
Your operation can't wait for a cloud round-trip.
Port terminals, rail networks, and logistics fleets run on control decisions measured in milliseconds. When those decisions route through the cloud, operations wait. When the link drops, they stop.
Proven in environments where failure costs more than a delayed shipment. Trusted by operators where downtime runs $220K–$770K per day.
- BP
- Sunrock
- Boskalis
- Noble
TL;DR
Helin is the secure edge application engine for transportation operations where control cannot fail. Rail operators, port terminals, and logistics fleet managers run control logic at the asset, manage distributed OT infrastructure from one platform, and meet NIS2 compliance obligations without building a separate compliance programme.
- Port crane collision avoidance requires a response in under 50ms. Cloud-routed control at standard connectivity adds 200–800ms. The control loop can't absorb that.
- Railway turnout condition monitoring fails when trackside WAN drops. Faults don't wait for the link to come back.
- NIS2 Annex I classifies transportation as an essential entity sector. Essential entities must issue an incident early warning within 24 hours and a detailed report within 72 hours, backed by a demonstrable OT governance trail.
- Transportation operators running five separate vendors for security, remote access, device management, data pipelines, and runtime have no single party who owns what happens when it doesn't work.
Where milliseconds decide whether operations hold or stop
- By the time the control decision fires, the hazard has already happened
- Port crane collision avoidance requires a response in under 50ms. Turnout fault response on a busy main line is measured the same way. Cloud-routed control at standard connectivity adds 200–800ms. Port downtime at a major container terminal runs $50,000–$200,000 per hour (industry estimate). A single turnout failure cascades across every train behind it for 45–90 minutes.
- Monitoring stops exactly when faults are developing
- Rail networks have inconsistent trackside WAN coverage. A condition monitoring platform that depends on a continuous cloud connection stops detecting faults during coverage gaps. Faults develop during those gaps as reliably as they develop when the link is up. The same applies to port logistics equipment at the edge of terminal networks and road freight fleets in transit.
- Five vendors, no owner
- A transportation operator building control at the asset ends up with a security tool, a remote access platform, a device management layer, a data pipeline, and an application runtime. Each vendor covers its piece. Integration risk goes back to the operator. When a NIS2 auditor asks who holds the compliance posture, nobody in particular does.
- NIS2 compliance can't be assembled manually inside 72 hours
- Transportation is an essential entity sector under NIS2 Annex I. The obligations include a 24-hour incident early warning and a 72-hour detailed report with a demonstrable OT governance trail. Most transport operators can't produce that from current systems in time. Telemetry is spread across multiple SCADA environments, site historians, and vendor platforms. Assembling it manually takes longer than the deadline.
Delay exposure calculator
Delay minutes × cost per minute × avoidable share. Performance regimes differ by country and by contract, so we don't guess your rate. Put your own in. The 5 percent default is a deliberately conservative placeholder, not a Helin benchmark.
Where control timing determines the outcome
Each use case runs on the same platform. Add one, the infrastructure for the next is already there.
One architecture. Every asset on your network.
Key features by capability
- Edge control01
Edge runtime
Applications execute at the terminal, the trackside controller, the vessel. Control decisions, AI inference, and data processing happen locally. When the WAN drops, operations continue.
- Edge control02
Hardware-agnostic deployment
Runs on existing OT hardware across port terminals, trackside locations, and rolling stock. No fleet-wide hardware replacement before you can start.
- Edge control03
Edge buffering
No data lost during connectivity outages. Data queues locally and syncs when the link returns. The compliance record stays complete.
- Edge control04
OTA updates
Software and firmware updates reach every asset in the fleet without a site visit. Staged rollout, tested before it reaches the production fleet.
- Edge control05
Fleet and device management
Provision, configure, monitor, and patch every edge node from one console. No engineer on-site for routine management across hundreds of distributed assets.
What changes when control moves to the asset
Control that holds when connectivity doesn't
Cloud-dependent control in a rail or port environment fails when the environment is most demanding. A track section with degraded WAN, a terminal in a coverage gap: the monitoring stops exactly when operations need it.
Edge-resident control logic runs at the asset. It doesn't need the link to function. When connectivity returns, data syncs. The operation doesn't pause to wait for it.
Security in the runtime, not the vendor stack
A transport operator with five vendors covering security, remote access, device management, data pipelines, and runtime has no single party responsible for the result. Each vendor covers its piece. Integration risk and NIS2 compliance exposure land back on the operator.
