Secure · cyber-physical risk intelligence

Know what's on your network — and how sure you can honestly be.

Most tools answer what's there and bluff the rest — inventing risk scores, painting everything red. Secure does the opposite. Every number is derived from real observed signals. Nothing is fabricated. When it isn't sure, it says so — and hands the decision to you.

mcp.bwtr.ai/app
  1. 01Inventory
  2. 02Topology
  3. 03Vulnerabilities
  4. 04Attack paths
  5. 05PQC · Reports

01 · Inventory

Know your network, device by device.

Every device grouped by the decision it needs. What's resolved, what's provisional, what's corroborated versus thin. Confidence and exposure from real signals — never a score we invented.

  • Needs-review, flagged, and accepted sets — one obvious next action per row
  • Exposure and identity confidence derived from observed signals, never painted on
  • Hosted Secure does not scan. Discovery stays on a collector you authorize, or a labeled simulator
  • When we aren't sure, we say so — and the call stays yours

02 · Topology

The network as observed.

Grouped by what things actually are, with pending-review provenance built in — not a pretty fiction of a complete map.

  • Landscape, relationships, and devices from the same run evidence
  • Pending-review markers on groups that still need a human
  • Inspect a node without leaving the map — the custody trail travels with it

03 · Vulnerabilities

Coverage first — what ran, and what didn't.

A clean result is never mistaken for a complete one. Findings carry provenance; gaps sit up front.

  • Candidate versus confirmed, with the claim boundary in view
  • Provider coverage and the methods this run did not execute
  • CPE→CVE with evidence — not a red wash of invented scores

04 · Attack paths

Ranked routes to crown jewels.

Attack-path analytics from the same evidence base. Blast radius, and a rehearsal you run before anything touches production.

  • Ranked paths with cited evidence — entry, hops, and the jewel
  • Blast-radius scoring on what those routes can actually reach
  • What-if rehearsal in the console. Hosted Secure executes nothing on your network

05 · PQC · Reports

Quantum deadline, honest artifacts.

Crypto inventory for the post-quantum clock: what's classical, what's hybrid, what still needs a plan. Reports that stamp their own honesty — scope, freshness, evidence grade.

  • PQC readiness from the same run — a planning posture, not a quantum-safety score
  • Folios that cannot ship without disclosing their limits
  • Simulator data labeled as not evidence-grade. Nothing is dressed up as a determination

Why you can believe the numbers

Built so it can't lie to you.

01

No fabricated data

Every score — exposure, confidence, blast radius, evidence grade — is derived from real observed signals. Never a number we invented.

02

Render-only frontend

The interface cannot invent domain data. Every view is served a read-only model from the source of truth. An automated guard fails the build if that boundary is crossed.

03

Scope, re-enforced

The collector — the only thing that touches a real network — re-enforces your scope at run time, in the agent itself, rejecting any target outside your allowlist.

04

The human, in the loop

When the platform isn't sure, it says so, plainly — and the decision stays yours. Nothing autonomous ever gets ahead of your consent.

Certainty, earned —
and honestly bounded.

Open the dashboard