catch up on their own.
Industrial ground truth
Full-fidelity ICS network packet captures paired with SCADA and process historian records from the same operating window, sourced from live production facilities and licensed for detection engineering, model training and product validation.
Live plant sources Full-fidelity, unsampled Purdue L1–L3 Delivered under NDA
The problem
Language models had the web. Industrial models have nothing comparable. Every serious OT dataset sits behind a plant gate, and the operators on the other side of it have no reason to open up.
01
Vendors with a large installed base sit on years of real telemetry from customer sites. Everyone building against them starts with nothing and has no route to catch up on their own.
02
A protocol simulator emits well-formed frames on a tidy network. Real plants give you legacy firmware, flat segments, duplicate MAC addresses, malformed packets and remote sessions nobody documented. Models tuned on lab traffic fall over on the floor.
03
Storage and labelling are solved problems. Getting a pharmaceutical or steel operator to let you mirror a switch during live production is not. That relationship is what we have built.
What we deliver
Captured together where the site permits it, so network behaviour and process behaviour can be read against each other rather than in isolation. This pairing is the part most OT data sources cannot offer.
Raw packet captures from mirror ports on production switches, taken while the line runs.
The process side: what the plant was actually doing while the packets moved.
Protocol catalogue
Live means captures exist or can be commissioned from an estate we already have access to. On request means we source a plant running that protocol against your specification.
| Protocol | Purdue level | Typical estate | Availability |
|---|---|---|---|
| S7comm | L1–L2 | Siemens PCS7, S7-300 / 400 / 1500 | Live |
| PROFINET IO / DCP / PTCP | L1 | Siemens distributed I/O, PROFINET rings | Live |
| OMRON FINS | L1–L2 | OMRON PLC estates, packaging and filling lines | Live |
| OPC over DCERPC | L2–L3 | PCS7 OS servers, classic OPC clients | Live |
| VNC / RDP remote access | L2–L3 | Engineering stations, vendor remote support | Live |
| OPC UA | L2–L3 | Modern SCADA, MES and edge gateways | On request |
| Modbus TCP | L1–L2 | Mixed-vendor estates, utilities, packaged skids | On request |
| EtherNet/IP & CIP | L1–L2 | Rockwell / Allen-Bradley estates | On request |
| DNP3 | L1–L2 | Electric utilities, water, pipeline SCADA | On request |
| IEC 61850 MMS / GOOSE | L1–L2 | Substation automation, protection relays | On request |
| BACnet | L1–L2 | Building management, HVAC, cleanroom utilities | On request |
Delivered
One pharmaceutical sterile injectables facility running multi-line parenteral filling on a redundant Siemens PCS7 architecture. This is the shape of a single engagement, not a cumulative total.
12.4M
Packets in one 75-minute window
159
Distinct IP endpoints
7
Simultaneous capture points
12mo
Historian window delivered
895K
Tag definitions in config export
22GB
Single delivery volume
Delivered under mutual NDA with a full README, data dictionary, network topology summary, anonymisation note and per-file SHA-256 manifest. Buyer identity withheld.
Comparison
Public testbed corpora such as SWaT, WADI, the Morris power-system datasets and the 4SICS lab captures are genuinely useful for benchmarking, and they are free. They are also testbeds: purpose-built rigs with a handful of nodes, one or two protocols, and most of them captured between 2015 and 2019. If your detection logic has to hold up on a customer site, that gap matters.
| Public testbed corpora | OTTrace | |
|---|---|---|
| Source | Purpose-built laboratory rig | Plant actively manufacturing product |
| Network scale | Typically 5 to 20 nodes | 159 distinct endpoints across 7 capture points in a single delivery |
| Protocol mix | One or two, cleanly separated | Ten or more concurrent, including IT services and remote access |
| Process context | Limited sensor logs | Full historian, alarms, SOE, batch records, operator audit trail |
| Network realism | Clean, well-formed, documented | Legacy firmware, flat segments, malformed frames, undocumented sessions |
| Currency | Mostly 2015 to 2019 vintage | Captured on request against current estates |
| Custom capture | Not possible | Commissioned to a written specification |
| Cost | Free | Commercial licence, quoted per engagement |
Sector coverage
Live means we have an existing plant relationship and can commission a capture. On request means we source it against your specification, typically inside a few weeks.
Live
Sterile injectables, multi-line parenteral filling, lyophilisation, ampoule and pre-filled syringe lines. Siemens PCS7 and OMRON estates.
Live
Melt shop and rolling operations with energy monitoring across roughly 200 machines.
Live
Abrasives and precision component manufacturing, year-round line access.
On request
Batch lines, utilities, packaging and clean-in-place cycles.
On request
Kiln control, mills, dispatch and quality loops.
On request
Generation units, substations, IEC 61850 station and process bus.
On request
Upstream, pipeline SCADA and refinery unit operations.
On request
Press shop, body-in-white, paint and final assembly.
On request
Treatment trains, pumping stations, distributed RTU networks.
On request
Pulp mill, paper machine and recovery boiler.
On request
Concentrator, smelter and dispatch systems.
On request
Float line, batch plant and forming controls.
How it works
Every engagement runs the same way, whether you want a dataset already held or a capture commissioned against a spec you write.
01
You tell us the vertical, the protocols, the Purdue levels and the process conditions you need represented. We tell you honestly what is sourceable and what is not.
02
We commission the capture through our plant partner network, or pull from datasets already collected and held.
03
Simultaneous multi-point network capture with a matching historian export from the same operating window wherever the site architecture allows it.
04
Protocol decode, endpoint census, packet and tag counts, and a completeness check written directly against your original specification.
05
Configurable to your risk posture, from full-fidelity under NDA through to scrubbed addressing, hostnames and product identifiers.
06
Presigned S3 access with a SHA-256 manifest, README, data dictionary and topology summary. You verify integrity before anything is accepted.
Terms
Every dataset ships with a completeness statement written against your spec. If a capture missed something you asked for, you hear it from us before you are invoiced.
Our standing commitment
Who buys this
Training anomaly detection, asset discovery and protocol parsers on traffic that behaves like a real plant.
Real operational baselines to tune rules against, so false-positive rates hold up once deployed on a customer site.
Process time-series, batch records and alarm sequences for forecasting, quality and predictive maintenance models.
Real operating signatures and asset inventories to ground synthetic environments in how plants actually behave.
ICS testbed programmes and academic groups needing reference data from production environments they cannot access.
Questions
If your question is not answered here, email [email protected] and you will get a direct answer, not a sales sequence.
Get started
Send a specification and we will tell you what is already available, what we can commission, and what nobody can realistically get you. Samples move once a mutual NDA is in place.
Goes straight to the founder. Expect a reply within one business day.
or email [email protected]