Elantis
Maritime and offshore OT assurance. One evidence language across dissimilar assets, collected inside the access window the asset actually allows.
MeruEPC engineers deploy to the site, work the problem in front of them, and build the thing that fixes it. Our assurance products are what remains afterwards — method earned in control rooms, on platforms, and aboard vessels over two decades, not assembled in a conference room.
We do not write the report and leave. We do not ship the box and hope. Our engineers deploy to the asset, work the problem that is actually in front of them, and what remains afterwards becomes a product. The product is the residue of the deployment — never the other way round.
If an engagement ends and nothing has entered the platform, we treat it as a failure — however well it was delivered.
That standard is why our products look the way they do. Every one of them started as a problem someone handed us on a site, under real constraints, with a running process that could not be stopped.
Energy and maritime infrastructure does not sit in a data centre. It sits offshore, at sea, on a plant floor, at a berth, and in a substation — each with its own access constraint, its own safety case, and its own reason the assessor cannot simply walk up to it.
Everything we build resolves into three lines. Each one exists because a deployment forced it into existence — and each one is where the next deployment's learning goes.
Evidence about the state of an OT environment, produced to a consistent method so that findings from different assets can be compared and defended.
Assurance work that has to happen where the assessor cannot easily go — at the gateway, at the boundary, on assets that are remote, unmanned, or only reachable in scheduled windows.
Operating knowledge sits with a small number of experienced people, and it walks out of the door with them. This line addresses continuity of engineering judgement across the asset lifecycle.
Services, training, and AI capability sit across all three lines rather than beside them — they are how a line reaches an operator, not separate offerings. The full index of what we deliver is below.
The complete list of products and services, grouped as an operator would buy them.
Assurance that reaches every asset.
Elantis helps maritime and offshore operators build a consistent, evidence-led view of OT assurance across remote and safety-critical assets.
OT-localised LLMs and agentic automation deployed on your infrastructure — on-premise or air-gapped, human-approved, fully auditable. Automates evidence review, compliance mapping, and reporting.
How it works →Offline IT/OT configuration assurance. Turns exported network-device configurations into prioritised security findings and defensible assessment evidence — no credentials, no connection to the device.
What it analyses →Risk assessments, gap assessments, and architecture reviews for rigs, plants, vessels, FPSOs, and renewables — IEC 62443 zone & conduit method, P×C scored, evidence-backed.
Scope & method →Plant-safe adversarial testing: passive analysis on live systems, active exploitation only in FAT, staging, and offline replicas. Real attack-path validation without risking a running process.
Discuss scope →IACS UR E26/E27 readiness for newbuilds and fleets: vessel asset mapping, control implementation, test & acceptance design, and class-notation evidence packs — aligned to IMO MSC.428(98).
Maritime track record →Fifteen expert-led programs across five tracks — OT, Maritime, Corporate, Family, and Intelligence — from ICS/OT fundamentals and CyberHAZOP to UR E26/E27 resilience. Delivered worldwide, in-person or virtual.
View training catalogue (PDF)Elantis helps maritime and offshore operators build a consistent, evidence-led view of OT assurance across remote and safety-critical assets.
When asset access is difficult, assurance evidence cannot be optional.
One fleet. Different exposure. One evidence language. Vessels, chartered assets, drilling rigs, and offshore installations each carry a different combination of systems, people, rules, and risk — and charters, port calls, maintenance windows, and vendor changes move the boundary continuously. A fleet-level assurance decision still needs evidence that compares across all of it.
Elantis makes the evidence method travel to the asset, rather than asking the asset to wait for an assessor.
An assurance approach built for safety-critical environments: no configuration changes to OT systems, no cloud dependency, and no requirement to treat control, power, bridge, or cargo systems like ordinary IT endpoints.
Evidence can be gathered without routing a specialist assessor to every hull and rig. Assurance stops being constrained by access, sailing schedules, and mobilisation logistics.
Consistent evidence across assets and repeat cycles builds a defensible baseline, clear exceptions, and traceable proof of remediation — not a one-time observation.
AI is used where it adds speed and consistency — comparing patterns and surfacing insight inside an assessor-led process. It never executes on the asset, changes an OT configuration, or authorises a risk decision.
Qualified people retain context, technical judgement, and accountability at every stage.
MeruGuard is an offline IT/OT configuration-assurance platform that transforms exported network-device configurations into prioritised security findings and defensible assessment evidence.
