Add-on module

AIS Bastion

On-Site Network Hardening and Local Threat Detection

A camera system is only as private as the network it sits on. Bastion is the other half of the estate: a hardened firewall, intrusion detection, a full SIEM, endpoint telemetry, and an AI analyst — all running on site, with nothing shipped to a cloud console.

Why it exists

The camera platform assumes a network worth trusting

Bastion is how that assumption gets earned. It was built for our own estate deployment first, for the same reason everything else here was.

A private camera system on an open network is not private

The most common way footage leaves a property is not a vendor breach — it is a flat network where a compromised laptop, a smart television, or an unmanaged IoT device can reach the recorder directly. Sovereignty is a network property before it is a product feature.

Cameras are the softest devices on most estates

IP cameras run firmware that is patched rarely and reset easily, and most ship with cloud services enabled by default. We disable those services and default-deny the camera network to the internet. Bastion is what enforces that at the gateway rather than trusting each camera to behave.

Detection without retention is a rumour

When something does happen on the network, the question is always what else that machine touched, and when. Without centralised logs with a real retention window, nobody can answer it. That is what the SIEM layer is for.

On the wire

The cameras have no way out, and no way in

Every device on the estate is discovered, labelled, and placed. The two classes with no business reaching the internet do not reach it — enforced at the gateway, not trusted to firmware.

The stack

Six layers, one deployment, no cloud console

Every component runs on hardware on the property. There is no vendor dashboard holding your logs, your network map, or your endpoint telemetry.

Firewall and intrusion detection

A hardened gateway with IDS inspection, segmented VLANs, and default-deny egress for cameras and IoT. The devices that have no business reaching the internet do not reach it.

SIEM

Central log collection, a custom rule engine, file-integrity monitoring, and automated response. Firewall, endpoints, and network events land in one queryable place with a real retention window.

Endpoint telemetry

Process spawn, network connection, file write, and registry change from every managed machine, with tamper protection on the agent itself. Visibility and alerting — the module observes and reports rather than intervening on the endpoint.

Local AI analyst

A language model running on your own hardware reads the alert stream, summarises the day, and escalates the patterns it judges worth waking you for. Ask it questions in plain English. No telemetry leaves the property.

Network visibility and live map

Every device on the network discovered, labelled, and shown as a live map with the traffic actually flowing between them. You cannot defend an estate network nobody has ever seen drawn.

Camera and IoT isolation

The cameras AIS depends on are the most-compromised device class on any estate. They sit on an isolated network with no route to the internet and no route to the household — enforced at the gateway rather than trusted to each camera's firmware.

Where this stands

One build, two consoles

Bastion and AIS are specified together, commissioned on the same visit, and sized as one build. Today they present through two interfaces.

Bastion runs its own console and its own alerting path alongside the AIS dashboard. Merging them into a single surface is on the build order and will ship when it is genuinely one system rather than a shared login.

What is deployed today is a hardened network, a SIEM with real retention, endpoint visibility with tamper protection, and an AI analyst reading all of it locally — specified by the people who engineered your camera system, sized for the same property, with one point of contact for both.

If a single pane of glass is a requirement rather than a preference, say so on the call and we will give you the timeline before you commit to anything.

Bastion is an add-on to the camera platform, not a replacement for it.

Back to the AIS platform

Harden the network the cameras sit on.

Bastion is scoped during the same site survey as the camera build. If you already have a capable firewall, we will tell you what to keep.