Gateway and service boundaries
Identify the agent host, OS/architecture and reachable service targets. Device authorization does not mean separate roles for every service on that device.
We are developing EdgeSocket to reach existing services on industrial PCs and machine-data gateways across production lines. Each maintenance user connects only to edge devices they are authorized to access.
A maintenance team wants to review status in an existing gateway web app or diagnose it through an approved SSH service. This example is not a PLC control integration or access to the entire production network.
An organization administrator explicitly grants the maintenance user access to a specific gateway. Organization membership or an admin role does not automatically grant connection rights.
The authorized operator reaches the configured TCP/UDP service through a local connection address. The target application’s user accounts and permissions still apply.
Device access or the relevant identity can be revoked. Existing signaling/TURN checks enforce revocation; active-session shutdown behavior must be validated in the actual deployment.
Identify the agent host, OS/architecture and reachable service targets. Device authorization does not mean separate roles for every service on that device.
Manage user/device identities and explicit enterprise grants. Simple onboarding, SSO and a management GUI are future work; a ready-to-use end-user portal is not available today.
Exercise connection loss, revocation and maintenance windows in an isolated pilot. The site owner should approve targets and production impact; audit and update workflows need further work.
Direct P2P can avoid routing application traffic through a relay and may reduce latency. If a direct connection cannot be established, an accessible, authorized TURN server relays encrypted traffic. This does not change network policies or guarantee universal connectivity or minimum latency.
Explore the connection technology →Cloud and complete on-premises deployment options are planned. We publish security preparation, a source SBOM and remaining work on the CRA page. We do not claim CRA conformity or IEC 62443 certification; real field acceptance remains open.
CRA preparation and source SBOM →The existing enterprise model grants a user access to a specific device explicitly. Other devices do not become available automatically. Separate service/port authorization and time-window approval workflows are not complete.
EdgeSocket provides transport to existing TCP/UDP services. Industrial protocol addons, application accounts and control logic are separate concerns; no ready-made SCADA/PLC integration is offered.
A ready and validated fully isolated deployment is not claimed. On-premises signaling, authority and any required TURN connectivity need their own design and tests.
Share the gateway/PC type, existing services and number of teams that need access. The product is in development; let’s identify pilot requirements early.