IT, OT and IoT gateway · Zero Trust remote access (ZTNA) · self-hosted

The gateway that gathers your IT, OT and IoT equipment, and the Zero Trust access that protects it.

Your equipment connects outbound - 4G, 5G, NAT, closed firewall - to the hub you host. From there nobody reaches the network: each person opens only the machines and services they have been allowed, one by one - terminal, files, screen, PLC. Every session is logged, and recorded if you want it.

From €2,900 excl. VAT / year, the whole hub included · no inbound port · none of your fleet data on our side

The fleet, connected outbound Prise 1
The fleet, connected outbound gateways, kiosks, controllers: each one calls the hub
Looping video, 10 s - to capture
A traced session, replayed Prise 3
A traced session, replayed who, when, on which machine - and the time cursor
Looping video, 12 s - to capture

What you get out of it

One hub to supervise, to reach and to prove

Supervise

The agents report telemetry and metrics from the equipment. You see what answers and what no longer does, and you prepare the work before opening a session.

Control

Rights are granted by role, by fleet and by target. A contractor gets what the job needs, and loses it in one gesture once the job is done.

Prove

The log keeps who came in, on which machine and for how long. Terminal and screen sessions replay. You do not tell what happened: you show it.

Industrial remote access without open ports Self-hosted OT bastion and ZTNA Remote access to PLCs and HMIs

What the hub is

Gateway and bastion: both, that is the hub

PipeLinker Hub brings together a gateway, which gathers the agents' outbound connections, and a bastion, which decides on remote access. Not two pieces of software: one application and a PostgreSQL database, hosted on your premises.

1 · The gateway

The whole fleet comes to you

The agent on each machine opens an outbound connection to the hub and keeps it. Nothing to open on site, nothing to ask the carrier for, and a whole fleet that reconnects on its own after an outage.

  • Telemetry, inventory, software bill of materials
  • Signed updates, rolled out progressively
  • Controlled commands, logged
  • One fleet per site or per customer, partitioned
  • 4G · 5G
  • NAT
  • closed firewall
  • site link
  • Linux · Windows · Android
  • embedded systems included

2 · The bastion

Remote access, controlled and traceable

From the console you jump through the agent to the machine and to what sits behind it: PLC, HMI, camera, Windows workstation. Every access is granted by role, limited to one destination, and leaves a trace you can show.

  • Terminal, files, SSH, SFTP, VNC, RDP, web
  • Sessions recorded and replayable
  • Audit log: who, what, when, for how long
  • Immediate revocation, automatic expiry
  • Target credentials sealed in the hub, never handed to the person intervening
  • Refusals counted by origin, addresses blocked, alerts
  • RBAC
  • recording
  • replay
  • supervised mode

Seven ways to reach a machine, in detail Hosting the hub

The range

Four pieces make the base, two make the work faster

The base is the hub on your premises, one agent per machine, and the portal on our side, which the hub does without if you want. The two applications come on top, for people: they make some tasks faster, and none possible that the console would not allow. The range in detail.

The base - only one to host

On your premises · on a server

PipeLinker Hub

The gateway and the bastion: one binary with its web console, backed by PostgreSQL. It is what you buy and what you host.

  • Debian package
  • Linux
  • x64 · ARM64
Hosting the hub

On your premises · per machine

PipeLinker Agent

On the gateway, the kiosk, the controller. It calls the hub outbound, reports its state, receives signed updates, and opens what lives behind it.

  • Linux
  • Windows
  • x64 · ARM64
What it does and refuses

On your premises · on Android

PipeLinker Agent Android

The same agent for kiosks, rugged terminals and production tablets: telemetry, inventory, commands, a terminal and files within the limits of the system.

  • Android
What it does on Android

On our side · optional

PipeLinker Portal

Your licence and the signed binaries. The hub only connects to it if you enable it - a setting, off by default - and on an isolated network the files are dropped by hand.

  • off by default
  • none of the fleet's data
Updates

Two applications, to go faster

On your premises · on the workstation

PipeLinker Desktop

Your usual tools - PLC client, database, remote desktop - reach the equipment by name, through the hub. The key lives in the TPM.

  • Windows
  • Linux
In which offers

On your premises · in the pocket

PipeLinker Mobile

The fleet, the map and the alerts in your pocket. And on a machine: terminal, files, screen, remote desktop, internal web pages. The hub's password never goes in.

