Skip to main content
Operator monitoring process screens in an industrial control room
Control room

One runtime. Every capability your edge stack was missing.

Where control cannot fail. Device management, security, edge compute, data pipelines, and control logic. All built into one architecture. Runs on your hardware. No cloud dependency on the control loop. One vendor owns what sits underneath.

Talk to an expert
  • Running at BPupstream oil and gas assets
  • Sunrock300 solar farms
  • Boskalis500+ vessels
  • 400+ sites and vesselsin production
  • 150mscontrol decisions at the asset

TL;DR

  • Helin is the secure edge application engine for industrial operations where control cannot fail.
  • One runtime runs six capability layers on your existing hardware: device management, security, edge compute, connectivity, data pipelines, and control logic.
  • Applications deploy to the runtime once. Every new application shares the same infrastructure already on the asset.
  • Control decisions execute locally in under 150ms. The control loop has no cloud dependency.
  • Zero-trust security and certificate-based device identity are built into the runtime at provisioning. Not configured site by site.
  • One architecture covers offshore rigs, solar farms, maritime fleets, and remote industrial sites. The runtime is the same across all of them.

What a fragmented stack costs you before anything goes wrong

No single owner when something fails
Five vendors means five conversations before anyone accepts the problem. In offshore operations, that delay runs at €200K+ per day before you've isolated the fault.
Control decisions that depend on a cloud hop
When the network link degrades, the control loop breaks. For time-critical operations like curtailment windows, zone intrusions, and grid frequency events, that dependency is the risk.
Security spread across five attack surfaces
Five tools, five update cycles, five access logs. Your CISO can't govern what isn't unified, and NIS2 requires you to prove it on demand.

Calculate your current stack exposure →

50
10
20

Your current exposure

80 percent of your 50 sites cannot act on their own data.

Holding the stack together costs you around 240 engineering days a year.

Talk to an expert

The percentage is your own two numbers. Engineering days are what you entered, multiplied by twelve. It excludes license cost and downtime.

The architecture: six layers, one runtime

Every solution Helin builds, and every application a customer deploys, runs on the same six layers.They ship together, update together, and are owned by one vendor.

  1. 01

    Device & fleet management

    Provisioning, OTA updates, OS lifecycle, mass configuration, and compliance auditing across every node in the fleet.

  2. 02

    Security

    PKI infrastructure, certificate-based device identity, zero-trust remote access, network segmentation aligned to the Purdue model, and audit logging.

  3. 03

    Edge runtime

    Containerized application execution at the asset. Sub-100ms control loop. Offline-capable — the runtime keeps running when connectivity fails.

  4. 04

    Data pipelines

    Protocol adapters for OPC UA, Modbus, MQTT, CAN bus, NMEA, and REST. Data filtered, structured, and timestamped at the edge before transmission.

  5. 05

    Developer tooling

    CI/CD pipelines to the edge, hardened containers, static code analysis, vision AI development tooling, and an application catalog with staged rollouts.

  6. 06

    Cloud management

    Centralized orchestration of distributed edge fleets, cloud dashboards, container registry, and Cloud Fanout to multiple destinations simultaneously.

What the architecture does for your operations

Key features by capability

No cloud, no latency, no compromise.

  • Edge control01Edge runtimeApplications execute at the asset. Control logic runs locally, with or without a cloud connection.
  • Edge control02Hardware-agnostic deploymentRuns on existing edge hardware. No proprietary device requirement. No replacement project.
  • Edge control03Offline-capable operationWhen connectivity fails, the runtime keeps running. Data buffers locally and syncs on reconnection.
  • Edge control04OTA updatesSoftware updates push across the full fleet from one console. No site visits. No version drift.
  • Edge control05Centralized fleet orchestrationOne console shows the health and status of every edge node, application, and device across the fleet.

The runtime installs on the edge device and provisions from the OS up. Applications run in hardened containers on local hardware. When the satellite link drops or the LTE connection degrades, nothing changes for the control loop. It was never dependent on the link. Local state is maintained, decisions keep executing, data buffers without loss. When connectivity returns, the buffer syncs. No manual intervention. No gap in the operational record.

