Piscium SecurityPISCIUMSECURITY
Autonomous vulnerability validation

Find out which of yourvulnerabilities are actuallyexploitable, before someone else does.

Piscium Radius attacks your environment the way an adversary would, inside rules you sign, and proves which paths reach the systems you cannot afford to lose. It runs on IT, cloud and OT/ICS environments alike, and re-attacks every path after you fix it.

Validated attack path graphA network graph tracing an exploited chain from the Internet through a VPN and identity provider to a PLC and the Reservoir SCADA, a critical asset.InternetVPN-04DMZ-WEBIAMPLC-A12PG-PRODReservoir SCADACHAIN · RC-0417 · DEMOVPN → IAM → PLC → SCADA

Demo data · Attack path validation

3 chains 1 fix

BLAST RADIUS
17critical assets
reachable
Building alongside the security ecosystemPartners, clusters & research allies
CIHubs
Cyber Cluster
neural coders
Tropical Hunters
CAMTIC

Visualize the invisible.
Walk every chain that ends at your critical assets.

This is what continuous threat exposure management (CTEM) means in practice: a path you can follow hop by hop, and a fix you can watch collapse it. The chains below are demo data from the RiverClear environment.

radius://attack-graph/ot-water
DEMO DATA
Attack graph for OT · Water TreatmentInternet → SCADA reservoir control in 4 hops. Mis-scoped VPN policy reaches the IAM bridge, which trusts a stale OT service account, opening a write path to PLC-A12 and the reservoir SCADA controller.InternetVPN-04IAM BridgePLC-A12Reservoir SCADADMZ-WEBPG-PROD12345
AssetControlOTCritical asset
Walk this chain yourself →Interactive tour of the real product. No signup.

Four things that
change what you fix.

Most tools hand you a ranked list of findings. Radius hands you the handful of changes that break the most paths to your critical assets, and proves each one worked.

What an attacker can reach

An asset list says what exists. Radius maps what an attacker can actually reach from where they already are, so a critical CVE on an unreachable host stops competing for your week.

Proof behind every finding

Nothing reaches your queue on a CVSS number. Radius runs the chain against your real environment first, and every finding arrives with the path that produced it, the command and the timestamp.

The few fixes that matter

Chains that share a hop share a fix. Radius ranks the few changes that collapse the most paths, then re-attacks each one the moment it lands.

A record that carries over

Every run leaves knowledge. Radius does not begin from zero: it knows how your environment is configured today, what it found before, what was fixed and what reopened. That memory is what a board decision is built on.

Five steps,
then the same path again.

Radius runs the same loop an attacker runs, and does not stop at the report. After you fix a path, it attacks that path again.

RADIUS · LIFECYCLEStep 01
Radius loop: observe, reason, attack, validate, report. Currently on Observe01Observe02Reason03Attack04Validate05ReportRADIUSLOOP
The surfaceObserve
01

Observe

Discovers and watches the surface: assets, services, identities and dependencies, including what was never in the inventory. It starts passively, so nothing is written to a controller.

  • Passive discovery by default
  • Finds what the inventory missed
  • Identities and dependencies as well as hosts
02

Reason

Builds the attack graph and decides what to try first, by where each path leads, not by severity score.

  • Every path traced to what it reaches
  • Ordered by consequence, not CVSS
  • Shared hops become one fix
03

Attack

Runs the real chain against your environment, inside the rules of engagement you signed. It does not simulate it.

  • The rules you signed live in the engine
  • Per-asset limits, enforced before every action
  • A stop button that works mid-run
04

Validate

Confirms whether the path worked and how far it got. Stops before the destructive payload. Every action logged.

  • How far the chain got, hop by hop
  • Stops short of impact
  • Command, timestamp and decision recorded
05

Report

Delivers reproducible evidence, the fix and the priority in three reports, each at three levels. After you fix it, attacks the same path again.

  • Executive, technical and compliance reports
  • Each at run, asset and finding level
  • Re-attacks the path once you fix it

Safe enough for OT/ICS.
Ready for every environment.

Attacking a plant without touching the plant.

Industrial hardware cannot be rebooted to see what happens. Radius observes passively first, so no packet reaches a controller unless you authorize it, asset by asset, and when it attacks it stops at the point before impact.

  • Passive discovery, no writes to controllers
  • Per-asset rules of engagement
  • Stops before the destructive payload
Per assetEvery action is checked against the rules in force for that asset, then logged with the decision and the reason
Explore the solution →
OT & ICS attack graph view
RADIUSOT & ICS
Industrial facility used as the backdrop for the RiverClear demo environment
DEMO ENVIRONMENTRiverClear
Demo environment

See what an organization looks like inside Radius.

RiverClear is a demo environment: a modeled multi-plant operator with IT, cloud and OT segments that share more than they should. It is how we show the attack graph, the safety trail and the three reports without exposing a customer. It is not a customer and its numbers are not results.

Walk through RiverClear →
START WITH ONE RUN

Start with
one run.

A scoped run against the environment you authorize: fixed scope, fixed price, re-validation included, credited toward continuous coverage if you keep going. It starts with a 30-minute call, and nothing is touched before the rules are signed.

Scope a run →Or walk the product first, no signup →
OWASP APTS· Aligned
Certifications· None yet. SOC 2 and ISO 27001 on the roadmap
Encryption· In transit and at rest
Rules of engagement· Signed before anything runs