Why HartBeat

Every other layer of the enterprise became remote, identity-governed, and audited years ago. Field instrumentation, where mistakes are among the most consequential, was left behind. HartBeat brings that model to HART field instruments.

The field-instrument access blind spot

Process plants run on HART smart instruments: the pressure, temperature, level, and flow transmitters that measure and control chemicals, water, energy, pharma, and food production. HART is among the most widely deployed smart field-instrument protocols; FieldComm Group cites over 40 million HART instruments installed worldwide (source: FieldComm Group). Yet reaching those instruments has barely changed in decades:

  • Access means being there.A technician at the device with a handheld or laptop, or an ad-hoc remote setup stitched together case by case.
  • There’s rarely a usable record.Who changed that transmitter’s range last month? The answer is scattered across local tools, service notes, screenshots, and memory.
  • Access is all-or-nothing.There’s no clean way to give a contractor working access for an afternoon and then prove what they did.

A VPN gets someone in. HartBeat tells you what happened next.

Secure remote access is normal in IT, and the tools that broker it keep session logs that show someone connected. HART-IP gateways keep their own local log of who connected, and asset-management tools log configuration changes on the systems they run on. HartBeat adds a centralized, persistent, tamper-evident record on top: which instrument was reached, which HART command was sent, under what authority, and with what result, across every site and every person.

A VPN log ends at the connection. A HartBeat record continues command by command to a signed record. VPN log Signed in Connected No record of what happened at the instrument HartBeat Signed in Session on LT-204 Read, allow Read, allow Write, flagged Each command classified, evaluated, recorded Signed record

Your tools still matter

Plants already run configuration and diagnostics software they trust, and technicians shouldn’t have to relearn their craft. HartBeat doesn’t replace those tools. It gives them a secure remote path and adds an evidence layer across sites, people, vendors, and sessions.

Keep your tools; govern the access path.

Evidence, not reconstruction

HartBeat’s record is evidentiary by construction: every record is digitally signed and chained to the one before it, so any edit, deletion, or reordering is detectable. Integrity is mathematical, not “we promise we keep logs.”

When an auditor asks who changed what, you hand them an export rather than a reconstruction.

See a sample audit record

Why now

  • OT security expectations and regulation

    The ISA/IEC 62443 family (IEC 62443-3-3, Foundational Requirement 6, covers auditable, tamper-protected logs and remote-session logging), NIST SP 800-82 Rev. 3, and US EPA water-sector cybersecurity guidance all expect controlled, accountable remote access, including for vendors.

  • Workforce change

    Experienced instrumentation people are retiring and field teams are thinner, so scarce expertise has to reach many sites remotely.

  • The cost of the truck roll

    Sending someone to a site for a task that should take minutes remotely.

  • Contractor and vendor risk

    Third parties need device access, and today that access is hard to scope and harder to audit.

What makes it new

The combination, aimed squarely at HART field instruments:

  1. remote reach to HART instruments,
  2. identity- and policy-aware access,
  3. a tamper-evident, exportable record of every HartBeat-mediated interaction,
  4. strict isolation across organizations,
  5. while technicians keep the tools they already use.

Pieces of this exist in adjacent worlds. What has been missing is this model applied to the field-instrument layer, where it has been hardest to do and where the consequences of ungoverned, unrecorded access are highest.

Set up a trial with our team.

Contact sales to set up a trial: for distributed operators, service teams, and instrumentation groups ready to evaluate governed remote HART access.