1. Home
  2. Questions
QuestionsIncluding the ones where the answer is no

What people ask on the first call.

Grouped roughly in the order they come up. If yours is not here, ask it in a working session or use the search on this site, which will try to answer it directly.

What it is

Is this hardware or software?

Software. Six of the products run on hardware you already own, and RoomIQ and SpacesIQ can also be hosted by us in a region you pick. There is no appliance to buy and nothing is installed on the equipment we identify.

What does it need from us?

A read-only account on the switches already carrying your traffic, and network reach to them. That is the whole ask.

Do we need to be an AV company to use it?

No. Rooms are where the problem is loudest, which is why RoomIQ exists, but the method reads any managed switch port. A building is as good a place to start as a room.

What it will not do

Can it change anything on our network?

No. Every build ships with a test that fails if any write path exists in the product. It is not a setting that can be switched on.

Do you use a SPAN port, mirror or tap?

No, in any product. Packet contents are never examined. We read the counters and tables a switch already keeps.

Does it block or quarantine devices?

No. It identifies and it evidences. Enforcement is deliberately somebody else’s tool, because anything that can block traffic can also take your network down.

Will it install an agent?

Not on anything it identifies. Nothing is installed on the device being identified, and the device is never contacted directly. The one agent is optional: a small USB agent for workstations, part of RoomIQ and SpacesIQ, if you want USB attack hardware detected.

How sure it is

What happens when it cannot identify something?

It says so. The device stays on the report with its port and its hardware address. The confidence drops, and the report names what would settle it. How it works has a real pass where that happened to a third of the devices.

Why does a score have a ceiling?

Because a number built on thin evidence should not be able to look like a number built on good evidence. CrossCheck caps at 60 when the firmware version came from memory. CrossRoom caps at 74 when part of the call went unmeasured.

Do you ever guess?

No. Where two sources disagree you get both, cited. Where the evidence runs out you get a stated gap. A guess dressed as an answer is the thing these products exist to replace.

Buying it

Do we have to buy all eight?

No. Buy one. It does its job the same way whether or not the other seven are ever installed.

What does it cost?

Each product is quoted on its own, for the scope you want covered. The 30-day pilot has no fee. Tell us what you want to cover, one room, one building or one network, and we will send a quote.

Where do most people start?

A discovery pass with CrossScan. Every other question needs a real list of what is connected before it can be answered, and hardly anyone has one.

What happens in a working session?

Thirty minutes. You bring one room, one closet or one folder. We point the relevant product at it and you leave with the answer, including if the answer is that it found nothing interesting.

Security and compliance

Which security standards do you align to?

SOC 2 Type II and NDAA 889. Both are alignment claims only. We hold no SOC 2 Type II report and no FedRAMP authorization, and the trust page lists what we do hold.

Is the site accessible?

We target WCAG 2.2 Level AA and publish what our own automated check finds, including where it fails. The statement is here.

Where does our data go?

It stays in the deployment you choose: on your own hardware, or for RoomIQ and SpacesIQ, hosted by us in a region you pick. Every product reads your network and nothing else. The privacy page covers what this website itself collects, which is separate and much smaller.

Still not answered?

Search this site and it will try the question directly. Or bring it to a session, where a person who works on the product answers it.