Docs
Solution · IT / OT

Open by default. Secure by definition.

We speak the protocols your network already speaks, we write to standard storage, we run inside your perimeter. Outbound traffic only, an audit on every write, exportable history. Data you can read only with one tool is not really yours.

governance · activityon-prem
3,240
tags · 14 sites
100%
writes logged
0
open OT ports
Source offline · Line 2, OPC-UA gateway. Last write 18 min ago.
Back online · session re-established, 0 data lost (local buffer).
setpoint audit
09:42GP800 setpoint 62 → 58 °C · m.rossiok
08:15Pump 2 threshold 4.2 → 3.9 bar · a.bianchiok
Architecture

Sources, core, destinations. Outbound only.

OT network
PLC · BMS · meters · CNC
Meddle agent
on-prem / edge · outbound connection
Core
normalizes · no-code rules · governed AI
IT
dashboards · SQL · ERP/MES · alerts
No open ports towards OT. The agent opens outbound connections, compatible with DMZ and segmentation.
Protocols

Industrial standards, any brand.

OPC-UA
Siemens S7
Profinet
Modbus
TCP / RTU
MQTT
Sparkplug B
BACnet
MTConnect
CAN
REST API
Historians / SQL

Compatible ecosystems: Siemens · Allen-Bradley / Rockwell · Omron · Mitsubishi · ABB. If a connector is missing, we integrate it as part of the suite, with no upsell.

Format lock-in. History ends up in a proprietary archive no other tool can read.

Every protocol is code. Every new line becomes custom development, which someone then maintains.

Zero observability. A tag that stops writing is something you find out weeks later, among a hundred disconnected alarms.

Security and governance

Every read and every write, logged.

Audit trail
09:42GP800 setpoint 62 → 58 °C · m.rossiapproved
08:15Pump 2 threshold 4.2 → 3.9 bar · a.bianchiapproved
yesterdayBoarding-area AHU, manual mode · l.verdiapproved

Previous value, new value, user and time on every write to the machines.

Control

Role-based permissions and separate environments (dev, staging, production).

Read-only in the pilot. Writing to PLCs is enabled only after your validation, with instant override.

NIS-2 ready. Data in Europe (AWS Milano) or in your own data center.

Technical honesty

What we do not do.

We are not a MES, an ERP, a SCADA or a BMS. We connect to all of them, we do not replace them.

No heavy proprietary ML. We do anomaly detection with rules and thresholds, and we route the data to third-party analytics where needed.

ISO 27001 in progress, not obtained yet. CyberVadis with an active score. For sensitive contexts: on-prem, read-only, joint pen tests.

Build vs buy

You have a team that could build it.

Many of the people we talk to could. The question is what is worth maintaining: connectors, formats that change and new protocols are the part that breaks and eats time. Meddle takes that edge, your team stays on the product. And the data stays yours and open, so the choice is always reversible.

Multi-brand connectors maintained by usMeddle
Product logic and AI for your domainYour team
History and pipelines, in open formatsReversible
FAQ

The rest, briefly.

What happens to the data if we stop?

It stays yours and readable. History is queryable in SQL and exportable in open formats. No format lock-in.

What does it cost at scale?

Cost follows the machines connected. No cost per tag, per data point or per source, so adding signals does not inflate the bill.

Who does the configuration and how much effort do we need?

We do it. On your side we need one technical contact for the initial session, then we handle the conversations with your suppliers.

Try it on your network.

A pilot line inside your perimeter, outbound, without touching the rest.

Book a demo