Industrial Asset Management Built Around Trustworthy Evidence
OTserver keeps discovery evidence, human decisions, and access boundaries together in one self-hosted inventory.
Inventory that survives network changes
Every asset is identified by its normalized MAC address, not an IP address, device name, or serial number. Records without a usable MAC are skipped instead of being attached to the wrong device.
- Track vendor, model, firmware, protocols, ownership, location, status, criticality, and custom fields.
- Search with the graphical filter builder or the supported Lucene query syntax.
- Define asset classes and automatic manufacturer/model classification rules.
Evidence-aware imports
OTserver accepts three discovery formats:
| Source | Format | What it preserves |
|---|---|---|
| OTserver Otter | Schema-version-2 JSON | Observations, interfaces, ports, topology, warnings, and field quality |
| Siemens PRONETA | XML topology export | High-quality Siemens-oriented device and topology data |
| Nmap | XML produced with -oX | Existing generic discovery workflows |
Field values follow an explicit quality order:
| |
Stronger evidence can improve weaker data. Weaker evidence cannot overwrite stronger data, and manual edits remain authoritative.
Network topology
Inspect the selected site’s assets and connections in the network topology view. Solid links show recorded connections; dotted links distinguish inferred membership.
Sites, roles, and accountability
Build a hierarchy with the site types and depth your organization uses. Grant users read-only or read/write permission at any site; access applies to its descendants. The protected Admin role retains unrestricted access.
Every registered collection is audited. The immutable audit log records inventory and authentication changes while redacting fields that resemble passwords, secrets, tokens, hashes, or sessions.
Native read-only discovery
The scanner is called OTserver Otter — a Rust CLI and GUI that runs on Windows, Linux, and headless AArch64 Linux and exports evidence directly for OTserver. It uses fixed identity requests and does not perform configuration writes, SNMP SET, DCP Set, brute force, exploits, vulnerability scripts, or Modbus requests. Every protocol can be turned on and off independently. Otter is developed alongside the application on GitHub: OTserver and OTserver Otter.
Explore the protocol discovery guides, read the Otter guide, or deploy OTserver.




