← Back to Protect Critical Machines and DevicesSolutions · Protect Critical Machines and Devices · FAQ

Frequently Asked Questions

Plain answers to the questions we hear most about Faction's cyber assured Zero Trust hardware gateways

Basics
What is a Faction Pod — and a Portal?

Faction Pods and Portals are purpose-built, assembled-in-USA, ORION Assured Zero Trust hardware gateways that extend Zero Trust to a physical location over Wi-Fi and Ethernet. Connect any device behind one — smart, dumb, or legacy — and it joins your private, owner-controlled Faction Network: unreachable from the public Internet, reachable only by you, with nothing installed on the device itself.

A Pod suits smaller sites and distributed teams; a Portal is the higher-capacity appliance for factories, business locations, and larger device fleets.

What's the difference between a Pod and a Portal?

Both bring devices behind them into your Faction Network the same way — the difference is capacity and reach:

  • Pod — compact and low-cost, ideal for small offices, home offices, and distributed sites.
  • Portal — higher capacity for factories, business locations, and larger fleets.

Additional models address specialized needs, including a long-range HaLow Portal for industrial, agricultural, and smart-infrastructure sites (on the roadmap).

What kinds of devices do Pods, Portals & Outposts secure?

Anything that connects — regardless of age or capability — and especially the OT and IoT that software-only tools can't protect:

  • IP cameras and the video streams they produce
  • Industrial controllers, PLCs, and SCADA equipment
  • Factory-floor machines, legacy and modern
  • Sensors, robots, and automation systems
  • Building systems — HVAC, access control, elevators
  • Medical, lab, point-of-sale, and kiosk devices
  • Printers, scanners, and network-attached storage
  • Legacy equipment that can no longer be patched
Do I need to install software on my devices?

No. Protection lives in the Pod or Portal, not on the device. Devices are protected simply by connecting behind it — no agent, no OS changes — so even devices that can't run software are covered.

Deployment options
What are the three ways to get one?

Once it is on your network, every option works the same way: the same Faction Network security, the same adoption, the same owner-controlled keys. What differs is the cyber assurance of the networking hardware itself.

  • Faction Pods & Portals — Pods and Portals: Faction hardware running Faction firmware, purpose-built, assembled in the USA and ORION Assured.
  • Faction Outpost — an Outpost: an FCC-certified router from an OEM we have screened, which we configure, test and ship. You scan and adopt.
  • Faction Canopy — Faction Canopy: hardware you already own, brought under Faction protection using Faction's tools and guidance.

Compare the options →

What is an Outpost?

An Outpost is a qualified OEM device that Faction curates, configures, tests and supplies. It takes the machines and devices behind it off the public internet and onto your Faction Network, exactly as a Pod or Portal does. The names Pod and Portal are reserved for Faction-built hardware running Faction firmware.

Equipment behind an Outpost is protected the same way as behind a Pod: off the public internet, reachable only from inside your Faction Network, with nothing installed on the equipment itself.

Is an Outpost as secure as a Pod or Portal?

The security of your Faction Network is the same: identical architecture, identical key control, identical isolation of the equipment behind it. Keys and certificates are controlled and issued by you, the Network Owner, and Faction's platform has no access.

What differs is the assurance of the networking hardware. A Pod or Portal has known provenance, a Faction-controlled boot environment, a per-unit provisioning record and ORION assurance. An Outpost runs on third-party hardware, so the residual risk in that hardware is higher.

Can an Outpost be ORION Assured?

A Faction Outpost can: because we hold the unit, putting its model through the ORION process is a planned option for buyers who need it — defense and federal, typically.

A router you enable with Canopy cannot. A device already in the field cannot go through the ORION process.

Which routers are supported?

We support only OEMs and models certified by the FCC for sale in the US, and none from an entity on the FCC Covered List. The same models are supported for Faction Outposts and Canopy. Each is tested at a stated firmware version; if you enable your own hardware with Canopy, you verify that your device matches it.

The supported list is published once our testing is complete. Canopy can also be used with hardware that is not on the supported list, but you are then on your own: its provenance, firmware and security risk are yours to assess.

What is Faction Canopy?

Faction Canopy is Faction's enablement and configuration offering for compatible hardware you already own. It brings the machines and devices behind that hardware onto your owner-controlled Faction Network. There is no new hardware to buy, and nothing is installed on the equipment you are protecting.

Canopy is not a device and not software. It is the third way to get onto a Faction Network, alongside Faction Pods and Portals and Faction Outposts — the difference is whose hardware it runs on.

Who does the work with Canopy, and who holds the keys?

By default your own people do: your IT team, your MSP or your integrator, working from Faction's documentation, guidance and command-line tools. Faction also offers premium support and services if you would rather we took it on.

Whoever does the work, the keys are generated on the device itself. The private half stays in your keystore, and Faction never has access to it. That is the same for every deployment option.

Should I choose an Outpost or Canopy?

Choose an Outpost when you want Faction to supply the hardware: a qualified OEM device we curate, configure, test and ship, ready to scan and adopt. Choose Canopy when you already own compatible hardware and want to bring it under Faction protection without buying anything new.

All deployment options provide the same Faction Network security and owner-controlled cryptographic trust. Hardware provenance and assurance vary by deployment option. Where hardware assurance matters most, choose Faction Pods and Portals.

Security & privacy
How do Pods & Portals keep devices secure?

