Ask in English concept · pilot build

You already know what
matters. Just say it.

No IP addresses. No ports. No knowing which path to test. You name what you're protecting, in plain English — and the product asks your network every reachability question for you.

exposure · ask your network
Which of my risky devices can reach the data centre?
Resolving “data centre” → 10.66.123.0/24 · scanning 6 end-of-support / KEV devices · running a read-only path-lookup for each…
🔴
Cisco ASA — HWLAB perimeter
end-of-support · 9.1 · KEV CVE class
wide open
🟢
FortiGate — L71 HA pair
CVE-2018-13379 · CISA-KEV “critical”
blocked · zone-firewall
🟢
Legacy IOS switch — branch core
end-of-support · no path to target
blocked · ACL
🟢
Old ASA — DR site
end-of-support · segmented
blocked · zone-firewall
🟢
Unpatched WLC — campus
KEV CVE class · no route
blocked · no path
🟢
EoS router — remote office
end-of-support · segmented
blocked · ACL
1 of 6 risky devices reaches your data centre. The Cisco ASA — end-of-support, flagged by no CVE feed as urgent — has a clean, uncontrolled path to your crown jewels. The “critical” FortiGate everyone patches is contained. That’s the one to fix first.
◆ concept mock-up · the path-lookup engine is live today (driven by hand at the demo) · the plain-English layer above is what the pilot builds · read-only, describe-only

The customer never picks a path

Knowing which path to test is the very expertise the product replaces. So it inverts: you declare the target once — the system generates and runs every question.

You say — in English
What are you protecting?

One plain sentence. The system resolves the name to the real subnet from IP Fabric’s discovered inventory — and can even propose it: “these look like your servers, confirm?”

“Protect my data centre.”
System — automatic
What’s dangerous here?

Every end-of-support, KEV, or otherwise risky box — enumerated straight from IP Fabric’s own inventory. No input. The threat context picks the devices, not you.

6 devices flagged → queued
System — automatic
Can each one reach it?

A read-only path-lookup per pair — the four you ran by hand at the demo, but all of them — returned as plain-English verdicts, worst-first.

wide open · blocked · blocked …

What changes

Today · the raw tool
  • You type a source IP, a destination IP, a port
  • You have to already know which path matters
  • One lookup at a time — expert-driven
  • The answer is a diagram you must read
Pilot · ask in English
  • You name the crown jewel in plain language
  • The system generates the questions from threat context
  • Every risky device checked, automatically
  • The answer is a ranked, plain-English verdict list
the point

The right question to ask your network is “what am I protecting?” — not “test 10.64.128.9 to 10.66.123.110 on 443.” You bring the business context. The product brings the questions.