Industry · Military & Law Enforcement

Owner-controlled Zero Trust for military and law enforcement

Faction delivers enterprise-grade Zero Trust at a fraction of the cost of Enterprise SDN or ZTNA — protecting your vulnerable OT & IoT, data, and communications without rip-and-replace

Military installations and law enforcement agencies carry strict obligations and sit high on the target list — bases, stations, depots, field sites and the vehicles and systems that serve them, often with aging equipment that cannot simply be retired and minimal IT staff and budgets. Faction provides an architecture where trust is owned and controlled by the organization, and protection extends to the OT, IoT, and legacy systems traditional tools can't secure.

Do You Know Your True Risk?

Military and law enforcement networks are a top target. State-sponsored actors — the campaign known as Volt Typhoon — have pre-positioned inside U.S. critical infrastructure, and Salt Typhoon penetrated major telecom networks in one of the most damaging breaches in memory. The FCC has determined that foreign-made routers pose an unacceptable national-security risk, and many are already in agency networks.

Pre-positioned
State-sponsored actors have embedded in U.S. critical infrastructure to enable disruption
CISA / NSA joint advisory, 2024
Salt Typhoon
Chinese actors breached major U.S. telecom networks — among the most damaging breaches in memory
Congressional / press reporting, 2024–25
“Fair game”
The FBI warns the PRC treats every sector that makes society run as a target
FBI, April 2024
A single breach reaches far

Disrupted operations

Missions, patrols and facility operations knocked offline when systems go down.

Compromised data

Case files, evidence and operational data exposed or exfiltrated.

Cross-agency spread

A breach in one system reaching others through shared dependencies.

Public trust

Eroded confidence in the institutions people depend on.

Where the risk lives

Networking

  • Legacy and OT systems spread across installations, stations and field sites
  • Shared services whose compromise can cross agency boundaries
  • Foreign-made routers now flagged as a national-security risk, already in agency networks
  • Secure remote and field access for personnel and contractors

Devices

  • Building controls — HVAC, power, access control, elevators
  • Legacy systems on unsupported or unpatchable operating systems
  • Everyday smart gear — printers, cameras, UPS — used as a way in
  • Field and remote endpoints beyond the office

Data

  • Case files, evidence and operational data kept confidential
  • Communications between agencies, units and partners
  • Data downloaded onto contractor and staff BYOD devices
  • Controlled, auditable sharing across agencies
How Faction secures military and law enforcement
01

Virtual Private Circuit (VPC)

Take agency networks, applications, and devices off the public internet into a circuit only you can see and reach — then segment and micro-segment it with Groups, so a compromise in one area can't cross into another.

  • IT, OT, and legacy systems on one circuit
  • No public exposure to scan or reach
  • Identity-based access between segments
  • No shared control plane to cross agencies
02

Owner-Controlled Keys & Zero Knowledge

Encryption keys are created and held by the agency and never leave your devices. Faction routes traffic but has no access to what you protect.

  • Operational and evidence data encrypted end to end
  • Keys stay with the agency, not a vendor
  • Encrypted in transit and at rest
  • No third party in your trust path
03

Zero Trust, Identity-Based Access

Every user and device is authenticated and authorized; nothing anonymous can reach the circuit — aligning directly with federal Zero Trust direction.

  • Out-of-band Zero Trust authentication
  • Scoped, time-limited contractor access with audit trails
  • Step-up to verified human identity (iValt, roadmap)
  • No anonymous movement on the network
04

Cyber-Assured Hardware — Pods & Portals

Faction's own purpose-built, Cyber-Assured networking hardware brings legacy and OT systems into the circuit with no agent. Pods and Portals are Purpose Built, Assembled in USA, ORION Assured — independently tested by ORION, the public-private partnership between the Air Force Research Laboratory and AIS — a direct answer to the foreign hardware now flagged by the FCC.

  • Reach building controls and legacy systems
  • No agent, no patching of the device
  • Assembled in USA, independently tested by ORION
  • Deeper assurance through AIS for military, government and enterprise customers
Protects · Facility OT and building controls, vehicle and surveillance systems, legacy systems, and the records and communications agencies hold
05

Encrypted Data & Ransomware-Proof Backup

The Faction Data Security Suite keeps files, email, and media encrypted under your keys — and backs them up where only you can decrypt them.

  • Keep the email and cloud tools staff already use
  • Every file encrypted under your own keys
  • Owner-keyed backup that can't be ransomed
  • Share across agencies without broad exposure

Secure the infrastructure you already have — don't rip and replace it

What about the foreign-made routers on the FCC's Covered List, or the decades-old systems a station or installation can't simply retire? Ripping out and replacing infrastructure that delivers public safety is slow, expensive, and disruptive.

Deploying a Faction Virtual Private Circuit is the faster, lower-cost path. You secure the machines and devices that matter by choosing from three flexible options — Faction Pods and Portals, Faction Outposts, or hardware you already own enabled with Canopy — and you can pick one or mix and match.

  • Secure existing networking hardware in place rather than replacing it.
  • Replace only what can't be brought up to standard — with Cyber-Assured Pods & Portals.
  • No rip-and-replace project and no service interruption.
  • Reach Zero Trust on your timeline and budget.

Bring everything from PLCs to IP cameras onto your owner-controlled network — reachable by what you need, unreachable from the public Internet. No agents, minimal IT support, no rip-and-replace.

A worker in a hard hat using an industrial touchscreen control panelOrange industrial robot arms along an automated production lineA wall-mounted outdoor security cameraTwo electric vehicle charging stations with cables connectedA round smart thermostat on a wallA desktop network attached storage unit with its drive bays exposed

Supports federal and CJIS requirements

Cryptographic isolation, owner-controlled keys, and identity-based access map to the mandates military and law enforcement organizations answer to — applied to the OT, IoT, and legacy systems traditional tools can't secure.

CJIS Security Policy

Criminal justice information protected with owner-controlled keys and scoped access.

NIST 800-53

Access control and system & communications protection mapped by the architecture itself.

Federal ZT (M-22-09)

Identity-based, least-privilege access; nothing anonymous reaches a system.

Audit & Accountability

Full, scoped logs of who and what reached each system.

Supply-Chain Risk

Scope and time-limit access for vendors and contractors, with audit trails.

FCC Router Mandate

Foreign-made routers pose clear risks and should be assessed for replacement or reconfiguration. Deploy a Faction Pod, Portal or Outpost, or bring hardware you already own under Faction protection with Canopy, to reduce exposure without rip-and-replace.

Own your trust. Keep your peace of mind.

The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.