A vehicle stops where no vehicle should.
A camera the site already owned sees a vehicle dwell on the access road, hours after the last authorized visit. On its own this is nothing: a note, not an alarm. EXCOM logs it and keeps watching.
Cyber-physical intelligence for critical infrastructure
EXCOM combines physical behavior intelligence with cyber threat context, turning disconnected signals from your facilities into one operational picture your teams can investigate and act on.
Request a briefing
EXCOM is a joint cyber-physical offering in partnership with RedSkyAlliance RedXray.
Software only, built to run on compliant cameras and edge compute you procure.
No facial recognition. Appearance-based continuity, ephemeral by design.
Raw video stays on site. Only detections, tracks, and incidents leave the edge.
You deploy and operate it. EXCOM has no standing access to your data.
Runs fully disconnected on premises when the environment requires it.
No EXCOM cloud holds your data: your infrastructure or your own government-cloud subscription.
Related detections collapse into one scored incident with the full timeline attached. Your operators triage a developing situation, not a queue of disconnected alarms.
A camera the site already owned sees a vehicle dwell on the access road, hours after the last authorized visit. On its own this is nothing: a note, not an alarm. EXCOM logs it and keeps watching.
A person leaves the vehicle and holds position beside the west fence. Behavior, not pixels: presence, duration, and place, measured against how this site normally moves at four in the morning. Severity rises, and the reason is written down.
Three observations, one story. EXCOM correlates the vehicle, the loiter, and the crossing into a single scored incident with the full timeline attached, so the operator triages one developing situation, not a queue of disconnected alarms.
Illustrative example.
The operator acknowledges, investigates, resolves: one picture across every site, with cyber exposure from the partner feed raising physical posture when it matters. Every action lands in a tamper-evident audit trail. At 04:31 the incident closes, before the cut, not after the outage.
Processing runs at the site, on infrastructure you control. Video stays inside your operational environment; only security events and metadata move to systems you authorize. Built to protect OT, ICS, and facility operations without adding exposure.
Related detections collapse into one scored incident with the full timeline attached. Your operators triage a developing situation, not a queue of disconnected alarms.
A common operational picture across every site: live map, incident board, acknowledge, investigate, resolve. When cyber risk against a facility rises, physical posture and severity tighten with it, with the reason attached. Every action lands in a tamper-evident audit trail.
Capabilities
Continuous physical security intelligence for substations, water utilities, data centers, and distributed industrial sites, including remote and lightly-manned perimeters.
Cyber exposure monitoring and physical detection in one program: cyber indicators linked to physical consequences for OT, ICS, and building systems, with RedXray as the partner cyber feed.
Understand movement patterns around protected zones: approach behavior, prolonged presence, unauthorized access routes, and activity outside expected operating windows.
A more complete view of risk: physical observations and cyber threat context in one picture, so escalation decisions come faster and better grounded.
The same behavior engine covers every vertical below. Zones, lines, and time windows are configuration, not custom code.
Perimeter breach, copper-theft staging, fence-line loitering, transformer-approach tampering, after-hours anomaly, correlated into one incident per attack chain.
Chemical-storage access, perimeter breach, after-hours movement, and vehicle activity across large, lightly-manned perimeters, deployed through site configuration alone.
Tailgating at controlled doors, after-hours presence, unauthorized-visitor behavior.
Track trespass, cable-theft staging, abandoned objects, platform crowding.
Yard intrusion, restricted access, gate and truck behavior, convoy movement.
Theft staging, vehicle intrusion, tamper approach on remote, low-connectivity sites.
Vehicle presence, loitering near line assets, route deviation along corridors.
Tailgating, lobby and visitor anomalies, loitering at controlled perimeters.
EXCOM ships software only, designed to run on compliant camera and compute hardware procured by the customer, for example Axis, Hanwha Vision, Bosch, Pelco cameras and NVIDIA Jetson edge compute.
No facial recognition. Multi-camera continuity uses pseudonymous, appearance-based identity that is ephemeral by design.
Raw video stays on site. Only event metadata (detections, tracks, incidents) leaves the edge node.
On-premises, air-gapped, or in the customer’s own Azure Government / AWS GovCloud subscription. EXCOM operates no cloud that holds your data and has no standing access to it; any support access is customer-authorized and audited.

EXCOM and RedSkyAlliance share a single operational model: RedXray cyber exposure intelligence and EXCOM physical behavior intelligence, engineered together as one cyber-physical risk program.
A briefing walks your operators through the live console against scenarios from your own sector.