Adversarial validation for systems that cannot fail.
Tropiro is building an AI-assisted product security lab for industrial software, gateways, HMIs, firmware, and edge devices. The lab is designed for vendor-authorized validation inside isolated, restoreable ranges—away from live operations.
03Control boundary
HMI · protocol · engineering station
example boundary
04Simulated process
Controller · field I/O · safe state
LAB-FIRSTVENDOR-AUTHORIZEDSAFETY-BOUNDEDEVIDENCE-BACKEDOPERATOR-INFORMEDBUILDING IN PUBLIC
Open work
The first control is implemented, not implied.
RANGESPEC / 0.1.0Verified component
Machine-readable authorization before execution.
RangeSpec is an offline-first schema and command-line tool for declaring exact targets, permitted actions, time and rate limits, safe state, stop conditions, recovery evidence, approvals, and evidence handling.
Public release 0.1.0 is live with passing GitHub Actions verification.
The problem
When software touches the physical world, failure stops being abstract.
Industrial products now connect decades-long equipment lifecycles to cloud portals, remote support, APIs, and rapidly changing software.
Tropiro is being designed for the gap between a conventional product scan and evidence that a vulnerability can cross a real trust boundary. The first mission is controlled validation away from live operations—where products can be challenged, restored, fixed, and tested again.
01 / RECREATE
Build the representative range
Recreate the product's deployment boundaries with vendor-provided hardware, firmware, software, identities, protocols, and simulated field behavior.
Firmware
Gateway
HMI
02 / CONSTRAIN
Define the safety boundary
Set the authorized assets, safe states, maximum impact, stop conditions, recovery path, and human approvals before active validation begins.
Safely validate authentication, update, remote-access, protocol, and trust-boundary failures without exposing a live process to experimental activity.
Reproduction
Bounded impact
Audit trail
04 / CLOSE
Close and replay
Give product engineers the evidence and recovery context they need, then replay the exact scenario to prove the fix closes the path.
finding / fixed / verified
Current status RangeSpec 0.1.0 is publicly released with passing CI. The physical range, customer service, and field capability do not yet exist; Tropiro does not test live industrial or safety-critical environments.
Operating model
No test without a safe state.
In critical systems, finding a flaw is never more important than protecting the process. Authorization, containment, recovery, and operator judgment come first.
01
Vendor authorization
Named owners, exact assets, written scope, exclusions, disclosure contacts, and test windows are verified first.
02
Disconnected range
Representative systems remain separated from live operations, with target allowlists and independent stop controls.
03
Defined safe state
Every scenario has maximum impact, stop conditions, recovery instructions, and named human approval.
04
Recoverable evidence
Every action is attributable and reviewable; every environment begins from a restoreable baseline.
Start with the people who build and integrate the equipment.
▣
Product suppliers
Teams building industrial gateways, remote-access products, HMIs, device-management systems, firmware, and edge platforms.
⌁
System integrators
Organizations that assemble and maintain industrial solutions and need evidence that product and access boundaries hold.
↳
Critical software maintainers
Teams maintaining software foundations used across industrial environments, with the capacity to triage and remediate findings responsibly.
Founding principle
Trust is earned in the lab before it is requested in the field.
Tropiro is founder-led and recruiting experienced OT security leadership. We are learning from product suppliers, integrators, and maintainers before selecting equipment or offering customer testing.
Founder / building since 2025
Christopher Yanez
Computer Science student at the University of Central Florida, building open-source authorization and evidence foundations for lab-based industrial product security.
Tropiro is an early-stage founder-led project. Christopher owns the current product and engineering work while recruiting the experienced OT security leadership required before external industrial assessment work begins.
Not as a generally available service. RangeSpec 0.1.0 is public as the first open-source foundation; the lab, OT leadership, and external assessment capability are still in development.
Will Tropiro test live industrial systems?+
No. The initial service is lab-only. Future field work would begin through established OT partners and operator-approved passive validation before any active scenario is considered.
Can Tropiro test any target I provide?+
No. Testing is limited to vendor-owned products, Tropiro-owned labs, or assets covered by explicit written authorization. Ambiguous scope and high-risk safety systems are excluded.
Is Tropiro affiliated with a model provider?+
No affiliation or program approval is claimed. The planned architecture is provider-independent and will use frontier models only where access, authorization, and operating controls permit.
Product discovery
Help shape the first lab workflow.
If your team builds industrial software or equipment that can be assessed away from a live process, we want to understand the validation work that is slow, repeated, or difficult to prove.