





























Keep your hardware. Bring it under Faction protection.
Use Canopy to bring compatible hardware you already own onto your Faction Network to secure access to all your OT, IoT and ICS machines and devices.
Faction Network security, on hardware you already own. Faction provides a suite of services, support, tools and/or AI Skills that enable you to convert existing hardware into a Faction network node.
Once enabled, it can only connect to your Faction Network, and any machine or device behind it is unreachable from the public Internet. You keep local admin access to and control of your hardware. Compatibility identified by Faction.
Your Canopy-enabled hardware sits behind your existing modem, router or other upstream gateway, which are never trusted. Every connection is authorized by keys you control, and its only route for that equipment is the encrypted tunnel to your Faction Network.
That mitigates the threats from vulnerable or compromised foreign-made routers and smart hardware already inside your networks. No additional firewall to deploy or configure, no software agents on endpoint devices, no rip-and-replace of existing hardware or network infrastructure.
Owner-controlled keys
Your keys are created and controlled only by you, shared only with the members of your Faction Network, and Faction never has access to them.
Full local control
You keep full local administration of your hardware. Faction manages only what it set, and the Faction app is designed to tell you if it has been changed outside it.
Simplicity
Manage your Canopy-enabled hardware and all the machines and devices behind it in your Faction app. Use Faction Groups to segment access and permissions with ease.
Check compatibility
Against Faction's supported list.
Enable it
Have Faction enable your compatible hardware with Canopy.
Verify
Each step is checked to confirm it took effect, and your hardware generates its own keys.
Connect your equipment
Behind it. Nothing is installed on the equipment.
Not the router running your network. Use spare hardware or purchase a model from our supported list through your own procurement.
- Owner-controlled keys. Keys and certificates are controlled and issued by the Network Owner, and distributed only to authorized members. Faction never has access to them.
- Off the public Internet. Equipment behind your Canopy-enabled hardware has no path to the Internet, and is reachable only from inside your Faction Network.
- Out-of-band authentication. A direct key exchange that isn't exposed to external observation or attack.
- Nothing on the equipment. No agent, no software and no changes to the machines and devices you protect.
- Zero knowledge of content. Faction never has access to your keys, so it can never read your data. It sees only the routing metadata of encrypted traffic crossing your Faction Network.
- Zero anonymity of action. Every action on your network is tied to a verified device or user, and that record is under your control.
- Contained by design. A compromised machine or device behind it can't reach the Internet or call home, and Faction Groups limit what it can reach.
Compatible models
FCC-authorized for sale in the US; compatibility identified by Faction. Each compatible model is tested at a stated version; you verify your firmware matches before enabling.
Your own choice
Your hardware, your call: you can enable hardware we don't support, but you are then on your own. Its provenance, firmware and security risk are yours to judge.
Devices compatible for Canopy conversion require:
- A secure tunnel for the encrypted Faction connection.
- Local access only, with vendor cloud access restricted or off.
- A firewall that denies by default.
- NAT for the network behind it.
Limitations:
- No hardware assurance on either route: hardware already in the field cannot go through the ORION process. Where hardware assurance matters most, choose Faction Pods & Portals.
- Hardware enabled with Canopy is protected by default-deny to the extent possible while keeping it usable. You keep local administration access, and are responsible for that security and meeting our requirements.
Available option:
- Monitored: vulnerability and patch monitoring through our partner OSec, coming soon. It covers the cyber integrity of your Faction Network, and does not extend to the hardware itself or its vendor firmware.
Nation-state threats
Nation-state and ransomware actors increasingly target OT, IoT, ICS and the hardware supply chain — not just data for users and applications.
Rob Joyce — China's cyber explosives are in placeFCC Router Mandate
The FCC's Covered List stops new foreign-produced routers from being authorized, but does nothing about the ones already deployed. Faction contains the risk from those already inside your networks, with no rip-and-replace.
FCC Covered List — foreign-made routersEvery FCC Covered List action in 2026AI and technical debt
AI is amplifying attacker capability exponentially, against equipment that already carries decades of unpatched technical debt.
AI meets decades of technical debtFaction Pods & Portals
Faction purpose built. Faction hardware running Faction firmware: Purpose Built, Assembled in USA, ORION Assured.
See Faction Pods & PortalsFaction Outpost
Faction curated. A screened third-party router we prepare, test and ship. Plug it in behind your existing router and adopt it on your local network.
See Faction OutpostNot sure your hardware qualifies
Send us the make and model. We will tell you where it stands, and it tells us what to validate next.