Running in production

Not a pilot. Not a proof of concept. BP, Sunrock, and Boskalis run Helin across live operations at scale.

BP

Red Zone Manager runs on the platform across upstream oil and gas assets. Camera feed to vision AI to physical control action in under 100ms — no cloud hop on the control loop. Outcome cited by BP: human lives saved.

Read the BP case study →

Sunrock

Smart Grid Manager runs across 300 solar farms. Curtailment and dispatch decisions execute at the asset. When Sunrock added a second application, the platform infrastructure was already there.

Read the Sunrock case study →

Boskalis

Platform for Maritime runs across 500+ vessels. A second application module was live in two weeks — same runtime, no new infrastructure deployment.

Read the Boskalis case study →

Bring your stack. We'll show you where the platform fits.

A 45-minute session with one of our engineers. You describe your current architecture, the vendors, the gaps, the integration points. We show you exactly where Helin sits, what it replaces, and what it leaves alone.

Four ways to run an industrial edge stack

This table compares architecture approaches, not specific products. Your current stack may contain elements from more than one column.

Point-solution stack, cloud-first platform and OT suite compared with the Helin Platform
 Helin PlatformPoint-solution stackCloud-first platformOT suite
Control loop runs offlineYesDepends on vendorNoPartial
Sub-100ms control decisionsYesDepends on vendorNo — cloud round-tripPartial
Device identity at provisioningYes — X.509, TPM 2.0No — configured per sitePartialPartial
One security policy across fleetYesNo — per vendorPartialYes, within suite
Single support contractYesNo — per vendorYesYes
Runs on existing hardwareYesPartialNoPartial
Protocol support (OPC UA, Modbus, MQTT, NMEA, CAN bus)YesPartial — per vendorPartialPartial
Second solution on same infrastructure2 weeks — Boskalis referenceNew procurement cycleNew moduleWeeks to months
One vendor owns the full stackYesNoPartialYes, within suite
NIS2 / IEC 62443 audit trail built inYesNo — separate toolPartialPartial

What the platform covers

Helin Platform specifications
CategoryDetail
Edge OSUbuntu 20.04 / 22.04
HardwareHardware-agnostic. Runs on existing edge hardware — x86 and ARM. No proprietary device requirement. No replacement project.
ProtocolsOPC UA, Modbus, MQTT, CAN bus, NMEA, Siemens S7, REST API
Network architecturePurdue model — OT levels 0–3, DMZ at 3.5, IT at level 4. Managed centrally across all sites.
ConnectivityOperates fully offline for local control decisions. Edge buffer maintains data without loss during connectivity outages. Syncs on reconnection.
Deployment modelsEdge node + cloud hybrid · On-premises / private cloud for data-residency requirements · API-first for embedding Helin capabilities into third-party applications
Cloud destinations (Fanout)Kafka · Azure Data Explorer · TimescaleDB / TigerData · Cold storage
SecurityX.509 certificates · TPM 2.0 · TLS · Zero-trust remote access (SSH / HTTPS / GUI) · MFA per session · No VPN · Network segmentation (Purdue model) · Signed containers · Static code analysis at build · SOC-level security monitoring
Compliance alignmentNIS2 · EU Cyber Resilience Act · IEC 62443 · IMO Cyber Risk Management · EU CSRD / IMO CII
PerformanceControl-loop response under 100ms. Camera feed to vision AI to control action with no cloud round-trip.
Scale400+ sites and vessels in production. Architecture designed to scale from 1 to 1,000+ assets without added overhead.
Data modelStructured and timestamped at the edge. Delta filter transmits only on configurable value change. Semi-structured JSON tagged with asset metadata.
Application managementStaged rollouts (test → pilot → production) · OTA updates · Signed containers · Role-based access · Audit trails · Multi-tenant governance
SupportSingle point of contact across all solutions. One escalation path.

Questions engineers ask.

