DeviceShelf
Network scanner & security
Free · In-App Purchases · Designed for iPad. Not verified for macOS.
New: connect to a 24/7 DeviceShelf server, custom scan ranges, per-device uptime and Fingerbank identification. Private and local-first — no account, no tracking.
DeviceShelf shows you every device on your network — what it is, what it exposes, and whether it's a risk. No account, no telemetry, no hidden cloud. Your network data stays on your device.
WHAT YOU GET
• See every device: name, vendor, type, IP and open ports, discovered over Bonjour and port probing.
• Security at a glance: a risk score with plain-language findings — open Telnet, exposed SMB, weak defaults, aging TLS certificates, known CVEs.
• Diagnostics that answer real questions: ping, speed test, DNS lookup, and your public IP and ISP.
• Ask the built-in assistant about your network in plain language. Bring your own AI key — nothing is sent unless you turn it on.
• Watch devices come and go, with per-device uptime.
PAIR WITH YOUR COMPUTER OR SERVER
iOS limits how deeply an app can scan a network. Connect to DeviceShelf on your Mac or PC, or to a 24/7 DeviceShelf server, and this app pulls the full inventory — every device's vendor, name and MAC — plus its security report and timeline. One license covers desktop, server and mobile.
PRIVATE BY DESIGN
No sign-up. No tracking. Nothing leaves your device unless you enable an optional feature. License checks work offline.
OPTIONAL AI, CLEAR CONSENT
If you configure a cloud AI provider, DeviceShelf asks before sending anything. The consent screen shows the provider, endpoint, and exact data categories first: your question or selected network/device signals such as IP addresses, pseudonymised MAC addresses, host/device names, vendors, open ports, service banners, certificate names, OS hints and security findings. Local providers such as Ollama do not need cloud consent.
Try it free for 7 days. One-time purchase, no subscription.
more • Every CVE finding now shows what it rests on (the port, the text the device sent, the affected versions) and its CVSS score.
• An open Docker port 2375 is checked before it is reported. Only a Docker daemon that answers counts as high risk.
• The security report now also lists the CVEs found by a paired desktop app.
1.5.43 1 day ago
• A satellite receiver that names itself "stlinux" on the network is now listed as TV / Cast instead of Computer.
1.5.42 4 days ago
• Ollama: the plain server address (http://host:11434) now works, and if Ollama does not answer, the app names the address it tried.
1.5.41 3 Oct
• Devices that moved to another network, such as a phone you take between two homes, now show the IP address they have there instead of the old one.
1.5.40 1 Oct
• AI settings: the model list shows each model's name and full id instead of cutting it off, opens on all models, and finds models by words in any order. A button clears the model, so the provider's default applies.
• AI requests may take up to five minutes and give much longer answers, so slow or thinking models no longer fail. A cut-off answer says so, and every AI request can be cancelled.
1.5.39 30 Sept
• AI assistant: it can search the web if you allow it (Anthropic, OpenRouter), and it now gets the whole conversation, not only the last question.
• The scanner recognizes more home-lab services, among them Homebridge, Ollama and WinRM.
• Fixed an error when the settings were closed before they had loaded.
1.5.37 29 Sept
• SSH: the app asks for a username before it opens the connection.
• Remote servers: a token the server refused is no longer sent again on every refresh, so the server no longer locks the phone out.
1.5.36 28 Sept
• ASUS routers: the app now logs in over HTTPS first. If your router only answers over unencrypted HTTP, the connection test tells you, so you can switch HTTPS on.
1.5.35 26 Sept
• Routers and other devices with a built-in media server no longer show up under the name of the server software.
1.5.34 25 Sept
• Security findings from a paired desktop or server now appear in the app's language instead of English.
• Requests to your AI provider now identify themselves as DeviceShelf with the version number.
1.5.33 24 Sept
• A paired desktop or server now fills your list by itself: right after you add it, when the app starts and when it comes back to the front. The last list is kept across a restart.
• The server card says what the phone holds and why a refresh did not work; “Refresh now” and “Share device metadata” sit on the card.
• “Find DeviceShelf nearby” explains that it looks on port 8088 and how to add a desktop on another port.
1.5.32 22 Sept
• Already have a DeviceShelf license? The activation screen now says how to use it on iPhone and iPad: open the activation link from your license email on this device and tap “Open in the DeviceShelf app”.
• “Share device metadata” and its explanation are translated into French, Italian, Spanish, Arabic and Chinese.
1.5.31 21 Sept
• Rename a device on the desktop or the server and the phone shows that name too. It was always in the data; the app skipped the field.
• Tap a CVE number in the security report to open its record at the National Vulnerability Database.
• Device details survive the largest text size. The sheet scrolls, long labels wrap.
• BT Smart Hub 2, also sold as EE Smart Hub and Plusnet Hub Two, is in the router list. The router card says what each brand needs, and a device with no MAC address says what to set up.
• Newer OpenAI models work with your own key again.
1.5.30 20 Sept
• Names from a UniFi controller are hints again: the "Mac fe:93" style labels the controller invents lose their MAC tail, and a bare MAC address is not a name. A name you gave a device is never replaced.
• The controller's own switches and access points now appear in the list with their names instead of as unknown devices.
• Name cleaning is now the same as on the desktop, and clients the controller lists without an IPv4 address no longer become devices.
