Back to cybriq.io The Cross Family is part of CybrIQ
CrossTrust
CrossTrust
Documentation you can check.

Half your network documentation is wrong. This tells you which half.

Point CrossTrust at the folder your drawings, switch configurations and spreadsheets already live in. It reads them, finds the places where your own documents contradict each other, and cites both sides down to the line number and the spreadsheet cell.

It reads and never writes: your files are left exactly as they are. It runs on your own machine, and nothing about your documents leaves it.

CrossTrust showing one disagreement: a switch configuration says the AV controller is on VLAN 512 while the estate spreadsheet says 340, each cited to its exact position, with CrossTrust declining to choose between them.

One disagreement, both sides cited. And a product that hands the question back when it cannot answer.

The problem

Nobody knows which document to believe, so everybody goes and looks.

There is a Visio drawing from the last refresh, a spreadsheet somebody has been maintaining since 2019, a folder of switch configs pulled during an audit, and a wiki page three people have edited. Every one of them describes the same network. No two of them agree, and none of them says how old it is.

So the real record becomes the walk to the comms room. Every change request starts with somebody physically confirming what a document already claims to say, because the document has been wrong before and nobody can tell you when it started being wrong.

The documentation is not missing. That is the frustrating part. It is there, it cost real money to produce, and it sits unused because acting on it is a gamble.

How it works

It separates what was said from who said it.

That is the whole engineering idea, and everything above falls out of it. A fact and a source are stored apart, so ten documents saying the same thing is one fact confirmed ten times, and two documents disagreeing is two sources on one question with neither overwriting the other.

  • It reads what you already have Visio drawings, switch configurations, spreadsheets in both Excel formats, CSVs and PDFs with a text layer. Configurations are recognized by what is inside them rather than by the file extension, across 11 configuration languages. It installs nothing on your network and asks nothing of your devices.
  • Every fact keeps the exact place it came from A line in a config, a row and column in a spreadsheet, a shape on a Visio page, a character range in a PDF. That is why you can check any finding in about a minute, which is the only reason anyone will ever act on one.
  • It shows you the file list before it opens anything You get the list of what it can read, what it will skip and why, and then it waits. A file it cannot handle is named on that screen, never dropped quietly, so the gaps in the answer are visible before the answer exists.
  • It finds the passwords in your documentation 13 credential rules run before anything is parsed. It tells you the file and the line, records that a credential is there, and never stores the credential itself. A file it cannot read safely is held back and named individually. It never joins the clean pile.
  • It audits the switch settings while it is in there 71 settings checks, 33 of them from the 252 requirements published for Cisco IOS and NX-OS switches, mapped to 252 NIST SP 800-53 control entries. Findings are counted by problem rather than by switch: telnet being on across six hundred switches is one thing to fix, not six hundred rows to read.
  • The second run is the one that pays It tells you what changed since last time, and what you already answered stays answered. That is the only screen in the product that reports progress, and progress is the thing nobody has ever been able to show for documentation work.

See it work

Three documents about one network.

A switch config, a Juniper config and an estate spreadsheet, all describing the same small campus. Watch what falls out of reading them together.

CrossTrust Demo data
1

Start here. You will point it at a folder, watch it read three documents, and find the one thing they disagree about. It takes about a minute.

CrossTrust documentation you can check Sample

Sample data: the three documents CrossTrust ships in samples/Network Records. Every finding on these screens came out of the real engine reading them.

The limits

It reads documents. It does not read your network.

CrossTrust never touches a device. Everything it knows about your estate came out of a file you already had, which is what lets it run with no credentials and no access to anything. When it says a switch is set a certain way, it means a configuration file in your folder says so, and it dates that file on the screen so you can weigh it yourself. If you want the network read directly, that is CrossScan and CrossConnect, and they are separate products.

There is no model in here and no assistant. Every format it reads is structured, which is why two runs over one folder give the same answer. It cannot read Word documents, scanned images or the old Visio format, and it names those files on screen instead of pretending the folder held nothing else. A PDF with no text layer needs to be scanned properly before it is worth anything to anyone, and CrossTrust says so.

Exactly one thing in the product reaches the internet: a button that checks whether the published requirements it checks against have been revised. It sends nothing about your machine or your documents, and it only ever runs when you press it.

The refusal

It had a satisfying answer available, and it turned it down.

Every tool in this category resolves a conflict by ranking the sources and declaring a winner. The switch config beats the spreadsheet, so the answer is 512, and the report reads beautifully. CrossTrust could have printed that. Here is why it did not, and why that is the reason to trust the answers it does print.