  • Android
In which offers

How it works

Three steps, and your fleet is in the console

One hub to host, and it is on your premises. No VPN per site, no firewall rule to negotiate.

  1. The hub installed, its console answers Prise 0
    The hub installed, its console answersthe door, at your address, before any fleet and any agent

    Install the hub on your premises

    A Debian package, seven questions, a PostgreSQL database. One public address and two names. On your server, in your network.

  2. An agent enrolled from the console Prise 12
    An agent enrolled from the consolethe form, the platform, then the command to paste on the machine

    Put the agent on your machines

    Linux, Windows or Android. It calls the hub outbound, once, and keeps the channel open. No port to open on site, nothing to ask the carrier for.

  3. A terminal on a remote machine Prise 2
    A terminal on a remote machinefrom the click to the prompt, with nothing opened

    Act from the console

    Terminal, files, screen, remote desktop, web interfaces of the PLCs behind the agent. Every session is traced, recorded if you want it, and revocable in one gesture.

Who it is for

You will recognise yourself in one of these cases

Three ways of running a fleet, and three reasons to want a bastion. The hub was built for all six, and the "Who it is for" page says what it does in each.

You run several sites

Plants, installations, depots. One fleet per site, partitioned, and one screen for all of them. The technician acts from headquarters instead of taking the road.

What the hub does for you

You run your customers' fleets

Integrator, maintainer, industrial managed-service provider. One fleet per customer on a single instance, rights per person, and a log you can show.

What the hub does for you

You build machines

Your equipment is at your customers'. The agent on the machine reports its state, receives its signed updates, and opens you an access without touching the customer's network.

What the hub does for you

Your machines have no public address

Behind a 4G or 5G router, a NAT, a firewall that lets nothing in. The agent calls the hub outbound, and you get in through that channel: without knowing the site's public address, without opening a port there, without a VPN to deploy.

What the hub does for you

You must know who did what

Rights are granted by role and by fleet, sessions are logged and recorded, and the machines' credentials can stay sealed in the hub: the person intervening opens the session without ever receiving the target's password.

What the hub does for you

You bring in contractors

An account that stops on the date you set, an access limited to one destination, revocable in one gesture, with a second factor required by role. No account on the machine, no VPN to open for them, and a trace of what they did.

What the hub does for you
  • 0inbound port to open on your sites. The agent goes out, nothing comes in.
  • 1binary to host, with a PostgreSQL database. Nothing else to run.
  • 7protocols, all logged: shell, SSH, SFTP, VNC, RDP, raw port, proxy.
  • 3systems for the agent: Linux, Windows, Android - on x64 as on ARM64.

Self-hosted

Your hub, in your own environment

Most remote-access solutions run through a platform the vendor holds. Here the hub is installed on your premises: you choose where it lives, your fleet data and your access logs stay there, and an outage on our side does not close your sites. That is what the autonomy of an industrial site, a network that is not always online, and a governance that must say where its records are all ask for.

Pricing

A self-hosted Hub sized to your fleet

Three offers and a custom one. The whole hub in every offer; what varies is the number of machines, accounts and fleets - and the two applications, PipeLinker Desktop on the workstation and PipeLinker Mobile on the phone. Yearly prices, in euros, with no cost per session or per connection.

From €2,900 excl. VAT / year, the whole hub included

The licence is yearly, and when it expires you never go blind on your fleet: monitoring goes on, only the actions stop.

See the three offers

Before you write to us

The four questions we are asked first

Do we need to open a port on our sites?

No. The agent opens an outbound connection to your hub and keeps it. Nothing listens on site.

Does our data go through you?

No. The hub is on your premises; we see neither your machines, nor your sessions, nor your logs. The portal only serves the licence and the binaries, and only if you enable it.

What happens when the licence expires?

The console opens, telemetry comes in, alerts arrive. Only the actions stop, and you are warned thirty days ahead.

What about PLCs that cannot carry an agent?

An agent on a machine of the same network acts as their gateway: web interface, VNC, RDP, SSH, raw port. Nothing to install on the PLC.

All the frequently asked questions

Let's talk about your fleet

Tell us what equipment you manage, how much of it, and behind which networks. We answer with concrete sizing (CPU, memory, storage), a demonstration on a case close to yours, and what would need adapting for your hardware.

Or write to us directly: contact@pipelinker.fr
A question first? The questions we are asked