Air-Gapped · Edge AI · Vendor Agnostic

Nuclear-grade cybersecurity for commercial energy systems

Cortex AI is an on-site intelligence platform that brings air-gapped network security and autonomous energy optimization to commercial buildings — at 1/200th the cost of enterprise solutions.

~$1K
Hardware Kit
Air-Gapped
OT Network Security
5+
Vendor Protocols
Cloud-connected building equipment is under active attack
Commercial BTM energy systems route control signals through the public internet with no network isolation. In April 2026, CISA, FBI, and NSA confirmed state-affiliated actors are actively exploiting internet-facing industrial controllers — manipulating HMI displays to blind operators while modifying control logic.
🛡

No Cybersecurity Baseline

BTM systems expose operational technology directly to the internet. No air-gapped isolation exists between control networks and public-facing infrastructure. DOE CESER (2022) flags this as a critical gap.

HMI/SCADA Exposure

Internet-connected Human-Machine Interfaces let attackers manipulate operator displays, masking unauthorized changes to energy systems. The April 2026 Rockwell advisory documented this exact attack vector.

💰

$200K+ Enterprise Security

Traditional air-gapped solutions cost hundreds of thousands in hardware alone, putting nuclear-grade network security out of reach for commercial and industrial facilities.

🔄

Multi-Vendor Fragmentation

3–5 vendor protocols per site, custom controls engineering at every deployment, $14K–$28K in integration costs. No unified interface, no coordinated dispatch, no consistent security posture.

Cloud Dependency

Cloud DERMS platforms create vendor lock-in with recurring SaaS fees while routing safety-critical dispatch decisions through internet-connected infrastructure.

📉

Rising Demand Charges

~5 million U.S. commercial customers face demand charges representing 30–70% of electricity bills. Data centers, electrification, and EV charging are pushing peak demand higher.

Five-layer edge architecture with air-gapped security
A two-device hardware kit — edge compute unit plus dedicated air-gap security gateway — deployed on-site. No cloud dependency for dispatch. No inbound internet path to connected equipment.
01

Air-Gapped Network Security

Dedicated security gateway enforces unidirectional data flow (egress-only), VLAN-isolated control planes, and a DMZ accepting only pre-defined inputs. Consistent with IEC 62443-3-2 and NIST SP 800-82 Rev. 3. Zero inbound internet exposure.

02

Perception Layer

Translates Modbus TCP, local REST, MQTT, and cloud APIs into a common device model across battery, solar, EV, HVAC, and monitoring systems.

03

State Layer

Live building model — per-circuit loads, battery SOC, solar production, EV sessions, HVAC setpoints, and utility tariff structure — updated in real time.

04

Reasoning Layer

On-site AI proposes dispatch decisions, adapts to unusual conditions, and explains every action in natural language. Replaces static if/then rules with intelligent optimization.

05

Safety Envelope

Deterministic safety constraints enforce battery SOC limits, inverter ratings, EV minimums, and HVAC comfort bounds. If AI is unreachable, automatic fallback to rule-based dispatch.

How air-gapped architecture stops active attacks
In April 2026, CISA, FBI, and NSA confirmed Iranian APT actors exploited internet-facing Rockwell Automation PLCs across U.S. energy and water infrastructure. Here's how the attack unfolded — and exactly where Cortex AI's architecture breaks the chain.
✘ Internet-Exposed (Rockwell Attack)
1

PLCs left internet-facing

CompactLogix and Micro850 controllers directly accessible from the public internet. No network segmentation.

2

CVE-2021-22681 exploited

Authentication bypass in CIP protocol allowed unauthorized Studio 5000 connections to production PLCs.

3

Project files extracted

Attackers downloaded operational logic and configuration data from running controllers.

4

HMI displays manipulated

SCADA/HMI screens altered to mask unauthorized changes — operators couldn't see what was happening.

5

Operational disruption & financial loss

Facilities experienced service disruptions with no visibility into the root cause.

✔ Air-Gapped (Cortex AI Architecture)
1

OT network air-gapped

Dedicated security gateway isolates all control equipment from the internet. Zero internet-routable addresses on the OT network.

2

CVE-2021-22681 unexploitable

Authentication bypass requires network access. With no inbound internet path, the vulnerability exists in firmware but cannot be reached remotely.

🛡 Attack chain broken
3

Unidirectional data flow

Even at the perimeter, data diodes enforce egress-only telemetry. No commands can flow inward. Studio 5000 write operations are architecturally impossible.

4

DMZ blocks unauthorized protocols

Only pre-defined, validated data inputs traverse the DMZ. CIP traffic from an unauthorized engineering workstation is dropped at the boundary.

5

Operations continue uninterrupted

Edge AI handles dispatch locally. HMI displays show verified local data. No external dependency, no attack surface.

Source: CISA/FBI/NSA Joint Advisory, April 7, 2026 — Iranian APT exploitation of Rockwell Automation/Allen-Bradley PLCs (CVE-2021-22681)
Nuclear-level security at commercial-level pricing
Traditional air-gapped enterprise solutions price out every commercial facility. Cortex AI delivers the same network isolation at a fraction of the cost.
Traditional Enterprise
$200K+
Network monitoring hardware alone. Full deployment often exceeds $1M with integration, SIEM, and ongoing vendor contracts.
vs
Cortex AI
~$1,000
Complete two-device kit: ~$600 edge compute + ~$400 air-gap security gateway. Pre-configured, activated remotely. No on-site engineering.
Built by operators who've lived the problem
1,100 MW of solar in service. $2.5B advisory pipeline. Licensed EPC in DC, MD, VA, and CA.

Dan Lee

Managing Partner & Project Lead

Former U.S. Department of Energy, Morgan Stanley, GE Ventures, Head of US Low Carbon at Bechtel. Harvard Kennedy School MPA, Wharton MBA. NABCEP PV Associate.

John Nguyen, PE

Principal & Technical Lead, Cortex AI

Licensed Professional Engineer & Master Electrician. 10+ years at LA Department of Water and Power. Developer of the Cortex AI platform. Wharton MBA, BS Civil Engineering.

Trevor Chang

Principal, C&I Deployment & VPP Strategy

Virtual Power Plant and distributed energy specialist. ~$2B prior real estate transaction experience. Wharton MBA, dual BS EECS & Finance from MIT.