OT asset and engineering fabric
EAM, CMMS, historian exports, engineering docs, P&IDs, configuration records, maintenance notes, vendor manuals, and safe operating limits.
VDF.AI sits above the operational, security, asset, engineering, incident, and compliance systems critical-infrastructure operators already run. It coordinates agents for threat intelligence, incident response, NIS2 reporting, OT documentation, resilience analysis, and playbook authoring. Read-only. Air-gapped capable. No path to control-system commands. Every action traceable.
Asset records, procedures, historians, SIEM alerts, threat feeds, outage records, ticketing, resilience plans, and compliance obligations stay where they are. VDF.AI reads approved context, applies advisory and access boundaries, activates the right agents and tools, and returns evidence with the work.
VDF.AI · advisory only · model agnostic · sovereign cloud · air-gapped capable · any LLM
EAM, CMMS, historian exports, engineering docs, P&IDs, configuration records, maintenance notes, vendor manuals, and safe operating limits.
SIEM, SOAR, vulnerability management, threat-intel feeds, advisories, asset exposure, ticket history, and incident notes.
Shift logs, alarms, outage records, restoration events, field notes, network alerts, service impact, and work-order timelines.
Risk registers, dependency maps, BCPs, exercise results, supply dependencies, safety constraints, and recovery objectives.
NIS2 obligations, CER resilience expectations, IEC 62443 zones, NIST CSF controls, regulator correspondence, and audit findings.
Set the target: reduce incident documentation time, prioritize threat advisories, find OT procedures faster, improve resilience planning, or meet NIS2 reporting timelines.
Enforce read-only mode, OT/IT separation, zone-aware access, approved sources, model route, human review, and no-control-command policies before agents execute.
The platform ranks actions by service impact, safety context, asset criticality, threat relevance, compliance deadline, evidence strength, zone policy, and required human approval.
Ingest advisories and internal signals, correlate them with real assets, rank operational relevance, and prepare analyst-ready briefings.
Surface runbooks, summarize logs, build timelines, capture actions, and draft response records while responders retain authority.
Answer procedure questions, standardize SOPs, capture expert knowledge, and route drafts for SME approval before use.
Map NIS2, CER, IEC 62443, and NIST obligations to controls, compile evidence, and draft regulator-ready documentation.
Runs in on-premise, segmented, or air-gapped environments with read-only data surfaces and no path to control-system commands.
Stores objective, source, retrieval, correlation, model route, human approval, output, and lessons learned for future response and audit.
Advisories and internal signals mapped to actual assets, impact, and response priority.
Procedures retrieved, logs summarized, timelines assembled, and response records drafted.
Obligations, notifications, control evidence, and reviewer sign-off compiled on deadline.
Operators find approved procedures, asset records, and engineering answers with citations.
Dependencies, continuity gaps, exercises, and mitigation options synthesized for decision forums.
Procedures drafted from existing material, reviewed by SMEs, versioned, and traceable.
VDF.AI starts with the operational, security, or compliance outcome, then coordinates agents, read-only tools, approvals, and evidence so teams move faster without weakening the boundary.
Connect read-only data from historians, SIEM, SOAR, EAM, CMMS, GIS, document stores, ticketing, outage, risk, and compliance systems without changing control infrastructure.
Zero rip-and-replacePrioritize live threat advisories, reduce incident report cycle time, find the right OT procedure in seconds, close NIS2 evidence gaps, or turn exercises into updated playbooks.
Objective-first executionThreat, incident, documentation, compliance, resilience, and playbook agents call only approved read-only tools with role, zone, source, model, and human-approval policies enforced.
Advisory only by designThe platform records sources, retrievals, correlations, model routes, confidence checks, approvals, outputs, and outcomes while building reusable response memory.
Auditable at executionEssential-service operators face threat overload, tight reporting windows, aging documentation, resilience obligations, and hard OT boundaries. AI must improve decision support without becoming a new operational risk.
Asset data, procedures, engineering drawings, SIEM signals, tickets, outage records, and compliance evidence sit across different systems. Teams assemble the picture under pressure.
AI must never become a write path into control systems. Critical infrastructure needs read-only, advisory execution with explicit separation from SCADA, ICS, PLCs, and safety systems.
NIS2 notifications, outage reports, incident records, root-cause evidence, and regulator requests require speed and precision when teams are already responding.
Procedures age, experts retire, threat patterns change, and lessons from exercises disappear into documents unless the system captures and reuses them.
No migration
The agentic layer connects approved read-only context.
