InfoRelay  /  Products  ·  Use cases
Docs  ·  Downloads  ·  Contact
InfoRelay · NetGuard
Offline · Single-binary · No phone-home

Audit STIGs.
Cut certificates.
Stay offline._

InfoRelay's tool suite for air-gapped admin workstations. Offline DISA Cisco STIG audits and single-binary AD CS cert lifecycle — no telemetry, no installer, no phone-home. Built for the engineers running the perimeter, not their dashboards.

1,005 STIG rules 40–60% MANUAL reduction 100% air-gapped SCIF-deployable
 netguard — ~/audit · live SSH pull
$ netguard --pull 10.0.0.10 --user scan --audit-after
Password for scan@10.0.0.10: ••••••••
SSH 10.0.0.10 · autodetected cisco_xe
pulled 17,842 bytes · hostname core-sw-01
product IOS-XE_Switch · STIG NDM, L2S, RTR
153 rules · 10 PASS · 6 FAIL · 137 MANUAL
MANUAL triage: 35 N/A · 102 applicable · 0 unknown
V-220544 FAIL — vty 0 4 exec-timeout 9:59
line vty 0 4 / exec-timeout 5 0
Saved: core-sw-01-20260521.ckl · .annotated.cfg · .xlsx
Built for the standards that matter DISA STIG NIST 800-171 NIST 800-53 CMMC 2.0 FedRAMP-aligned
The platform

One offline suite. Ten product families.

Catalog-driven, intelligence-augmented, audit-trail-ready. Every tool ships as a single binary — no MSI, no service, no registry edits.

Live · v0.1

NetGuard Audit

DISA Cisco STIG audit · live SSH pull · MANUAL triage · CKL / annotated.cfg / XLSX / PDF.

Live · v0.1

NetGuard Routing

L3 routing + EIGRP troubleshooter. See which prefix rides static vs EIGRP, pinpoint why an adjacency won't form (auth-key gap, K-values, MTU), and get make-before-break key rotation + a static→EIGRP migration plan. Reads IOS/NX-OS/ASA/FTD.

Live · v0.1

NetGuard Traffic

Read the core's flow cache + NBAR offline and split every port & protocol into internal (east-west) vs external-outbound. Fingerprints each host's device family (Windows, AD/DC, SQL, Linux, Cisco) and thumbprints irregular traffic — sensitive services leaving the enclave, cleartext egress, scans. Read-only, never sniffs packets.

Live · v0.1

NetGuard NetOps

A NetBrain-style diagnostic brain that runs offline, day one. Ask it in plain English — "a host authenticates but gets no IP", "an approved site times out through the FTD", "EIGRP neighbor is down" — and it fires diagnostic agents that chain network Intents (device-tracking, DHCP-snooping/IPSG, 802.1x/ISE, EIGRP auth) and 31 executable runbooks, then ranks the root cause with the exact fix. Deterministic core; optional AI copilot skin. No $40k, no config project.

Live · v0.1

CertGuard

Windows AD CS-aware cert tool. Discover · monitor · enroll · bulk CSR · troubleshoot. 11 prebuilt template recipes.

AssetGuard

Tenable.sc operator's toolbox. See, find, and fix what the SC dashboard hides — license, scan zones, churn, diagnostics.

ScoreGuard

DoD Cyber Hygiene Scorecard automation. Import CSVs → preview → fill manual sections → export a paste-ready hardening workbook.

2026 Q3

NetGuard Trace

"Can workstation X reach Call Manager Y on tcp/2000?" Walks L2/L3/ACL/routing across every audited device.

2026 Q4

NetGuard Drift

Continuous config-drift detection across your inventory. Alerts on baseline divergence — without ever sending configs anywhere.

2026 Q4

NetGuard Vault

Automated device config backup with gold-image restore. Satisfies the STIG backup mandate offline — scheduled pull, signed snapshots, one-click revert.

2027

NetGuard Multi-vendor

PAN-OS and JunOS STIG audit modules with the same Deviation + Triage intelligence layer.

2027

NetGuard Inventory

Live discovery, normalization, and offline change-control for the whole fleet. CMDB-grade artifacts, zero connected services.

How it works

From a config you don't trust to a checklist you can file.

1,005
STIG rules across 9 families
L1
Deviation engine
L2
MANUAL triage intelligence
.ckl
+ annotated.cfg · XLSX · PDF
SHA-256
is the whole SWAB artifact
Use cases

Built for the situations that break other tools.

The deadline

The quarterly review is in two weeks and 70% of findings are MANUAL. NetGuard triages them with engineering reasoning — so you file, not flounder.

The air gap

The admin workstation can't talk to the internet. Cloud tools are not an option. NetGuard never phones home — the binary is the whole deployment.

The approval cycle

Anything that installs needs a 6-week Software Approval Baseline review. No MSI, no service, no registry edits — the SHA-256 IS the artifact your ISSO tracks.

v1 in final hardening

Public downloads are parked while we finish v1.

NetGuard is in final testing on live DoD-grade fabrics. Public builds return when v1 ships — no half-baked binaries on air-gapped networks.

Need early access for an evaluation? Email licensing@inforelay.ai — we hand-issue evaluation builds to qualified shops.