1.5.26 17 Sept
• A second address on your router's MAC (such as a UniFi honeypot decoy) now keeps its own name, note, type, tags, favorite and manufacturer correction. Before, renaming it renamed the router.
• Edits to such a device wait until a paired server runs 1.9.40. All other edits keep syncing.
• The device list from the last scan is still there after the app restarts.
1.5.24 14 Sept
• The vulnerability check now names what the app actually found on the device: matched CVEs, risky ports, an expired certificate, a web interface without HTTPS. It used to describe the device a second time instead.
• Two findings the phone never raised are in: an expired TLS certificate, and a web interface reachable only over plain HTTP.
• A device can no longer forge its own signals. Text a device picks itself (hostname, model name, service banners) can no longer write extra lines into what the AI is given.
• Devices synced from a desktop or server now bring their product versions and their port-scan status with them, so a fully scanned device is no longer reported as unchecked.
1.5.21 10 Sept
You can now store an Anthropic workspace ID for the AI assistant. Plus bug fixes.
1.5.20 9 Sept
• Device details show considerably more: open ports now carry the service
name and banner instead of bare numbers, plus availability and latency in
the sheet itself, the TLS certificate, the web UI title, and where the
device is attached (access point, switch port, Wi-Fi).
• The scan collects what it could previously only display: the whole TLS
certificate rather than just the name, and the web UI title.
• A device remembered from your last session now says so, instead of looking
like a device nothing was found about.
• More room for the device list: the scan-range box only appears when your
network actually has more to offer.
• The stop button now ends the scan immediately.
1.5.19 2 Sept
• Devices outside the range you scanned now sit in one group at the end of the list instead of scattered through it, with a badge saying how each was found. Nothing is hidden — they stay in monitoring and exports.
• Clear the list: remove everything the app has learned about your network, the same way the desktop does it.
• Open a device's web interface straight from its page.
• Zyxel routers are supported, bringing the number of router brands to 18.
• Printers are no longer probed. Some models answered a scan by printing a page.
1.5.7 30 Aug
• Custom device types and custom icons from a paired DeviceShelf server now show up on the phone — a type you created on the desktop or dashboard carries its icon here too.
• Through a paired server the phone reaches the full icon set, thousands of icons instead of the built-in subset, and every icon group is browsable.
• Robot vacuum, lawn mower, coffee machine and kitchen appliance are built-in device types now.
1.5.2 10 Aug
• OpenWrt routers are found without any setup. DeviceShelf asks LuCI for ubus on ports 80, 443, 8080 and 8443 — the last two are where GL.iNet puts it from firmware 4.7 on — and looks for the open port if none of them answer. You can also enter a port yourself, for example 192.168.8.1:8080.
• Devices are identified from local rules the app carries with it: the names and model strings devices publish over mDNS and SSDP. Nothing is sent anywhere for it.
• The router hint no longer asks you to install a package that LuCI already brings.
1.5.1 6 Aug
• A scan no longer empties the device list before refilling it. It updates the list in place, and a device that a completed sweep heard nothing from stays, marked offline, instead of vanishing. If it answers again, it comes back. A scan you stopped judges nothing, and a scan of one range says nothing about devices outside it.
• Sorting by address counts again, so .9 comes before .100 rather than after it. The order is now unambiguous, so rows the chosen column calls equal no longer swap places between refreshes.
• Ascending and descending order, which the list never had. The direction is kept between launches, spoken by VoiceOver, and shown on the arrow without opening the menu.
• The app now needs iOS 15. Everything from the iPhone 6s onward runs it.
1.4.0 5 Aug
• A failed router connection now names the cause instead of always pointing at the password: unreachable, no endpoint, refused, no data, or no matching brand. The wording matches the desktop app exactly.
• The four brands that have to be opened up on the router first now say so under the brand picker: ubus for OpenWrt, an API key instead of the account password for UniFi, the applications switch on a FRITZ!Box, www-ssl on MikroTik.
• Seventeen router brands were re-checked against recorded answers. A Peplink client that is not connected no longer counts as present, a Netgear device with an unreadable MAC no longer drops out of the list, and a UniFi controller on Network 9.x reads the switch port it actually reports.
1.3.9 3 Aug
• Devices that showed up as a bare IP address usually have a name now. The app asks them directly, the way the desktop app does, so a phone or tablet that stays quiet about itself is no longer just a number in the list.
• Choosing a source used to change the device list only. It now applies to every screen: overview, topology, security and snapshots all show the devices you picked.
• The remote server screen claimed metadata was merged between server and phone. It is exchanged, not merged, and the wording says so now.
1.3.7 31 Jul
• Editing a device could save the name, note or AI identification onto a different device. That is fixed.
• The app now works out the maker behind a MAC address itself, instead of leaving that to the AI to guess. A Raspberry Pi is recognized as one, and a device with a file share is no longer filed as storage.
• You choose what the list shows: this phone's scan, a server, or several at once, each one on or off separately. Every row says where it came from.
1.3.6 28 Jul
• Every CVE finding now shows what it rests on (the port, the text the device sent, the affected versions) and its CVSS score.
• An open Docker port 2375 is checked before it is reported. Only a Docker daemon that answers counts as high risk.
• The security report now also lists the CVEs found by a paired desktop app.
more Version 1.5.43 1 day ago
Data Not Collected The developer does not collect any data from this app.