Platform.

Context

Your sites, your roles, your equipment. The personas read it before they write a word, so the work comes back about your business, not a template.

ContextSeeded for you, then yours
Sites
Roles
Responsibilities
Equipment
Vendors

OSINT seeds context, then monitors it

The context above is built from public record, then monitored. A tool that alarms you about everything gets ignored, so only high-confidence matches against your model reach you.

Automated discovery
  • Sites and facilities
  • Leadership and roles
  • Operating technology
  • Products and brands
  • Suppliers and integrators
  • Domains and network edge
  • Regulators and obligations
  • Hazard exposure
  • Filings and public record

Target your own company, a supplier, or anyone you are about to sign.

Continuous monitoring
  • VulnerabilitySiemens controllerTechnology
  • VulnerabilityApache TomcatNo match
  • ICS advisoryRockwell AutomationTechnology
  • Regulation changeReaches your footprintCompliance
  • Lookalike domainRegistered this morningDomain
  • VulnerabilitySAP NetWeaverNo match
  • Leaked credentialsFound in a public dumpCredentials
  • Leak site listingA supplier of yoursSupply chain
  • Role changeNamed in a public profilePeople

Every match attaches to the part of your context it hit, and keeps the source it came from.

Documents

Policies, standards, procedures and risk registers. Every claim carries the source it came from.

DocumentsWritten with you
OT Security PolicyCurrent
Access Control ProcedureIn review
Risk RegisterDraft
Incident Response PlanDraft

Content generation writes them with you

Your content generation pipeline reads your context, finds the clauses that apply, plans the document, then writes it section by section. The document carries its own reference list.

Content generation
  1. Validating request
  2. Loading context
  3. Planning structure
  4. Writing sections
  5. Fabrication review
  6. Finishing up

You watch every step. When it finishes, open it in the workspace to read and edit.

OT Security PolicyDraft

Purpose and scope

Roles and responsibilities

Asset identification

Access control

Incident response

Sources

IEC 62443-2-1Used in: Roles and responsibilities, Asset identification
AWWA J100Used in: Asset identification
AWIA Section 2013Used in: Incident response

The reference list is part of the document. Each source names the sections it was used in.

Knowledge Base

The OT standards, ready to be pulled into the work. When a persona uses one, the document cites it.

Knowledge BaseCited by clause
ISA/IEC 62443
NERC CIP
NIST SP 800-82

Personas

OT security disciplines with a real role profile and a job to do. The platform recommends who belongs in the conversation, and you can override it.

PersonasRecommended for the task
GRC
Security Architecture
Intelligence
Security Operations
Engineering
Program Management
Procurement
Vulnerability Research
+More disciplines arriving

Flows

Every persona's work is packaged the way the app packages it: tracks, and the flows inside them. A flow is a real piece of work with a start and a finish. Pick one and the conversation walks it.

Flows · GRCPick one, walk it
GRCGovernancePolicy & StandardsMetrics & Reporting
Develop a GRC operating model for OT
Discuss how governance, risk and compliance divide across our program
Author or review the GRC calendar, artifacts and ownership

Conversations

Where the work happens. You and the personas walk one flow from a blank page to a finished document.

ConversationYou and the personas
GRC

Feeds

What the outside world publishes about your equipment, your vendors and your sector, matched to your context and told to you with the reason.

FeedsMatched to your context
AdvisoryNames your equipment
VulnerabilityNames your vendor
NewsNames your sector

Automations

The routine steps run on a schedule and come back for your sign-off. This is where the platform is headed, and the work is under way.

AutomationsRolling out
Refresh the advisories watchWeekly
Re-check documents against new rulesMonthly
Update your context from public recordWeekly

Routine work on a schedule, back for your sign-off. Nothing ships without you.

Agents, Workflows, Expectations.

Agents

Each persona carries an agentic profile matched to a real role: its responsibilities, its qualifications, its limits. We do not throw agents at everything. They are good for some things, and not others.

Workflows

Workflows guide you and the agents through a set of tasks, like corporate OT security documentation. That structure is why the work comes back accurate, and why it beats a chatbot.

Expectations

OT security knowledge sits behind six-figure budgets and 62443 experts while rural infrastructure gets attacked. There is no bar to entry here. Start wherever you are.

Plugin.

OT Security

Beta

The open-source and dedicated OT security knowledge bank and agent for learners, tinkerers and industry professionals. Right inside ChatGPT and Claude with no sign up required.

Cabreza is the only plugin for authoritative, trusted OT security information to search, synthesize and generate outputs directly from your chat.

We built this plugin for those who want to learn OT security, build assessments, questionnaires and training content. We help draft cited content for documentation, decks, messages and narratives for cyber security deliverables and fundamental best practices.

Using Cabreza's agentic framework and guardrails, we deliver ICS, OT and CPS outputs that intentionally avoid generic AI results. This is achieved through our toolset of flows, personas, context, and document generation, which are connected to our trusted and authoritative knowledge bank.

Dedicated OT security skills, tools, personas and knowledge that assist you where you work. That’s what you get. If you already use Cabreza, this plugin extends your workflows and connects directly to your Cabreza workspace.

Add it to Claude
  1. Open Settings, then Plugins.
  2. Click Add, then Add marketplace.On a Team or Enterprise plan, your admin adds it.
  3. Paste the name below, then click Sync.
  4. Click Install beside OT Security by Cabreza.
  5. Open the plugin, then its Connectors tab. Click Connect.Skip this last one and the skills load but the knowledge bank stays shut.
  6. When Claude first asks to use a Cabreza tool (“Claude wants to use … from Cabreza”), click Always allow (⇧⌘⏎).The long flows ask several questions in a row. Allow once lets one call through and the next question stalls; Always allow keeps the whole flow running.
Add it to ChatGPT
In the app
  1. Open Settings, then Plugins.
  2. Click Add, then Add a marketplace.No Add button? Turn on Developer mode under Settings, Security and login. On a Team or Enterprise plan, your admin adds it.
  3. Paste the name below, then click Add marketplace.
  4. Click Install beside Cabreza.
In the browser
  1. Go to chatgpt.com/plugins and click the plus.
  2. Name it Cabreza. Paste the address below.
  3. Set Authentication to Mixed.Pick OAuth and ChatGPT demands a sign-in before it shows you anything.
  4. Tick the box.
  5. Click Advanced OAuth settings and confirm what ChatGPT found.Cabreza's sign-in endpoints fill in by themselves — Dynamic Client Registration is pre-selected. Skip this and Create can close the window without making the plugin.
  6. Click Create.
  7. Enter your email, then Continue.Free to use — just an email. Verify it only to save context.

In Claude Code, run /plugin marketplace add CabrezaInc/cabreza-plugin and then /plugin install cabreza@cabreza.

View it on GitHub: github.com/CabrezaInc/cabreza-plugin

Try prompts like these

Click one to copy it, then paste it into ChatGPT or Claude.

Cabreza Product & the OT Security Plugin for ChatGPT and Claude