Skip to content

Security appliance

PLDrop

Penetration Testing Through a Box You Post, Not a Person You Fly

A sealed appliance you plug into your own network, which then becomes the single audited channel for penetration testing — internal, web, external, API and Wi-Fi. Every session opens only on the customer's approval, lasts exactly as long as they allow, can be cut mid-session, and leaves a per-command record in the customer's own storage.

  • Penetration testing
  • Security appliance
  • Zero retention
  • Audit trail
  • On-device AI

overview

What it is

PLDrop answers the question every security buyer actually asks about remote testing: if I let an outsider onto my internal network, what stops them going somewhere else? The appliance is posted to the customer and plugged into their network, and from then on it is the only route a tester has in — approved per session, time-boxed by the customer, revocable mid-session, and recorded command by command. The tester's environment is a sealed workspace inside the box, supervised by a model running on the device itself, and every record is written to storage the customer owns. The travel line disappears from the invoice; the evidence line appears in the audit file.

capabilities

Key features

Nothing Opens Without Approval

Access is granted per session by the customer, for a lifetime they set — and a live session can be revoked mid-command. There is no standing access to leave lying around.

The Unit Only Dials Out

No port on the device faces the internet, so there is no inbound path for anyone else to find. The audited channel is the only way in.

The Tester Works Inside a Sealed Workspace

The consultant gets one Linux workspace and the tools — and that is the whole of what they can reach. The uplink, the keys and the record sit outside it.

On-Device Supervision

A purpose-trained model on the device watches that workspace for an attempt to leave it, for work outside the agreed scope, and for data moving by volume or by class. Findings leave the unit; the traffic does not.

Records to the Customer's Own Storage

Every command and transfer is bound into a tamper-evident record written to the customer's own bucket. Remove a line and the record stops verifying.

Wireless Testing On Board

The hardware unit carries its own radio for Wi-Fi work — the one thing a software-only deployment cannot do. A virtual build covers everything that does not need a radio.

why it matters

Benefits

  • No flights, hotels or travel days on the testing invoice — the work is done through the unit.
  • The customer approves each session, sets how long it lives, and can cut it while it is running.
  • A dated, per-command, tamper-evident record lands in the customer's own storage — the evidence an assessor asks for.
  • The tester is boxed in by design, and the box is watched by a model that does not stop when the engagement does.
  • Internal, web, external, API and Wi-Fi testing through one audited channel instead of several ad-hoc ones.

in practice

Use cases

A regulated organization that needs recurring internal testing without repeatedly hosting an on-site consultant.
A multi-site business where sending a tester to every location is the real cost of the programme.
A security team that must show an auditor exactly who was approved, by whom, for how long, and what they ran.
An enterprise that will not let engagement data leave its own storage.

get in touch

Let's talk

Interested in PLDrop, or want to see how it could fit your work? Email is the best way to reach TRAGenX — send us a note and we'll get back to you.