Skip to main content
Operations control room with live telemetry screens
Edge runtime

Your app shouldn't have to solve the runtime problem too.

Write the application logic. The platform handles device identity, OTA updates, fleet management, and security underneath it.

Applications built by customer teams and partners already run on Helin nodes in the field.

  • BP
  • BOSKALIS
  • SUNROCK
  • HVC

TL;DR

  • Helin is a containerised edge runtime for industrial operations. You write the application logic. The platform handles device identity, encrypted OTA updates, fleet orchestration, and NIS2 compliance logging.
  • Runs on Ubuntu 20.04/22.04, x86 and ARM, on your existing hardware
  • Protocols: OPC-UA, MQTT, Modbus TCP, CAN bus, NMEA, Siemens S7, REST
  • Applications deploy as signed, hardened containers; the runtime enforces isolation
  • CI/CD to the edge is part of the platform; you bring your own pipeline

What you can build

Three application types developers have shipped on the platform so far.

Vision AI without the cloud hop.

Camera feeds processed locally. Inference triggers a control action in under 150ms. Red Zone Manager runs this way across offshore drilling rigs: the model runs at the asset, not in a data centre.

Control logic that closes the loop at the asset.

Sunrock's grid control runs across 300 solar farms with no cloud round-trip on time-critical trading decisions. The response time the cloud couldn't match, the edge handles natively.

Data pipelines that filter before they transmit.

Boskalis cut satellite bandwidth across 100+ vessels by filtering at source rather than streaming raw. The same application logic works across the whole fleet from a single deployment.

The platform doesn't constrain what you build. If it runs in a container, it runs on Helin.

How it works

  1. 1

    Package your app as a container. The platform takes it from there.

    Docker-compatible. Helin handles signing, verification, and deployment to the fleet. The runtime enforces isolation: your app can't touch resources outside its defined scope without an explicit policy.

  2. 2

    Stop building infrastructure you didn't set out to build.

    Device identity is PKI-based (X.509, TPM 2.0). Remote access is zero-trust, logged per session. OTA updates are encrypted and fleet-wide. NIS2 compliance logging is in the runtime by default. You inherit all of it.

  3. 3

    One console for the whole fleet.

    Health, resource usage, version state, and alerts for every application across every node. When something stops responding on a remote asset, you see it immediately and fix it from the console. No site visit.

Platform capabilities

CapabilityDetail
RuntimeContainerised, Docker-compatible; isolated execution per app
OSUbuntu 20.04 / 22.04
Hardwarex86 and ARM; no proprietary hardware required
ProtocolsOPC-UA, MQTT, Modbus TCP, CAN bus, NMEA, Siemens S7, REST API
Device identityX.509 certificates, TPM 2.0; enforced at provisioning
Remote accessZero-trust; SSH/HTTPS/GUI tunnels; MFA approval; no VPN
OTA updatesEncrypted, fleet-level; app and OS updates without site visits
CI/CDPipeline to the edge; static code analysis and security scanning at build time
Code signingEvery container signed at source; unsigned code does not execute
AI inference latency150ms end-to-end at the edge; 10ms control loop cycle
Compliance loggingNIS2 and CRA; automated; built into runtime by default
Fleet orchestrationCentralised monitoring, alerting, and management across distributed assets
Cloud fanoutKafka, Azure Data Explorer, TimescaleDB, cold storage
Offline operationApplications keep running on connectivity loss; local buffering, no data loss

What to know before you start

It's not self-service yet

Typical time to first operational deployment is 30 days. Boskalis reached first deployment in two weeks. A 7-day target is on the 2026 roadmap, not today.

Sandbox access is gated

Request it below. No demo required, but it's not open by default.

You write containerised applications

If you need a no-code interface, that's Helin Academy.

The runtime is proprietary

Protocol support (OPC-UA, MQTT, and others) follows open standards. The runtime itself is not open source.

No public community forum yet

The developer community is invitation-only, seeded from existing deployments. Expanding through 2026.

The ecosystem is small

Production deployments today: BP, Noble Corporation, Boskalis, Sunrock. Depth over breadth at this point.

Get started

docs.helinplatform.com

Full API reference, protocol documentation, integration guides, and getting started walkthrough. Public, no account required. Start here.

What the docs answer before you talk to anyone:

  • Which protocols are supported and how to connect your OT stack
  • How the container runtime works and what it expects from your application
  • How device identity and OTA updates are handled at the platform layer
  • How the CI/CD pipeline to the edge works and how to plug in your own tooling
  • How NIS2 compliance logging works in practice

Request sandbox access

Docs answer the architecture questions. Sandbox is the next step when you want to test a real deployment. No demo call required.

Frequently asked questions

Any language or framework that runs in a Docker-compatible container. The platform doesn't constrain the application stack.

Yes. The platform includes its own CI/CD tooling to the edge, with static code analysis and security scanning at build time. You can integrate your existing pipeline or use Helin's directly.

Applications keep running. Local buffering means no data loss during an outage. When connectivity comes back, buffered data syncs. The control loop at the asset doesn't depend on the cloud.

Every device gets an X.509 certificate at provisioning. The platform uses TPM 2.0 for hardware-backed key storage. Identity is verified before any connection is established. You inherit this when you build on the platform; you don't configure it from scratch.

Updates are encrypted and delivered fleet-wide from the central console. Roll out to all nodes at once or stage them. The platform tracks version state per node and surfaces mismatches.

Request it via the form on this page. No demo call required.

Incident detection, access logging, and full attribution are built into the runtime from provisioning. The platform generates the evidence trail the audit requires. You don't assemble it beforehand.

Yes. Current production deployments span oil and gas, maritime, renewables, and geothermal. Manufacturing and other industrial environments are in scope.

Edge intelligence, once a month.

Field notes from industrial operations running control at the asset: deployment patterns, compliance changes, and what we learn on site. No product marketing.

One email a month. Unsubscribe at any time.

Last updated: . Information is subject to change.