The platform installs on any Linux-based edge device or VM running Ubuntu 20.04 or 22.04. It runs on x86 and ARM hardware — standard industrial gateways and ruggedised edge servers. No proprietary hardware required. Boskalis deployed across 500+ vessels without replacing existing hardware on any of them.

Control logic runs locally at the asset. When connectivity drops, the runtime keeps executing — it was never dependent on the link for real-time decisions. Data buffers at the edge without loss and syncs when connectivity returns. No manual intervention. No gap in the operational record.

OPC UA, Modbus, MQTT, CAN bus, NMEA, Siemens S7, and REST API. Equipment from different OEMs with different communication protocols connects to one data layer. No custom middleware, no per-device integration project.

At provisioning, each device gets a unique X.509 certificate backed by TPM 2.0, managed by the platform's PKI infrastructure and renewed automatically before expiry. A device without a valid platform-issued certificate cannot connect. There is no exception path for legacy hardware added without going through provisioning.

Yes. Customer-built applications run on the same runtime as Helin's own solutions — same device management, security layer, CI/CD pipeline, and OTA delivery mechanism. Applications move through staged rollouts: test, pilot, production. Unsigned or unverified containers cannot execute.

Code goes through static analysis and security scanning at build, gets packaged as a signed container, and deploys to a staging environment, then a defined pilot group of nodes, then the full fleet. Deployment stops at any stage if validation does not pass. No engineer needs to be on-site for updates.

Certificate-based device identity, zero-trust remote access with per-session MFA, encrypted communications, signed software delivery, continuous security monitoring, and automated incident logging with full attribution — all on by default across every node. NIS2 requires 24-hour incident notification and a 72-hour detailed report. Operators running Helin can produce both from the platform, not from a pre-audit preparation exercise.

Each application runs in an isolated container with defined CPU, memory, and disk limits. A failed or compromised application cannot affect other applications or reach the underlying OS. Resource contention and lateral movement between applications are blocked at the sandbox boundary.

Two weeks in the Boskalis reference case. The infrastructure — device management, security, runtime, data pipelines — is already deployed. A second solution runs on what is already there.

No. The platform connects to existing SCADA systems via OPC UA and MQTT without replacing field devices or control room infrastructure. It sits alongside existing SCADA and closes the gap between OT data and real-time control actions.

What this is not

A cloud-first platform with an edge module bolted on

The runtime runs at the asset by design. Cloud connectivity handles data distribution and fleet management — not control decisions. If your architecture requires all processing in a central cloud and your connectivity is consistently high-bandwidth, there are cloud-native industrial platforms built for that. Helin is not one of them.

A replacement for your SCADA or historian

Helin connects to existing SCADA systems via OPC UA and MQTT and sits alongside your historian. It does not replace field devices, control room infrastructure, or the data records your operations depend on. The platform closes the gap between what your OT stack already captures and what it can act on.

A self-serve SaaS product

There is an engineering scoping and deployment process. First application live in approximately 30 days from signed order. If you need something running in hours from a dashboard sign-up, this is the wrong starting point.

A data contextualisation platform

Helin structures and filters data at the edge before it reaches the cloud. It does not provide a knowledge graph, an asset framework, or deep data contextualisation layer. Tools built for that purpose are complementary to Helin's data layer, not replaced by it.

A solution for every vertical today

Proven references are in oil and gas, renewables, and maritime. Manufacturing is in scope for Helin's ICP but has no named reference customer yet. If your environment is discrete manufacturing, we'll say that directly in a scoping call rather than fit a reference that doesn't match.

A safety system

Red Zone Manager is a monitoring and alerting aid. It does not guarantee safety outcomes, prevent injuries, or eliminate incidents. It gives operators faster, more accurate situational awareness so they can act. The crew remains responsible for securing safety on the floor.

Edge intelligence, once a month.

Field notes from industrial operations running control at the asset: deployment patterns, compliance changes, and what we learn on site. No product marketing.

One email a month. Unsubscribe at any time.

Last updated: . Information is subject to change.