Pricing

A self-hosted Hub sized to your fleet

Three reference points for sizing PipeLinker to your fleet and to the way your teams work. Every licence includes the self-hosted Hub, the agents, the telemetry, the logs and the controlled access. What varies: the fleet capacity, the users, the isolated fleets, and the PipeLinker Mobile and Desktop applications. Hosting stays yours: the price covers the software and its capacity, not the machine that carries it. Yearly prices, in euros, excluding VAT.

Pilot

Validate PipeLinker on a real-world, self-hosted deployment.

€2,900 excl. VAT / year

  • €2,755 excl. VAT / year over 2 years, i.e. -5 %
  • €2,610 excl. VAT / year over 3 years, i.e. -10 %

At the offer's ceiling: €24.17 per device per month.

  • 10 devices
  • 2 users
  • 1 fleet
  • 50 declared services
Request this offer

Control

Access authorised equipment with PipeLinker Mobile and Desktop, from the field or your workstation, while retaining control over access across your environments.

€9,900 excl. VAT / year

  • €9,405 excl. VAT / year over 2 years, i.e. -5 %
  • €8,910 excl. VAT / year over 3 years, i.e. -10 %

At the offer's ceiling: €2.75 per device per month.

  • 300 devices
  • 15 users
  • 10 isolated fleets
  • 600 declared services
  • PipeLinker Mobile, on Android
  • PipeLinker Desktop, on the workstation
Request this offer

Custom

Larger, several customers, or hardware of your own.

on quotation

  • Beyond 300 devices
  • One fleet per customer
  • PipeLinker Mobile, on Android
  • PipeLinker Desktop, on the workstation
  • An agent for your hardware
  • A named contact
Request a quotation
Between two examples, or beyond: compose your own. The price follows the same grid as the cards - no step to jump, no hidden formula. Tell us the size, we answer with a price.

What the licence caps, and what it leaves open

Every licence comes with clear capacities. Devices are what mainly sets the price; users, isolated fleets and declared services frame how the Hub is used. They are capacity limits, not consumption meters, and never an automatic bill.

The four caps

  • Devices - a machine where the agent is installed. That is what makes the price.
  • Users - a person who opens sessions, and takes on a responsibility.
  • Isolated fleets - one partition per site or per customer, generous at every step.
  • Declared services - the targets an agent reaches: a PLC, an HMI, a web interface, a workstation, a port or a terminal. It is an included capacity limit, which keeps one agent from exposing a whole network without bound.

No cap

  • Sessions, connections, minutes: open ten terminals or two hundred, the bill does not move.
  • Protocols: terminal, files, SSH, SFTP, VNC, RDP, web - and the ones we will add, with nothing to renegotiate.
  • Authorities and certificates: one per fleet, as many leaves as needed.
  • Volume: telemetry, logs, recordings.

PipeLinker Mobile, on Android: the fleet, the map and the alerts, and on a machine the terminal, the files, the screen, the remote desktop and the internal web pages. PipeLinker Desktop, on your workstation, for the gestures the browser does not do: your usual tools reach the equipment by name, and a remote desktop opens in the workstation's own client. PipeLinker Mobile and PipeLinker Desktop are included depending on the offer; they are not sold separately.

How you pay, and what happens at expiry

A yearly subscription, because the work goes on: the versions, the protocols, the security fixes. And an expiry that never leaves you blind on your fleet.

One, two or three years

Paid up front over several years, the licence costs less: 5 % over two years, 10 % over three. It is not a volume discount, it is a discount for certainty. Beyond that, a longer term is agreed in the contract - and we are the ones who propose it.

What goes on once the licence has lapsed

  • The console opens, the fleet can be read
  • Telemetry comes in, alerts arrive
  • Your agents and your certificates stay yours
  • Your data stays with you, whole

What stops

  • Commands and actions on the machines
  • Rolling out updates
  • Remote access and sessions
  • Enrolling new devices

The console warns you thirty days ahead.

