





























A Faction Outpost, ready to adopt
Easily secure access to all your OT, IoT and ICS machines and devices with flexible hardware options. Minimal IT staff required, and no rip-and-replace of existing hardware or network infrastructure.
Faction Network security, on curated 3rd party hardware we prepare and ship. A Faction Outpost is a qualified OEM alternative to a Pod or Portal: a screened third-party router that Faction curates, configures, tests and ships, sitting at your local network boundary. It takes the machines and devices behind it off the Internet and onto your Faction Network.
Once prepared, the Outpost can only connect to your Faction Network, and any machine or device behind it is unreachable from the public Internet. You keep local admin access to the router.
Faction Outposts sit behind your existing modem, router or other upstream gateway, which are never trusted. Every connection is authorized by keys you control, and the Outpost's only route for that equipment is the encrypted tunnel to your Faction Network.
That mitigates the threats from vulnerable or compromised foreign-made routers and smart hardware already inside your networks. No additional firewall to deploy or configure, no software agents on endpoint devices, no rip-and-replace of existing hardware or network infrastructure.
Owner-controlled keys
Your keys are created by you at adoption, generated on the device, and distributed only to authorized members. Faction prepares the unit for you to adopt locally, and never has access to your keys.
Full local control
You keep full local administration of the router. Faction manages only what it set, and the Faction app is designed to tell you if the device has been changed outside it.
Simplicity
Manage Faction Outposts and all the machines and devices connected to them in your Faction app. Use Faction Groups to segment access and permissions with ease.
Turn-key
It arrives as a Faction Outpost, configured and tested. Plug it in and adopt it on your local network: nothing to install or configure, and we support it. Where hardware assurance matters most, choose Faction Pods & Portals.
Plug it in
Behind your existing modem or router, by Ethernet or Wi-Fi.
Open the Faction application
A desktop application or command-line tool, on the same local network.
Adopt it
It joins your Faction Network on your local network, and your own keys are generated on the device.
Connect your equipment
Behind it. Nothing is installed on the equipment.
A Faction Outpost has no direct internet access, so it sits behind your existing modem or router rather than replacing it. Nothing about your current internet connection changes, and nothing you connect behind it needs a change to its hardware or software.
- Owner-controlled keys. Keys and certificates are controlled and issued by the Network Owner, and distributed only to authorized members. Faction never has access to them.
- Off the public Internet. Equipment behind the Faction Outpost has no path to the Internet, and is reachable only from inside your Faction Network.
- Out-of-band authentication. A direct key exchange that isn't exposed to external observation or attack.
- Nothing on the equipment. No agent, no software and no changes to the machines you protect.
- Zero knowledge of content. Faction never has access to your keys, so it can never read your data. It sees only the routing metadata of encrypted traffic crossing your Faction Network.
- Zero anonymity of action. Every action on your network is tied to a verified device or user, and that record is under your control.
- Contained by design. A compromised machine or device behind it can't reach the Internet or call home, and Faction Groups limit what it can reach.
Pre-screened
- OEMs and models are selected based on testing and consultation with our Cyber Assurance partners to ensure that our implementation is secure.
FCC-certified
- FCC-authorized for sale in the US, and not on the FCC Covered List. The model's own firmware is not changed.
Tested and supported
Each model is tested against the four criteria below at a stated firmware version before it ships.
- A secure tunnel for the encrypted Faction connection.
- Local access only, with vendor cloud access restricted or off.
- A firewall that denies by default.
- NAT for the network behind it.
ORION Assured
Optional: For military, government and enterprise customers, the ORION Assured process can be applied.
Nation-state threats
Nation-state and ransomware actors increasingly target OT, IoT, ICS and the hardware supply chain — not just data for users and applications.
Rob Joyce — China's cyber explosives are in placeFCC Router Mandate
The FCC's Covered List stops new foreign-produced routers from being authorized, but does nothing about the ones already deployed. Faction contains the risk from those already inside your networks, with no rip-and-replace.
FCC Covered List — foreign-made routersEvery FCC Covered List action in 2026AI and technical debt
AI is amplifying attacker capability exponentially, against equipment that already carries decades of unpatched technical debt.
AI meets decades of technical debtFaction Pods & Portals
Faction purpose built. Faction hardware running Faction firmware: Purpose Built, Assembled in USA, ORION Assured.
See Faction Pods & PortalsFaction Canopy
Customer owned. Keep your hardware. Faction enablement and configuration for compatible hardware you already own.
See Faction CanopyGet your OT, IOT and ICS off the Internet
Order a Pod, Portal or Outpost ready to adopt or bring hardware you already own under Faction protection with Canopy. Same Faction Network, same owner-controlled keys.