Three principles:

  • Owner-created keys. Adoption uses your Faction Network key, created and held on your own devices. No one else — including Faction — has it.
  • Out-of-band authentication. A direct invitation and key exchange that isn't exposed to external observation or attack — no phishable credentials.
  • Network invisibility. Once adopted, everything behind the Pod is off the public internet and reachable only from inside your Faction — removing the internet attack surface.
Can Faction see my data or my devices?

Your devices are visible and controlled only by you. Faction routes your encrypted traffic but holds no keys and cannot read what you protect — that's Zero Knowledge as a property of the architecture, not a policy promise.

Are Pods & Portals assembled in the USA — and how are they cyber-assured?

Yes. Faction Pods are purpose-built, assembled in the USA through our partnership with Z-AXIS, and ORION Assured. Portals, available from Q1 2027, will be built the same way.

ORION tests the Faction platform and the hardware model together — identifying vulnerabilities, reporting them, and verifying the mitigation. We also work with independent cyber labs on forensic inspection.

Vulnerability and patch monitoring after deployment is coming soon, through our partnership with OSec.

Don't VPN routers and firewalls already cover this?

No. The devices Pods protect typically can't be secured by a VPN router — they lack the resources for encryption or a programmable interface, or they're legacy and IoT with no modern OS. And firewalls only wall off parts of a network; they're routinely bypassed and don't make devices unreachable. A Pod takes the device off the internet entirely and into your owner-controlled network.

There's a deeper problem: many of the consumer and business routers people rely on are the foreign-made gear the FCC has placed on its Covered List as an unacceptable national-security risk. Layering a VPN on top of a compromised router doesn't fix it. Faction Pods, Portals and Outposts are purpose-built, assembled in the USA and ORION Assured — and they take your devices off the internet rather than trusting the router in front of them.

What if I'm worried about smart hardware already inside my network being compromised?

Great question — it's exactly the threat the FCC and U.S. cyber officials are warning about: foreign-made routers and smart devices that may already be pre-positioned inside ordinary networks. Faction is built for this:

  • Take it off the internet. Bring the device behind a Pod or Portal and it becomes unreachable from the public Internet — cutting off the path an attacker uses to reach it or call home.
  • Contain what you can't replace. Owner-controlled trust and micro-segmentation with Groups keep a questionable device isolated, so even if it is compromised it can't move laterally to anything else.
  • Secure what you already run — don't rip-and-replace. Faction's services and software secure the hardware you already run, and replace only what genuinely can't be brought up to standard with purpose-built, ORION Assured Pods and Portals.

You don't have to trust the gear that's already there. You put it inside a network whose keys and control belong only to you.

What about micro-segmentation with Cloud SDNs and ZTNA platforms?

Cloud SDNs and ZTNA platforms can micro-segment software-defined traffic — but they are software running on top of your network, and that is the limit. They can't put an agent on a camera, a PLC, or a legacy machine, and they still trust the routers, switches, and smart devices underneath them. If that hardware is the foreign-made gear on the FCC's Covered List — or a Trojan-horse smart device — the compromise sits beneath the layer the software controls, and segmenting the traffic above it doesn't help. Most also depend on a cloud control plane that becomes a high-value target of its own.

Faction is different because it is hardware-native:

  • Pods & Portals bring the device itself off the public internet and into your encrypted, owner-controlled overlay — no agent required.
  • Groups give true micro-segmentation, each with its own keys: access is binary — you hold the key, or you have no access at all.
  • Faction's own hardware isn't the weak link — Pods, Portals and Outposts are purpose-built, assembled in the USA and ORION Assured, so you aren't segmenting on top of hardware you can't trust.
  • There is no cloud control plane off which to pivot — trust and keys belong to you.
Deployment & cost
How fast is setup?

Click, Scan, Adopt — done. Connect the Pod to your modem or router by Ethernet or Wi-Fi, scan the QR code on the device in the Faction app, then connect the devices you want to protect. There's nothing to install on the devices, and you can organize them into Groups if you like.

My facility is large and spread out — is it expensive to deploy?

No. Pods, Portals and Outposts are low-cost and flexible, with models for different ranges and capacities. Deploy as many as you need. Support is simple too: if a unit ever fails, replace it and re-adopt it in seconds — no support calls or hours of troubleshooting.

I have custom needs, or existing routers I've standardized on.

Talk to us — and look at the three ways to get started. Rather than ripping out and replacing what you run, Faction's services and software lay owner-controlled trust over your existing networks, devices, and workloads:

  • Deploy alongside your current infrastructure — no rip-and-replace, no service interruption.
  • Owner-controlled trust — trust relationships and keys originate with your organization, not a vendor.
  • Out-of-band cryptographic identity for users and devices — eliminating the phishable credentials and interceptable authentication traffic that cloud identity platforms expose.
  • Secure existing hardware in place, and replace only what genuinely can't be brought up to standard — with Cyber-Assured Pods, Portals and Outposts.
  • Reach OT & IoT that software-only models can't, and adopt Zero Trust at your own pace.

If the routers you have standardized on are on our supported list, you can also bring them under Faction protection with Canopy. For specialized hardware we can work with you, and with OEMs as needed, to meet custom requirements.

Own your trust. Keep your peace of mind.

The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.

Get Early Access

Put a Pod or Portal in your own environment and see it bring your hardest devices under owner-controlled trust.

Get Early Access

MSPs & MSSPs

Deliver Cyber-Assured hardware to your clients and manage every fleet from one place.

MSP / MSSP Program