
One runtime. Every capability your edge stack was missing.
Where control cannot fail. Device management, security, edge compute, data pipelines, and control logic. All built into one architecture. Runs on your hardware. No cloud dependency on the control loop. One vendor owns what sits underneath.
Talk to an expert- Running at BPupstream oil and gas assets
- Sunrock300 solar farms
- Boskalis500+ vessels
- 400+ sites and vesselsin production
- 150mscontrol decisions at the asset
TL;DR
- Helin is the secure edge application engine for industrial operations where control cannot fail.
- One runtime runs six capability layers on your existing hardware: device management, security, edge compute, connectivity, data pipelines, and control logic.
- Applications deploy to the runtime once. Every new application shares the same infrastructure already on the asset.
- Control decisions execute locally in under 150ms. The control loop has no cloud dependency.
- Zero-trust security and certificate-based device identity are built into the runtime at provisioning. Not configured site by site.
- One architecture covers offshore rigs, solar farms, maritime fleets, and remote industrial sites. The runtime is the same across all of them.
What a fragmented stack costs you before anything goes wrong
- No single owner when something fails
- Five vendors means five conversations before anyone accepts the problem. In offshore operations, that delay runs at €200K+ per day before you've isolated the fault.
- Control decisions that depend on a cloud hop
- When the network link degrades, the control loop breaks. For time-critical operations like curtailment windows, zone intrusions, and grid frequency events, that dependency is the risk.
- Security spread across five attack surfaces
- Five tools, five update cycles, five access logs. Your CISO can't govern what isn't unified, and NIS2 requires you to prove it on demand.
Calculate your current stack exposure →
Your current exposure
80 percent of your 50 sites cannot act on their own data.
Holding the stack together costs you around 240 engineering days a year.
Talk to an expertThe percentage is your own two numbers. Engineering days are what you entered, multiplied by twelve. It excludes license cost and downtime.
The architecture: six layers, one runtime
Every solution Helin builds, and every application a customer deploys, runs on the same six layers.They ship together, update together, and are owned by one vendor.
- 01
Device & fleet management
Provisioning, OTA updates, OS lifecycle, mass configuration, and compliance auditing across every node in the fleet.
- 02
Security
PKI infrastructure, certificate-based device identity, zero-trust remote access, network segmentation aligned to the Purdue model, and audit logging.
- 03
Edge runtime
Containerized application execution at the asset. Sub-100ms control loop. Offline-capable — the runtime keeps running when connectivity fails.
- 04
Data pipelines
Protocol adapters for OPC UA, Modbus, MQTT, CAN bus, NMEA, and REST. Data filtered, structured, and timestamped at the edge before transmission.
- 05
Developer tooling
CI/CD pipelines to the edge, hardened containers, static code analysis, vision AI development tooling, and an application catalog with staged rollouts.
- 06
Cloud management
Centralized orchestration of distributed edge fleets, cloud dashboards, container registry, and Cloud Fanout to multiple destinations simultaneously.
What the architecture does for your operations
Key features by capability
No cloud, no latency, no compromise.
- Edge control01Edge runtimeApplications execute at the asset. Control logic runs locally, with or without a cloud connection.
- Edge control02Hardware-agnostic deploymentRuns on existing edge hardware. No proprietary device requirement. No replacement project.
- Edge control03Offline-capable operationWhen connectivity fails, the runtime keeps running. Data buffers locally and syncs on reconnection.
- Edge control04OTA updatesSoftware updates push across the full fleet from one console. No site visits. No version drift.
- Edge control05Centralized fleet orchestrationOne console shows the health and status of every edge node, application, and device across the fleet.
The runtime installs on the edge device and provisions from the OS up. Applications run in hardened containers on local hardware. When the satellite link drops or the LTE connection degrades, nothing changes for the control loop. It was never dependent on the link. Local state is maintained, decisions keep executing, data buffers without loss. When connectivity returns, the buffer syncs. No manual intervention. No gap in the operational record.
Running in production
Not a pilot. Not a proof of concept. BP, Sunrock, and Boskalis run Helin across live operations at scale.
BP
Red Zone Manager runs on the platform across upstream oil and gas assets. Camera feed to vision AI to physical control action in under 100ms — no cloud hop on the control loop. Outcome cited by BP: human lives saved.
Read the BP case study →Sunrock
Smart Grid Manager runs across 300 solar farms. Curtailment and dispatch decisions execute at the asset. When Sunrock added a second application, the platform infrastructure was already there.
Read the Sunrock case study →Boskalis
Platform for Maritime runs across 500+ vessels. A second application module was live in two weeks — same runtime, no new infrastructure deployment.
Read the Boskalis case study →Bring your stack. We'll show you where the platform fits.
A 45-minute session with one of our engineers. You describe your current architecture, the vendors, the gaps, the integration points. We show you exactly where Helin sits, what it replaces, and what it leaves alone.
