One-click network scan
Point it at your Wi-Fi or LAN and hit scan. A fast, read-only TCP-connect sweep finds every responding device in seconds and keeps the list fresh on every rescan — no setup, no agents, no router login.
A universal network scanner
One click maps your whole network: every connected device, what it actually is, the ports it has open, and the risks it carries. Then DeviceShelf keeps watch — alerting you when something new appears. All local. No account. No telemetry.
📡 One-click LAN scan 🖥 Mac · Windows · Linux · iOS · Android 🛡 Local-first, no telemetry
Inside the app
These are the views you actually use. Every value is populated by a live scan of your own network — no spreadsheets, no manual entry.
One click sweeps the whole subnet. Every responding device, with its IP, vendor and detected type — sorted, searchable, exportable.
Per-device deep dive: vendor from the MAC OUI, hostnames via DNS/mDNS/NetBIOS, OS guess from TTL, plus every open port with its detected service.
A prioritized security report: risk score, exposed dangerous services (Telnet, RDP, Docker API…), default-credential checks and CVE hints — with concrete fixes.
Background monitoring tracks who comes and goes, alerts on unknown devices, and shows live per-device bandwidth so you can spot what's hogging the line.
Stuck on an unknown device? Your own AI key identifies it from the network signals, summarizes the whole network, and answers plain-language questions.
A full toolbox built in: ping, traceroute, DNS lookup, speed test and Wake-on-LAN — no need to drop to a terminal.
Illustrative mockups — the shipping app looks even better.
For anyone who wants to know, fast: what's on the network, what each device is, and what's a risk.
Why DeviceShelf exists
One evening my router listed a device I didn't recognise — just a MAC address and an IP. Mine? A neighbour's? Something worse? The router's own page told me nothing useful, and the scanner apps I tried were either ad-riddled, cloud-bound, or stopped at a bare list of IPs.
I wanted the obvious thing: point it at my network and tell me what each device actually is — vendor, name, type, open ports — and flag anything risky. Locally. Without an account, without uploading my home network to someone's server.
So I built it. Scan, identify, watch, and warn — on every device I own, from my Mac to my phone. That became DeviceShelf.
— Christof, builder of DeviceShelf
Features
Three things stand out: a one-click scan that maps your whole network, deep identification that tells you what each device really is, and a security report that flags what's risky. Everything else builds on those three.
Point it at your Wi-Fi or LAN and hit scan. A fast, read-only TCP-connect sweep finds every responding device in seconds and keeps the list fresh on every rescan — no setup, no agents, no router login.
More than an IP list. DeviceShelf resolves the vendor (MAC OUI), hostname (DNS, mDNS/Bonjour, NetBIOS), OS (TTL, DHCP fingerprint) and device type — router, computer, phone, printer, camera, NAS, IoT — automatically.
A prioritized risk report for the whole network: exposed dangerous services (Telnet, RDP, ADB, Docker API, Redis…), default-credential checks, weak TLS, known-CVE hints and camera/privacy flags — each with a fix and a 0–100 risk score.
Per device, enumerate open TCP/UDP ports with service detection and banner grabbing. Quick, Standard, Deep (1–1024) and Full (1–65535) profiles, plus slow/normal/aggressive timing — you decide thorough vs. fast.
Background polling tracks which devices come and go and notifies you the moment an unknown device joins. Availability history with uptime and latency per device — perfect for spotting intruders or flaky gear.
See live throughput per device so you can tell what's actually using the line right now. Find the streaming box, the backup that's saturating the uplink, or the chatty IoT gadget at a glance.
Go further on any device: TLS grading and certificate inspection, SSH key fingerprinting, SMB share enumeration, UPnP model/serial, SNMP system info and nmap-style HTTP enumeration of common admin paths.
Ping with aggregate stats, streaming traceroute, DNS lookups, a connectivity health check and a built-in speed test (latency, download, upload) — the tools you'd otherwise juggle across five apps, in one place.
Power on compatible machines straight from the device list with a single tap. Great for waking a NAS, a desktop or a media server without getting up.
Export the device list to JSON or CSV, or generate a styled, shareable HTML report. Add custom names, notes and type overrides per device — they persist across scans. An optional local API and webhooks let you wire DeviceShelf into your own tooling.
Everything runs and stays on your device. No account, no sign-up, no telemetry, no analytics. Your license is verified offline with an ed25519 signature — no phone-home, ever.
The same scanning engine on macOS, Windows and Linux and on iOS and Android. Scan from your laptop at the desk or from your phone on the couch — one license covers every device you own.
AI, optional
Stuck on a device that's just a MAC address and an open port? Let AI name it from the network signals. Get a plain-language digest of your whole network, ask what's risky and why, and turn the security findings into step-by-step fixes. Everything is grounded in your real scan data — no guessing from a generic checklist.
