Architecture overview
How HartBeat connects your site, your people, and the record, at the level we publish. Security reviewers can go deeper in an architecture review under NDA.
The three parts
Illustration: your site, HartBeat, and your people. Fictional site, people, and readings.
Four things to know
-
Outbound from your site
A small connector runs at your site beside your existing HART-IP gateway and reaches outbound to HartBeat. Nothing on the plant network has to accept inbound connections from the internet.
-
Encrypted and mutually authenticated
The link between your site and HartBeat is encrypted, and both sides prove who they are. Each connector proves which organization it belongs to before it can carry traffic.
-
Personal sign-in, scoped roles
Everyone signs in with their own identity, with no shared accounts. Four roles give each person the access their job needs, and repeated wrong passwords lock the account temporarily.
-
A signed record
Every HART command is classified, evaluated against your access policy, and written to a digitally signed, append-only record. Each record is chained to the one before it, so any alteration, deletion, or reordering is detectable.
Each customer organization is strictly isolated from every other: one organization can never see another’s sites, devices, sessions, people, or records.
What we don’t publish, and how to get it
We don’t publish ports, protocols, cryptographic details, hosting providers, or internal components. Publishing them would map an attack surface without helping you evaluate HartBeat. Security reviewers can request an architecture review under NDA.
Set up a trial with our team.
Contact sales to set up a trial: for distributed operators, service teams, and instrumentation groups ready to evaluate governed remote HART access.