What is not in the licence

Three services, billed separately, and none of them is indispensable: they are bought to go fast and sleep well.

Onboarding

Billed once, on time spent: installation, TLS, first fleet, enrolment, getting started. The installation comes down to one public address, two names pointing at it, a certificate, a PostgreSQL database and the hub's Debian package, which sets the rest up in seven questions - a team that already runs a server does it alone, with the documentation.

Support over time

A yearly allowance, interventions as needed, or nothing. The hub runs without us: we are there to help you progress, not to keep it running.

Custom development

In engineering days: an agent written for your hardware, metrics and actions specific to your business. What the third offer does not cover is quoted here, with the demonstration, before any commitment.

What comes with it

A customer area

Your licence, your installations and the signed binaries - agents, Desktop, Mobile, hub versions - in one place. Nothing is requested there, everything is recorded there.

Updates, at your pace

Your hub only contacts the portal if you ask it to: check, download or install, from one to twenty-four times a day - or nothing at all, and the files are dropped by hand.

Fixes, and reported vulnerabilities

A fix is not a service, it comes back to you because your licence is alive. A security report takes a separate path, and a faster answer.

Published by security people

LOOTUS SECURITY publishes the software and does the trade next door: secure development, audits and penetration testing, consulting. A bastion written by people who spend their days looking for how one gets in.

The licence in detail

What we commit to, point by point.

What a fleet is, and what it is for

A fleet is a logical partition inside your installation. One instance, one binary, one database - but fleets that do not see each other.

Each has its own managers, its own rights and its own agents. Someone attached to one fleet does not see another's machines; they do not even know they exist.

Two uses, and those are the only ones

Dividing yourself up. By site, by installation, by trade, or to separate what is in production from what is in acceptance testing. That is the case of a manufacturer who does not want a technician from one plant to reach another's machines.

Running your customers' fleets. A managed-service provider runs each customer's fleet without ever mixing them, and without installing one instance per customer. That is the use the partitioning was built for.

The boundary is not just a display filter

Each fleet has its own certificate authority, whose name constraint limits what it can ever sign. An identity claiming to belong to another fleet is refused by the verification library before reaching any application check. One identity per device, compatible with your PKI

What a fleet is not

It is not a second installation: there is only one hub, one database and one console. Nor is it a customer counter: nothing forces you to create one per customer if your operations do not call for it.

What the licence allows you to do

It covers operations - yours, and the ones you carry out for your customers. Both uses above are in it, without reservation.

What it does not cover is reselling the solution itself: redistributing it, reselling it under your name, or embedding it in a product you put on the market. That is not a refusal - it is a different conversation, with different terms and different commitments on our side. Let's talk about it

The line is there, and it is simple: are you selling a service this product helps you deliver, or are you selling this product? The first is your trade, and the licence is made for it.

Beyond the third offer, write to us

This is not a wall: it is where a grid stops being the right tool. Beyond it, the price per device falls faster than these three cards can write - an operator running a thousand machines does not pay three times what one running three hundred pays.

It is also the scale at which the questions stop being about price: database sizing, retention period, disaster recovery, sometimes a second instance. They are settled by talking, not by reading a card.

Describe your organisation to us

What we count, and what we do not - in detail

A PipeLinker licence counts machines and accounts. That is what costs to keep: an agent reports its state, receives its signed updates and renews its certificate; a console account opens sessions on your equipment, and takes on a responsibility. Those two numbers decide the price.

They are also the limits the hub applies itself, on your premises: what you bought and what the machine allows are the same document. No gap to discover six months later, in either direction.

What is never counted

Neither sessions, nor connections, nor minutes. Open ten terminals or two hundred, the bill does not move. That is what makes nobody on your side hesitate before going to check something on a machine - and monitoring you hesitate to open is of no use.

Nor protocols. Terminal, files, SSH, SFTP, equipment web interfaces, remote screen, remote desktop: everything is there, in all three offers. And the ones we add will be too, with nothing to renegotiate.