Four ways to run an industrial edge stack
This table compares architecture approaches, not specific products. Your current stack may contain elements from more than one column.
| Helin Platform | Point-solution stack | Cloud-first platform | OT suite | |
|---|---|---|---|---|
| Control loop runs offline | Yes | Depends on vendor | No | Partial |
| Sub-100ms control decisions | Yes | Depends on vendor | No — cloud round-trip | Partial |
| Device identity at provisioning | Yes — X.509, TPM 2.0 | No — configured per site | Partial | Partial |
| One security policy across fleet | Yes | No — per vendor | Partial | Yes, within suite |
| Single support contract | Yes | No — per vendor | Yes | Yes |
| Runs on existing hardware | Yes | Partial | No | Partial |
| Protocol support (OPC UA, Modbus, MQTT, NMEA, CAN bus) | Yes | Partial — per vendor | Partial | Partial |
| Second solution on same infrastructure | 2 weeks — Boskalis reference | New procurement cycle | New module | Weeks to months |
| One vendor owns the full stack | Yes | No | Partial | Yes, within suite |
| NIS2 / IEC 62443 audit trail built in | Yes | No — separate tool | Partial | Partial |
What the platform covers
| Category | Detail |
|---|---|
| Edge OS | Ubuntu 20.04 / 22.04 |
| Hardware | Hardware-agnostic. Runs on existing edge hardware — x86 and ARM. No proprietary device requirement. No replacement project. |
| Protocols | OPC UA, Modbus, MQTT, CAN bus, NMEA, Siemens S7, REST API |
| Network architecture | Purdue model — OT levels 0–3, DMZ at 3.5, IT at level 4. Managed centrally across all sites. |
| Connectivity | Operates fully offline for local control decisions. Edge buffer maintains data without loss during connectivity outages. Syncs on reconnection. |
| Deployment models | Edge node + cloud hybrid · On-premises / private cloud for data-residency requirements · API-first for embedding Helin capabilities into third-party applications |
| Cloud destinations (Fanout) | Kafka · Azure Data Explorer · TimescaleDB / TigerData · Cold storage |
| Security | X.509 certificates · TPM 2.0 · TLS · Zero-trust remote access (SSH / HTTPS / GUI) · MFA per session · No VPN · Network segmentation (Purdue model) · Signed containers · Static code analysis at build · SOC-level security monitoring |
| Compliance alignment | NIS2 · EU Cyber Resilience Act · IEC 62443 · IMO Cyber Risk Management · EU CSRD / IMO CII |
| Performance | Control-loop response under 100ms. Camera feed to vision AI to control action with no cloud round-trip. |
| Scale | 400+ sites and vessels in production. Architecture designed to scale from 1 to 1,000+ assets without added overhead. |
| Data model | Structured and timestamped at the edge. Delta filter transmits only on configurable value change. Semi-structured JSON tagged with asset metadata. |
| Application management | Staged rollouts (test → pilot → production) · OTA updates · Signed containers · Role-based access · Audit trails · Multi-tenant governance |
| Support | Single point of contact across all solutions. One escalation path. |
Questions engineers ask.
What this is not
A cloud-first platform with an edge module bolted on
The runtime runs at the asset by design. Cloud connectivity handles data distribution and fleet management — not control decisions. If your architecture requires all processing in a central cloud and your connectivity is consistently high-bandwidth, there are cloud-native industrial platforms built for that. Helin is not one of them.
A replacement for your SCADA or historian
Helin connects to existing SCADA systems via OPC UA and MQTT and sits alongside your historian. It does not replace field devices, control room infrastructure, or the data records your operations depend on. The platform closes the gap between what your OT stack already captures and what it can act on.
A self-serve SaaS product
There is an engineering scoping and deployment process. First application live in approximately 30 days from signed order. If you need something running in hours from a dashboard sign-up, this is the wrong starting point.
A data contextualisation platform
Helin structures and filters data at the edge before it reaches the cloud. It does not provide a knowledge graph, an asset framework, or deep data contextualisation layer. Tools built for that purpose are complementary to Helin's data layer, not replaced by it.
A solution for every vertical today
Proven references are in oil and gas, renewables, and maritime. Manufacturing is in scope for Helin's ICP but has no named reference customer yet. If your environment is discrete manufacturing, we'll say that directly in a scoping call rather than fit a reference that doesn't match.
A safety system
Red Zone Manager is a monitoring and alerting aid. It does not guarantee safety outcomes, prevent injuries, or eliminate incidents. It gives operators faster, more accurate situational awareness so they can act. The crew remains responsible for securing safety on the floor.
Edge intelligence, once a month.
Field notes from industrial operations running control at the asset: deployment patterns, compliance changes, and what we learn on site. No product marketing.



