Deployment posture

Local-first, offline-capable, noinbound path

ProtectionAI is a Windows desktop application with a local database. It runs and activates without an internet connection, and the only outbound call it can make is to the AI provider you choose to configure.

The shape of the deployment

One workstation, one local database

There is no server component to harden, because there is no server component.

ProtectionAI installs as a self-contained .NET 9 desktop application on a Windows 10 or Windows 11 x64 machine. It needs local administrator rights to install and roughly 500 MB of disk space for the application itself. After that it is an ordinary user-mode application.

Test data, settings versions, asset records, attachments and completed test sessions are held in a local SQLite database on that machine. Backup, retention and access control for that file follow your existing workstation and endpoint policies — the same ones that already govern the setting sheets and test records on the same laptop.

Nothing exposes an inbound control service or accepts remote commands. When an engineer explicitly opens the SharpPcap/Npcap transport, ProtectionAI can capture and inject Layer-2 IEC 61850 frames on the selected interface. That controlled local adapter access is distinct from an inbound application service and must pass the site's OT security review.

Facts a reviewer will want

Deployment and data handling

Runs offline
No internet connection is required to run tests or to activate a licence. A machine that never reaches the internet is a fully functional installation, minus the optional copilot.
Local storage only
A SQLite database plus the files you export. No cloud sync, no shared workspace, no GridAPM-hosted storage of your test data or your settings.
No OT connectivity
There is no inbound listener. IEC 61850 work starts on deterministic loopback; a physical SharpPcap/Npcap NIC path exists but must be explicitly selected and confirmed isolated — it is local raw Ethernet, not a cloud service, and requires separate OT-network qualification. There is no SCADA or historian connection.
Outbound traffic
One optional destination: the AI provider API you configure. If you never configure a provider key, the application runs and licenses without needing outbound network access.
Provider key at rest
Your AI provider API key — Anthropic, OpenAI, xAI/Grok or Google/Gemini — is encrypted at rest with Windows DPAPI, scoped to the machine and user context that stored it. GridAPM never receives it.
Licensing
A 7-day trial with no key, then an RSA-signed per-computer licence. Activation is offline and machine-bound; there is no licence server to reach and no check-in that can fail in a basement.

The copilot

What leaves the machine, and only when you enable it

The honest answer to the data-residency question depends entirely on one setting.

With no API key configured, the copilot is inert and no content is sent anywhere. The whole test workflow — import, plan, run, review, report, file — is available manually and stays on the machine.

With a key configured, ProtectionAI calls the provider you chose, directly from your workstation, when you use the copilot. What goes into those calls is the material the copilot needs for the step you asked for: your prompt, the relevant part of the working settings model, the retrieved passages from the relay manuals you ingested, test results being interpreted or written up, and any attachment you deliberately add. There is no GridAPM endpoint in the path.

That means the provider's own terms, retention behaviour and regional processing apply to that traffic, and they are worth reading before you enable the copilot on data you consider sensitive. Manual retrieval over your ingested PDFs is performed locally; it is the model call that leaves the machine, not the search index.

For your reviewer

What a security assessor should verify

Verify rather than accept. Everything below is observable on a test machine during the 7-day trial.

  • Install on an isolated Windows 10 or 11 x64 machine with no internet route and confirm the application starts, runs tests against the simulator and produces reports.
  • Confirm the SHA-256 of the downloaded installer matches the published value before you execute it.
  • Confirm the installer is self-contained: no additional runtime, framework or prerequisite is fetched during installation.
  • With no AI provider key configured, monitor outbound connections during a full test session and confirm no traffic is required.
  • Activate a licence with the machine offline and confirm activation completes without any network call.
  • Locate the local SQLite database file and confirm it falls inside your existing workstation backup, encryption and retention policy.
  • Confirm the stored AI provider key is not recoverable in plaintext from the configuration, and that it is protected by Windows DPAPI under the storing user context.
  • If the copilot will be enabled, capture the outbound destinations during copilot use and confirm they resolve only to the provider you configured.
  • Review your chosen AI provider's data-processing and retention terms as the applicable processor for copilot traffic, since GridAPM is not in that path.
  • Verify that IEC 61850 starts in deterministic loopback, that physical mode requires explicit selection and isolated-network confirmation, and that only the intended NIC receives or injects GOOSE/SV frames. Keep Npcap uninstalled where physical networking is outside the approved scope.
  • Exercise the report export path and confirm the generated Word, Excel, PDF and CSV files contain only what you expect to leave the machine.
  • Decide who may install and activate, since installation requires local administrator rights and licences are bound per computer.

What we do not claim

The limits of this page

This page describes deployment and data-handling properties of the software. It is not a certification, an attestation, a penetration-test result or an audit report, and it does not assert conformance to any security framework. Where you need assurance rather than description, ask — the procurement page lists what to request.

We also make no telemetry claim beyond what is stated here: the application runs and licenses fully offline, and the copilot is the one feature that requires an outbound network path. Verify that behaviour on your own machine during the trial rather than taking a sentence on a website as evidence.

ProtectionAI is a testing and record-keeping tool. It does not authorise, approve or perform switching, and it produces no output that should be treated as an operational instruction to a live protection system.

Try it for seven days and check the claims yourself

Install ProtectionAI on a Windows machine, import your own XRIO or RIO settings, run the plans you would really run against the built-in simulator and export a report on your own letterhead. No key is needed for the trial, and no internet connection is needed to run it. When you want a per-computer licence, email sales@gridapm.com.

Type to search research, platform pages, and tools.