How HartBeat works
HartBeat is secure, governed remote access to your HART field instruments, with a tamper-evident record of every HartBeat-mediated interaction. Connect to, work with, and account for instruments from anywhere, without replacing the tools your technicians already use.
Three parts, one record
-
A small site connector
It runs at your site beside your existing HART-IP gateway and reaches outbound to HartBeat over an encrypted, mutually authenticated connection. Nothing on the plant network has to accept inbound connections from the internet.
-
A secure web application
Authorized people sign in at core.hartbeat.app, see their sites, gateways, and instruments, discover devices, run remote work sessions, manage their team and access policy, and review the audit trail.
-
A tamper-evident audit record
Every device interaction is classified, checked against your access policy, and written to a digitally signed, append-only record that can be searched and exported.
HartBeat is multi-organization by design: each customer organization is strictly isolated from every other.
Connect. Work. Record. Prove.
A small connector at your site reaches out to HartBeat. Your people sign in, work with instruments through their usual tools, and every command lands in a signed record.
Connect
A lightweight site connector links your HART-IP gateway to HartBeat through an outbound, encrypted connection. Nothing on the plant network has to accept connections from the internet.
Work
Technicians sign in with their own identity and work with instruments through a governed HartBeat session, using familiar instrument software.
Record
Every HART command is classified, evaluated against your access policy, and written to the audit trail with the decision and the outcome.
Prove
Search and export a signed, tamper-evident record for troubleshooting, audit support, and accountability.
Four roles, clearly scoped
Give each person the access their job needs, instead of all-or-nothing.
| What people can do | Administrator | Engineer | Contractor | Auditor |
|---|---|---|---|---|
| Sign in with a personal account | ✓ | ✓ | ✓ | ✓ |
| Invite people, assign and change roles, remove access | ✓ | |||
| Choose which access policy is active | ✓ | |||
| Add a site connector, register a gateway, discover instruments | ✓ | ✓ | ||
| Open a remote work session with their own tool | ✓ | ✓ | ✓ | |
| See session history | ✓ | ✓ | Own sessions | |
| Search and export the audit record | ✓ | ✓ |
Customer administrators manage their own organization, and nothing in the product lets anyone escalate beyond it.
What HartBeat does today
Secure connectivity
- A site connector links your HART-IP gateway to HartBeat over an encrypted, mutually authenticated connection that starts from inside the site.
- Each connector proves which organization it belongs to before it can carry traffic.
- The app shows whether each connector is online, with a heartbeat indicator.
- Connectors reconnect automatically after network interruptions.
- Validated with live instruments over a local plant network and over a cellular-connected remote site.
Working with instruments
- Register a gateway, test connectivity, and trigger device discovery.
- Discovery finds the HART instruments behind a gateway, including sub-devices, and records tag, device identity, manufacturer, device type, and firmware and hardware revisions.
- A searchable inventory by tag, device, or gateway, with a detail page per instrument.
- Technicians use the software they already use. Endress+Hauser DeviceCare has been validated with live device sessions, including vendor device-type managers (DTMs) reading live parameters. HART-IP-capable configuration software connects through the HartBeat desktop client.
- Every remote work session is opened under a named person against a specific gateway, timestamped, and listed in the Sessions view.
Governance and accountability
- Every HART command is classified (identity, read, write, calibration, gateway, vendor-specific, and so on), checked against your active access policy for that person’s role, and recorded with the decision and the reason.
- Each record shows the policy decision and what actually happened to the command, so a reviewer never has to guess whether a flagged command was carried out.
- Each interaction is written as a digitally signed event, chained to the one before it, so any alteration, deletion, or reordering shows up.
- Administrators and auditors export the record, or the slice matching a search, as a spreadsheet-ready file.
- View your organization’s access policies and choose which one is active.
- Privileged administrative actions, including anything HartBeat’s own operators do on your behalf, are signed and recorded on a separate record.
Organization and team
- Administrators invite, edit, and remove their own people and assign roles. Removing someone ends their access.
- Everyone signs in with their own identity. No shared accounts. Repeated wrong passwords lock the account temporarily.
- One organization can never see another’s sites, devices, sessions, people, or records.
On our roadmap
Directional, not available today. We share it so you can see where HartBeat is heading.
- Enforcing mode: out-of-policy commands withheld, not only flagged
- Approval workflows: sign-off before sensitive changes
- Finer-grained access: per-device, per-site, and time-limited grants
- Device and network health monitoring, with signed records when a device or link goes silent
- Store-and-forward at the site: no lost records and uninterrupted local work during cloud maintenance
- Calibration records and scheduling
- Configuration backup, restore, and templates
- Out-of-band change detection: flag instrument changes made outside HartBeat
- Site map of distributed devices
- Full self-service export of all organization data
- Self-serve plans with online checkout and automatic setup
- Branded organization addresses
- Integrations: security monitoring (SIEM) feeds, webhooks, maintenance and work-order systems, API access for other systems
- Web-based device configuration in the browser, without a desktop tool
- AI-assisted insights (advisory only, never in the control path): plain-language audit search, anomaly spotting, compliance summaries
- Historical trends for instrument readings
- Single sign-on with your identity provider, and multi-factor sign-in
- Email and webhook alerts
- Public status page for service health and maintenance notices
See it in a record
The clearest way to understand HartBeat is to read what it records.
Set up a trial with our team.
Contact sales to set up a trial: for distributed operators, service teams, and instrumentation groups ready to evaluate governed remote HART access.