VDF.AI connects to operational records, security tools, asset systems, procedures, document repositories, outage platforms, ticketing, risk registers, and compliance systems through governed tools. Data stays inside your perimeter; agents receive only the scoped read access needed for the objective.
Control infrastructure should not be disrupted to adopt AI. A governed advisory layer starts with read-only workflows and expands across the resilience operating model.
Advisory layer above existing operational systems
Objective engine
The plan is ranked by service impact, safety, risk, deadline, and evidence quality.
Examples of objective-first critical infrastructure execution:
Threat · incident · resilience · compliance
Advisory autonomy
Each workflow gets the authority level it deserves.
VDF.AI lets operations, security, compliance, engineering, and resilience leaders define autonomy at the workflow level:
Assistive · delegated · escalated
Each workflow combines a defined advisory-agent pattern with tools that retrieve evidence, enforce permissions, summarize logs, verify sources, request approval, generate records, and export the audit trail.
Ingests advisories and internal signals, maps them to assets, ranks relevance, and drafts actionable briefings.
Surfaces runbooks, summarizes logs into timelines, captures actions, and drafts the response record.
Tracks obligations, maps controls, drafts compliance documentation, and assembles incident notifications.
Searches procedures, asset records, and engineering documents with cited, role-scoped answers.
Synthesizes dependencies, continuity plans, risk assessments, and exercise evidence into resilience briefs.
Drafts and standardizes playbooks from existing material, then routes every version for expert approval.
Builds outage timelines, impact summaries, root-cause hypotheses, and post-incident reports from logs.
Correlates alert floods, suggests likely resolutions from runbooks, and drafts incident reports.
| Requirement | VDF AI Capability |
|---|---|
| Deployment model | On-premise, segmented, sovereign cloud, disconnected site, or fully air-gapped enclave |
| Control-system isolation | Advisory-only operation on approved read-only data surfaces; no write path to SCADA, ICS, PLCs, or safety systems |
| System posture | Overlay architecture above historians, SIEM, SOAR, EAM, CMMS, GIS, outage, ticketing, document, risk, and compliance systems |
| Data sovereignty | Models, embeddings, prompts, retrieval indexes, operational data, threat signals, tool calls, logs, and outputs remain inside your perimeter |
| Private RAG | Procedures, asset records, engineering documents, playbooks, incident history, risk registers, and compliance evidence retrieved only inside approved environments |
| Role-based access | Agents, tools, knowledge, and outputs scoped by role, site, zone, system boundary, incident role, data class, and least-privilege policy |
| Model routing | Policy-aware routing by task sensitivity, data class, model approval, confidence need, latency, cost, and deployment boundary |
| Autonomy controls | Assistive, delegated, autonomous, and escalated modes configured by workflow, risk threshold, reviewer, and regulator-facing output type |
| Audit logs | Immutable logs for objective, requester, sources, retrievals, correlations, tool calls, model route, approvals, output, and disposition |
| Integration examples | Read-only SIEM/SOAR, asset management, EAM/CMMS, document stores, ticketing, GIS, outage platforms, risk registers, GRC, and custom MCP/API adapters |
| Encryption | At-rest and in-transit encryption, customer-managed keys, and deployment-specific key separation |
| Operations | High-availability clustering, backup and restore, offline update packages, health monitoring, SIEM export, and long-term evidence retention |
No. VDF.AI sits above operational, security, asset, engineering, document, and compliance systems as an advisory control plane. Your SCADA, ICS, historians, SIEM, SOAR, EAM, CMMS, GIS, outage, ticketing, and document systems remain the systems of record. VDF.AI coordinates agents and tools across approved read-only data surfaces.
No. VDF.AI is advisory by design. It can retrieve procedures, summarize logs, correlate alerts, draft reports, and prepare recommendations, but it does not write to SCADA, ICS, PLCs, or other control systems. Operational staff keep authority for every field, safety, restoration, and control decision.
Yes. The platform can run on-premise, in a segmented environment, or in a fully air-gapped enclave. Models, embeddings, prompts, tool calls, operational records, asset context, threat intelligence, and audit logs remain inside your controlled perimeter with no unmanaged external runtime calls.
Agents can map obligations to controls, monitor regulatory and threat feeds, retrieve approved procedures, summarize event timelines, draft incident notifications, and compile evidence packs. Every source, retrieval, model route, recommendation, approval, and output is logged so resilience, incident, and compliance teams can defend the record.
Start with one objective: threat intelligence, incident response, NIS2 reporting, OT documentation, resilience analysis, outage summaries, or playbook authoring.