MeruGuard analyses exported IT and OT device configurations to uncover risky firewall rules, weak management services, segmentation gaps, legacy security settings, and industrial-protocol exposure. It works locally, requires no device credentials, and produces prioritised, audit-ready evidence.
MeruGuard is a configuration-assurance and evidence-generation platform. It supports security assessments, remediation planning, and compliance activity by making the current state of your network configuration visible, comparable, and defensible.
A configuration review tells you what your devices are currently permitting. Judging whether that is acceptable remains the work of qualified assessors — which is exactly where MeruGuard hands off.
Some assets cannot be visited on demand. Access is scheduled, weather-dependent, or governed by an operating window that closes long before the assessment is finished.
The Edge line exists because the same problem kept appearing across different sectors: the assurance method was sound, but the asset was unreachable often enough that the evidence was always out of date by the time a decision needed it.
Our approach is to move the evidence method to the boundary — collecting what can be collected at the gateway, under the constraints the site actually imposes, so that assurance does not stall while it waits for travel, a window, or a shutdown.
This line is in active development. We would rather describe it accurately now than overstate it and correct it later.
Operating knowledge sits with a small number of experienced people, and it walks out of the door with them.
Across every sector we work in, the same risk surfaces late: the engineer who understands why a system is configured the way it is, what was tried before, and which constraints are real rather than habitual — retires, transfers, or moves to another operator. What is left behind is documentation that records decisions but not judgement.
The Continuity line addresses continuity of engineering judgement across the asset lifecycle. It is delivered through field deployment rather than sold as a shelf product, because the work only makes sense in the context of a specific asset and a specific operating history.
Further detail is available under NDA.
Products, engineering capabilities and delivered services across the three lines. Filter by line to see what each one actually contains.
Maritime and offshore OT assurance. One evidence language across dissimilar assets, collected inside the access window the asset actually allows.
Offline configuration assurance. Reviews exported firewall, router and switch configurations without credentials and without connecting to a live device.
Zone-and-conduit modelling, scored findings and a remediation roadmap sequenced around turnaround windows rather than calendar quarters.
Factory and site acceptance testing for vendor packages, so that what was written into FEED is verified before handover rather than assumed.
Asset mapping, control implementation and test design for the operating context shaped by IACS UR E26/E27 and IMO MSC.428(98).
Testing designed around a running process — passive where it must be, active only where the safety case and the operator explicitly permit it.
Assurance evidence collected at the boundary, so the position does not go stale waiting on travel, a weather window or a shutdown.
A controlled, tamper-evident collection kit built around real site conditions — write-blocked, sanitised between assets, and manifested on return.
Method designed for unmanned, low-bandwidth and scheduled-window assets, where assessor travel is the binding constraint on assurance.
Addresses the risk that operating knowledge concentrated in a few experienced people leaves with them. Delivered through field deployment, scoped per asset.
Multi-agent automation of evidence review, control mapping and reporting. Every action passes a human approval gate before it reaches an operational system.
Local deployment inside the security perimeter — on-premise or air-gapped — so plant documentation and findings never leave the operator's environment.
Engineers embedded with planners and process engineers to map the real workflow before a single agent is built. The plant comes first, the automation second.
Evaluating AI and agentic systems proposed for operational environments: what the model can influence, where the gates sit, and what evidence exists if a regulator asks.
Fifteen programmes across five tracks, written for people who run plant and sail ships rather than for people who run security operations centres.
Policy, standards mapping and audit support built for the operating context shaped by IEC 62443 — not lifted from an enterprise IT framework.
Our track record was built inside national oil companies, petrochemical complexes, ports, and classed vessels — not conference rooms. We don't name clients. Our references speak privately, which is how critical infrastructure prefers it.
Two decades across upstream, refining, and petrochemicals in the GCC and Asia — from wellhead RTUs to plant-wide DCS estates.
Vessel and port OT security delivered under class-society and IMO expectations — where connectivity risk sails with the ship.
We do not name clients — critical infrastructure prefers it that way, and so do we. What we can describe is the kind of operator we sit across from, and the question they arrive with.
Upstream, refining, and petrochemical estates where DCS, SIS, and packaged vendor systems have accumulated over decades, each assessed by whoever was available at the time.
Owned and chartered assets under IMO and class expectations, where the boundary moves with every charter, port call, and vendor change.
Newbuilds and greenfield plants where cybersecurity was written into FEED but never verified at factory acceptance, site acceptance, or handover.
Terminal operating systems, cranes, gate automation, and berth control where operational continuity and commercial systems have quietly converged.