Bring your own key — AI is entirely optional. Your prompts never touch our servers; they go directly from your device to the provider you picked. Prefer fully offline? Run a local model with Ollama.
No vendor lock-in. Switch providers in Settings → AI any time.
Private by default
A scan of your network is sensitive — it's a map of your home or office. DeviceShelf is built so that map never leaves your device unless you explicitly choose to send part of it.
Every scan result is stored locally on your device. There is no DeviceShelf cloud, no central database, nowhere for your network map to leak from.
Install and scan. No registration, no email verification, no profile. We don't know who you are, and we like it that way.
No analytics, no phone-home, no anonymous metrics. The app does not report what you scan, what you find, or that you opened it.
Your license is verified locally with an ed25519 signature — no license server, no online activation, no check-in. It keeps working even fully offline.
Data leaves only when you turn a feature on: AI (to your provider), Fingerbank device lookup, or WAN-IP info. Each is off by default and clearly labelled.
Default scans are non-intrusive TCP-connect probes — they observe, they don't attack. You control depth and timing, from a quick sweep to a full deep scan.
It knows what it's looking at
DeviceShelf combines many signals — MAC vendor (OUI), DNS, mDNS/Bonjour, NetBIOS, SNMP, UPnP, TTL, DHCP fingerprint and open-port profiles — to label each device with a type and a best guess at what it is.
Desktop and pocket
Not a watered-down companion — the iOS and Android apps run the same scanning engine as the desktop. Walk around the house or office and scan from where you stand. One license covers every device you own.
iOS & Android
Native iOS and Android apps that scan, identify and monitor on their own — no desktop required. The perfect way to check a friend's Wi-Fi, an office network or a hotel LAN while you're standing right next to it.
📱 Launching soon The mobile apps are in final testing — App Store & Google Play listings are on the way.Email us to get notified at launch.
Talk to us
We read every message and usually reply within a working day. For technical bugs the in-app Help → Send feedback dialog ships extra context automatically. Otherwise, this form:
Frequently asked
Locally, on the device that ran the scan. There is no DeviceShelf cloud and no account — your network map never gets uploaded anywhere. You can export it yourself to JSON, CSV or an HTML report whenever you like.
No — by default nothing leaves your device. Data is only sent if you explicitly enable an optional feature: AI (to the provider whose key you supplied), Fingerbank device lookups (fingerbank.org), or WAN-IP info (ip-api.com). No analytics, no phone-home, no telemetry.
Scanning a network you own or administer is completely normal, and DeviceShelf's default scans are lightweight, read-only TCP-connect probes — they observe rather than attack. Only scan networks you have permission to scan.
DeviceShelf combines Fing-style device discovery, nmap-style port scanning, a security report and continuous monitoring in one native app on all five platforms — and it's local-first with no account and no ads. Optional AI can even name devices that nothing else recognises.
Yes — and AI is entirely optional; the scanner works fully without it. Drop in your Anthropic / OpenAI / OpenRouter / Mistral / Groq / Gemini key, or run Ollama locally for fully offline AI. Your prompts always go directly from your device to your chosen provider.
One license = one user, unlimited personal devices. Use the same key on every Mac, PC, Linux box, iPhone and Android device you own. The license is per user, not per machine.
Yes — a 7-day free trial with full features, no credit card required. After that it's a one-time €39 purchase. No subscription, ever.
14 days, money-back, no questions asked. Email [email protected] from the address you bought with.
Desktop: macOS, Windows and Linux. Mobile: iOS and Android. The same scanning engine runs everywhere, and your single license covers all of them.
Local-first by design
Every scan, every device, every note lives on your device. There's no DeviceShelf server holding a copy — so there's nothing to breach, subpoena or sell. You own the data and you can wipe or export it any time.
Download, install, scan. No email, no sign-up, no login. We genuinely don't know who our users are or what's on their networks — and that's the point.
No analytics, no phone-home, no "anonymous metrics". The app doesn't report what you scan, what it finds, or even that you launched it.
AI is optional. When you use it, your provider key stays on your device and prompts go straight to the provider you chose. We never see them, and we host no model of our own.
Pricing
Pay once, own it forever. No subscription, no monthly bill. One license covers all your devices — desktop and mobile. AI works with your own provider key, so there's no extra cost and no vendor lock-in.
Good to know: DeviceShelf scans the local network the device is connected to. Run it on the Wi-Fi/LAN you want to inspect. Only scan networks you own or are allowed to scan.
For home networks, power users, homelabs and IT pros.
Honest expectations
Please read this before you buy. It saves both of us a refund.