An IT environment where standard device management isn’t enough
Claroty is a solution for companies that work with IoT devices from various manufacturers, which communicate using different protocols and have limited capabilities for central management, updates, or communication control.
These include, for example:
- PLCs, HMI panels, and industrial computers,
- production lines and control systems,
- sensors, measuring and automation components,
- cameras and access control systems,
- Building Technology, HVAC, and Energy Management,
- medical facilities and equipment
- automated warehouse and logistics systems,
- other devices on which a standard security agent cannot be installed.
The Claroty platform supports all known and available IoT management protocols. It combines various methods, approaches, and technologies to provide a comprehensive overview of what is happening on your network, who is connected to it, and where they are communicating.
A single platform for the entire device security context
Claroty links information about a device with information about its communications, known vulnerabilities, location, and the device’s importance to business operations.
This allows the security team to see not only that the device exists, but also:
- what its function is,
- who he is communicating with,
- what risks it is exposed to,
- What impact would his exposure have,
- Which measure has the highest priority?
The platform consolidates fragmented technical data into a unified view that can then be used for risk management, network segmentation, incident response, or technology refresh planning. It is precisely this combination of visibility, prioritization, and operational context that sets Clatoty apart from a standard network scanner or static inventory.
Technical Components of the Claroty Platform
Asset Inventory – An Accurate and Continuously Updated Inventory
Claroty detects IoT devices on the network and supplements them with available information about the manufacturer, model, operating system, firmware, network location, and protocols in use.
Equipment is classified according to its purpose, location, or technological unit. Their importance to operations can also be factored into the evaluation, so a critical control element is not assessed in the same way as a standard sensor.
In addition, the platform monitors the quality and completeness of the data in the inventory and flags areas where information is missing or needs to be verified.
Main Features:
- Identification of OT, IoT, IoMT, and BMS devices,
- classification of equipment and their technical characteristics,
- mapping of equipment by location and operational unit,
- expanding communication networks,
- ongoing monitoring of inventory quality.
Exposure Management – Risks Ranked by Actual Impact
Claroty links known vulnerabilities to the context of a specific device. It takes into account the device’s network accessibility, communication paths, operational importance, and the potential consequences of a compromise.
The result is a list of priority steps and corrective actions to bring the facility into compliance with established safety policies.
Main Features:
- identification of vulnerabilities and other exposures,
- evaluation based on technical and operational context,
- prioritizing rehabilitation facilities,
- recommendations for appropriate measures,
- Integrating findings into existing workflows.
Network Protection – Map of Actual Traffic and Data for Segmentation
Claroty monitors communication between operational devices, servers, and other parts of the infrastructure. It identifies which connections are essential for the environment’s operation and which may pose an unnecessary risk.
Based on actual network traffic, Claroty helps generate recommendations for network segmentation and communication policies. These rules can then be implemented on existing firewalls, switches, or NAC solutions. In addition, Claroty offers its own solution for external access to IoT devices—Claroty xDome Secure Access.
At the same time, the platform alerts users to new devices on the network and to communication that deviates from the configured rules. Segmentation is therefore not a one-time project, but an ongoing, continuously monitored, and updated component of network security.
Main Features:
- visualization of communication between devices,
- Identification of unnecessary and risky connections,
- proposals for network policies,
- support for microsegmentation,
- notice of a violation of the communication rules.
Threat Detection – Threat Detection with Operational Context
Claroty monitors changes and suspicious behavior that may indicate an attack, a misconfiguration, or unauthorized access.
Any security alert contains information about a specific device, its function, and its communication links. Alerts and other events can be integrated into an existing SIEM or SOAR solution or into another security operations center process.
Main Features:
- ongoing monitoring of operational equipment,
- detection of deviations from normal behavior,
- Identification of indicators of compromise,
- contextual evaluation of alerts,
- Integration into existing security operations.
Secure Access – Controlled Access for Employees and External Vendors
Service providers, manufacturers, and in-house technicians often need to access IoT devices remotely—for maintenance, updates, and other purposes. Traditional VPNs often grant users access to a larger portion of the network than is strictly necessary.
Claroty xDome Secure Access restricts access to specific devices and for specific purposes. It leverages Zero Trust principles and privileged access management features, provides centralized control over remote sessions, and logs all access and communication.
Main Features:
- access to specific devices and systems,
- permission management based on role and purpose,
- access control for external suppliers,
- monitoring of remote connections,
- Auditability of service interventions.




