Wind farms, solar PV, battery storage, and substation automation — distributed by design, unmanned by default, and reachable only through the gateway.
Any of the above, at the point where engineering judgement is concentrated in a handful of people and no handover document captures why the decisions were made.
Engagements described by shape rather than by name. Every one of these fed something back into a line.
We do not name clients. What we can describe is the pattern: the operating constraint we met, and what it forced us to build. Each of these entered one of the three lines.
Access to the asset was limited to scheduled windows governed by weather and operations. A conventional assessment could not complete inside one, and restarting it lost continuity each time.
Owned and chartered assets carried different systems, vendors, and reporting habits. Every asset had evidence; none of it could be compared, so no fleet-level decision could be defended.
Architecture documents described zones and conduits confidently. The device configurations permitting traffic told a different story, and connecting to live devices to check was not acceptable.
By the time an assessor could reach the asset and report, the environment had changed. The assurance position was always describing a state that no longer existed.
Field-derived engineering only works if the engineers are actually in the field. These are the two roles the whole method depends on — assessors who verify physically, and engineers who build beside the people running the process.
Our assessments happen on rig decks, vessel bridges, and plant floors — walking zones and conduits physically, verifying what drawings claim, and talking to the operators who live with the systems every shift.
Our engineers embed inside your operation — sitting with planners, operators, and engineers to map real workflows first, then building AI agents around them: localised, human-gated, and shaped to how your plant actually runs.
Independent assurance is our core service: telling you, with evidence, whether your OT environment is as secure as your paperwork says it is.
Structured, standards-based assurance of your OT environment — zone-and-conduit risk assessment, control validation, compliance audit, and evidence-backed findings scored by probability × consequence across safety, environment, financial, and reputational impact. Independent, vendor-neutral, and written for both the boardroom and the control room.
Purdue-model segmentation, DMZ design, remote access, and industrial network transport reviewed against how attacks actually move — not how diagrams look.
IEC 62443-aligned policies, procedures, and security programs mapped to regional regulation — written to be operated by your teams, not filed away.
OT-specific response plans, playbooks, and tabletop exercises that respect a running plant: you cannot simply pull the plug on a live process.
Security engineered into capital projects from FEED and detail design through cyber FAT at vendor factories, cyber SAT during commissioning, pre-startup review, and secure as-built handover.
Independent, capability-scored evaluation of OT security vendors and packages — and prioritised remediation roadmaps sequenced around turnarounds, legacy constraints, and operational risk.
OT cybersecurity training for engineers, operators, and leadership — grounded in the standards and incidents that shape your sector.
We don't sell AI. We engineer it to work safely where it matters: localised language models deployed on your infrastructure, inside your security perimeter — air-gapped where required — so nothing about your plant ever leaves your plant.
Local LLMs on your hardware, in your data centre or at the edge. No cloud dependency, no external API calls, no data egress. Suitable for air-gapped and sovereign environments.
Nothing generated by a model reaches an OT system without explicit human authorisation. Approval gates are enforced in the architecture — not promised in a policy.
Every input, output, and approval is logged and traceable. If a regulator or operator asks "why", the evidence trail already exists.
Not demonstrations. Work delivered into live energy and maritime environments, under the same constraints as everything else we build — on operator infrastructure, behind human approval, and auditable after the fact.
Multi-agent automation of evidence review, control mapping, and reporting — the repetitive analytical work that consumes assessor time. Every action passes a human approval gate before it reaches an operational system.
Local model deployment inside the security perimeter — on-premise or air-gapped — so that plant documentation, configurations, and findings are never processed outside the operator's own environment.
Engineers embedded with planners, operators, and process engineers to map the real workflow before a single agent is built. The workflow comes first; the automation is shaped around how the plant actually runs.
Structured evaluation of AI and agentic systems proposed for operational environments: what the model can influence, what it cannot, where the approval gates sit, and what evidence exists if a regulator asks why.
On the ground in the UAE, serving oil & gas, petrochemical, and utility operators across the GCC — aligned to UAE NESA/IAS and regional regulatory expectations.
contact@meruepc.com →MeruEPC Pte. Ltd. — our registered base and Asia hub, serving maritime, ports, and energy clients across Southeast Asia and the wider APAC region.
contact@meruepc.com →VyomEPC Private Limited — our India entity, delivering SCADA and engineering support, instrumentation & automation cybersecurity, and OT expert services to pipeline and energy operators across India.
contact@meruepc.com →A single assessment, a full assurance program, or a question about running AI safely inside your OT environment — reach us directly by email and we will route you to the right specialist.