1
The config was not stronger. It was only newer. Both sources came out at the same weight: the VLAN was worked out from a port description rather than read from the device, so the config is reasonable evidence and not proof. Two sources of equal weight disagreed, and the engine said so in those words rather than reaching for the tiebreak nobody would have questioned.
2
A refusal on its own is useless, so it keeps going. It prints what each answer would cost you: pick 512 and the spreadsheet is wrong and needs correcting; pick 340 and the config is. It prints the stakes in your terms. Then it names the one thing that can close the question, which is a command on a specific switch, because the switch is the only party to this argument that actually knows.
3
And when it does pick, it says what it is doing. A strict win is the only thing that gets adjudicated: the value has to be legal, outrank every source that disagrees, and be no older than any of them. Anything short of that comes back as a question for you rather than an answer from it. The refusals are what make the verdicts worth reading.

What it handed back for AV-CTRL-01

Question
Which VLAN is this on?
Says 512
IDF-A-SW-03.txt, line 13 (via the port description at line 11). The switch’s own settings, dated 2025-03-04 from the configuration-change header.
Says 340
estate-inventory.csv, row 4, column vlan. A record somebody typed, dated 2023-04-11 from the last_audited column.
Verdict
CrossTrust does not choose here. It reads two sources of equal weight disagreeing, so it does not choose between them.
Settle it
Find the switch port this device is plugged into and read its configuration. The switch is the only thing here that knows what the device is actually on, rather than what somebody recorded.

Nobody wrote that. The engine did. Note what the last line is: a job for one person, at one switch, that ends with the question closed for good.

Answer it once and it stays answered. Your correction survives the next run, and the run after that. If a document later says something new underneath your answer, CrossTrust brings the question back before your decision keeps standing on evidence that has moved.

The AV argument

It knows a Q-SYS core from a camera, and it knows what the switch owes each of them.

This is the part a general documentation tool cannot do, and the part an AV integrator will recognize in about four seconds.

An audio system on a network with no multicast querier will pass every ping you throw at it. The link stays up, the device answers, the monitoring is green, and the audio drops out somewhere between thirty seconds and five minutes after it starts working. It is the single most common cause of an AV system that passes commissioning and fails in week two, and it is invisible to every tool that checks whether a thing is reachable.

CrossTrust recognized the Q-SYS core and the Biamp Tesira in the demo from the port descriptions an engineer typed years ago, matched them to the equipment families that carry a clock in multicast, and checked what the switch underneath them was doing about it. It found no querier, no snooping, and no priority for the audio. It matches 52 equipment names and markers, from Q-SYS and Biamp to the plain word codec, sorts them into 6 equipment families, and checks which of four network controls that family actually needs. A Dante device needs three. A control processor needs one.

That is an argument you can take to a room full of people who each believe the problem belongs to somebody else, and it is worth about two site visits every time it lands.

The honesty rule

Its own coverage table names the things it cannot do yet.

The screen that lists what CrossTrust does with each make of switch is generated from the running build rather than written by hand, so a check that gets deleted stops being advertised the same day. Cisco IOS comes out at 27 settings of 27. Aruba CX comes out at 20 of 27, and the seven it cannot check are listed by name in the last column.

A support matrix with a tick in every box is a matrix nobody is checking. This one is uneven, it says so on the About screen where a prospect will find it, and every number on that screen is counted rather than claimed.

Before you ask

The eight questions we get on the first call.

What access do you need?

None. CrossTrust never contacts a device, so there is no credential to issue and no account to create. You point it at a folder on your own machine and that is the whole of it.

Will it change anything?

It reads and never writes. Your drawings, configs and spreadsheets are left exactly as they were, and nothing is installed on your network.

How long until I have something useful?

As long as it takes to read the folder. There is no rollout, no collection window and no baseline period, because the documents already exist.

Does this replace the tools I already run?

No. Nothing you own reads your documentation and checks it against itself. CrossTrust does that one job and hands the result to whoever maintains the records.

What happens when it is wrong?

It refuses. When two sources disagree and neither outweighs the other, CrossTrust declines to pick a winner, shows you both cited to the line, and tells you the one command that settles it.

Can I start with one documentation set?

That is the unit of work. One folder for one site. If what comes back is useful you point it at the next folder.

What data leaves my environment?

Nothing. It binds to 127.0.0.1 on the first free port in 8400 to 8430, reachable only from the machine you run it on. Your documents never leave that machine.

Will it work in a restricted or air-gapped environment?

Yes, and better than most things will. It needs no network access at all: no device to reach, no credential to pass, no service to call. A folder and a laptop is the entire dependency list.

What happens next

Four steps, and you can stop after any of them.

  1. Install it on your laptop. A double-click launcher, or a .dmg on macOS. Nothing touches your network.
  2. Point it at the folder your documentation already lives in. Drawings, switch configs, spreadsheets, CSVs and PDFs with a text layer.
  3. It reads them together and reports where they disagree. Both sides cited to the line number and the spreadsheet cell.
  4. Decide which document to fix. Or run the one command CrossTrust names, and settle it for good.

The buying unit is one documentation set. One site's folder, checked, before anybody decides whether the rest of the estate is worth the same treatment. No seat count and no platform commitment.

You already paid for this documentation. Find out what it is worth.

Point it at the folder. It takes about thirty minutes to go from downloading it to reading a list of the places your own records contradict each other.