Device identity, access governance, and OT telemetry run from one architecture. Every device is authenticated. Every remote access session is logged. The NIS2 audit trail is a structural output of normal operations, not a separate project.
Condition met. Response fires.
Condition monitoring that sends alerts to a dashboard requires a human to read the alert and decide what to do. In a time-critical environment, a crane proximity event, a turnout fault in progress, a bearing degrading on a high-speed line, the gap between alert and action is where the cost sits.
The model runs at the asset. When it detects a developing fault or a proximity event, the response executes locally, automatically, within the same control cycle.
Your domain knowledge, running at the asset
Your operations team knows what a failing turnout looks like in vibration data. Your terminal engineers know the crane approach parameters that matter. That knowledge lives in your tools, your models, your procedures.
Get it to the asset without an integration project for every application. Build the logic. Helin handles provisioning, security, OTA updates, and fleet-wide deployment.
Most transport operators reach this conversation after something stops.
A control failure that exposed the latency in the current platform. A NIS2 audit that revealed the documentation couldn't be produced in time. A modernisation programme that stalled because no vendor owned the integration.
Helin is the edge application engine that replaces the stack. One vendor. One audit trail. Control decisions at the asset.
How the architectures compare
| Helin edge platform | Cloud-first OT platform | Point-solution stack | |
|---|---|---|---|
| Control decision location | At the asset | Cloud data centre | Varies by vendor |
| WAN dependency | None for control logic | Required for control | Partial, varies |
| Response latency | Sub-50ms at the asset | 200–800ms+ | Varies |
| Device identity management | Built into the runtime | Separate tool | Separate tool |
| Remote access governance | Built into the runtime | Separate tool | Separate tool |
| NIS2 audit trail | Structural output of normal operations | Manual assembly across systems | Manual assembly |
| Fleet-wide OTA updates | Centralised, confirmed, logged | Not standard | Not standard |
| Hardware compatibility | Hardware-agnostic | Often OEM-specific | Varies |
| Integration responsibility | One vendor, one responsible party | Operator absorbs it | Operator absorbs it |
Technical reference
| Capability | Detail |
|---|---|
| Edge runtime | Containerized applications, hardware-agnostic, runs on existing OT hardware |
| Control loop latency | Sub-50ms at the asset for time-critical control decisions |
| Offline operation | Full monitoring and control capability without WAN. Data buffered locally, synced on reconnection |
| Device identity | X.509 certificates, TPM 2.0, TLS — every device authenticated at provisioning |
| Remote access | Zero-trust, session-based, policy-governed, full audit log |
| OTA update management | Signed updates, centrally deployed, per-device confirmation, fleet-level version dashboard |
| Protocols supported | OPC UA, Modbus, MQTT, NMEA, CAN bus, and OEM-specific protocols via Helin Data Collector |
| Compliance reporting | Structured incident records, access logs, and OT telemetry exportable for NIS2 reporting |
| Deployment model | Cloud Fanout architecture — control at the edge, aggregated visibility at the centre |
| Security framework | IEC 62443 aligned, NIS2 compliant by design, EU Cyber Resilience Act lifecycle documentation |
Frequently asked questions
What this is not
Not a fit for single-site reporting
Helin is a poor fit for operators who need better reporting from a single site. A site-level SCADA upgrade, a cloud analytics platform with an edge module, or a monitoring tool that sends alerts to a human for review on time-critical decisions are different categories of product.
Not a SCADA replacement at a single terminal
It reads from existing control infrastructure and extends it to the fleet level. If the requirement is a new site-level control system, that's a different procurement.
Not a cloud analytics platform
The value is in processing at the asset, not in moving data to a centralised platform for analysis after the fact. Operators who primarily want a better dashboard are not the right fit.
Not a security overlay
Certificate-based identity, zero-trust access governance, and NIS2 compliance reporting are structural outputs of the runtime, not a layer added on top of an existing OT stack.
Built for fleets, not for one asset
Helin sits underneath those applications. Device management, security, OT runtime, data pipelines, and application deployment run from one architecture across every asset in the fleet. The right fit is an operator managing distributed transportation infrastructure across multiple assets, OEMs, and regulatory jurisdictions, who needs one vendor to own the integrated result.
Edge intelligence, once a month.
Field notes from industrial operations running control at the asset: deployment patterns, compliance changes, and what we learn on site. No product marketing.