Nor certificate authorities, nor certificates. Partitioning properly is an architecture decision; it must not carry a price.

Nor volume. The data your agents report, the updates you roll out and how long you keep all of it are not billed: the licence counts neither bytes nor days.

Devices: those are your agents

A device is a machine carrying an agent. The PLCs, HMIs and equipment you reach behind an agent do not count as a device: they are declared as services, and an offer carries plenty of them to cover a real fleet.

Users: the console's accounts

Their number follows your organisation, not your technology. A fleet is run by three or four people; the offers are sized on that, not on your site's headcount.

Fleets: partition without counting

A fleet is a partition: a group separated from the others on the same instance, with its own managers, its own rights and its own authority. The hub carries it anyway, so the offers are generous - two, ten, twenty-five. You should never give up separating two customers or two sites for a licensing reason.

Why a subscription, and what happens if you stop it

Why a subscription, and what happens if you stop it

You do not depend on us to operate. You depend on us to progress. The hub runs on your machines, in your network, with your certificate authority: we hold neither your data, nor your keys, nor the path to your equipment. At expiry, nothing is taken back from you.

What goes on once the licence has lapsed

  • The console opens, the fleet can be read
  • Telemetry comes in, alerts arrive
  • Your agents and your certificates stay yours
  • Your data stays with you, whole

What stops

  • Commands and actions on the machines
  • Rolling out updates
  • Remote access and sessions
  • Enrolling new devices

The console warns you thirty days ahead. Losing control over a billing failure is a decision we refused to take: you never go blind on your fleet.

What the subscription pays for is that the work goes on. A publisher who sells once has no economic reason to still ship fixes in eight years - and that is the life of an industrial machine. You are not renewing the right to use what you already have: you are renewing the versions to come, the protocols we add without renegotiating your licence, the security fixes, and the signed updates your own compliance with the Cyber Resilience Act depends on.

Beyond a certain size, we stop publishing a price

Past the third offer's ceilings, it is a quotation. This is not commercial coyness: at that scale, database sizing, retention period and architecture weigh more than the price, and a published figure would be an extrapolation we would have to take back in front of you.

Your customer area, and updates at your pace

Everything that ties you to us lives in one place, portal.pipelinker.fr: your licence, your installations, the binaries your licence allows, and the notes for each version. You have no account to claim and no archive to dig out of an e-mail thread.

Your licence and your installations

Every installation is there with its licence, its expiry and its token. That is where the first binary comes from, and where you come back on the day you set up a second instance - a pilot site, an acceptance environment, a second plant.

Nothing is requested from that portal: everything is recorded there. What is negotiated is settled by a quotation and a conversation, not by a form. The portal only records the conclusion, which spares it from being a public door open on the internet.

Updates, at your pace or not at all

Your hub only contacts the portal if you ask it to. The setting starts off, and you choose how far it goes: check that a version exists, download the binary without installing anything, or - for the hub itself - install. Three steps, each set separately for the agents and for the hub.

The pace is yours: from one to twenty-four times a day, four by default. A reactive mode exists for an installation being set up - every five, ten or fifteen minutes -, to be kept for low-criticality environments, since updating the hub restarts the service.

And you can never enable it. The binaries are then dropped by hand, the link to us does not exist, and nothing changes in how your fleet works. When the hub queries the portal, it presents its installation's token - the only secret you receive - and the console offers you the version, with its note.

Everything we publish is signed, and nothing installs unless the signature matches - neither an agent, nor the hub itself. The key that verifies is compiled into the binary; the one that signs is neither on the portal nor on your hub. How the chain holds

You can also automate nothing at all and come and fetch the binaries by hand. On a network cut off from the internet that is the only path - and the product works identically.

We warn you, and not about everything

Two notices reach you by e-mail: your licence's expiry approaching, and the release of a version. Only the second can be turned off, and the distinction is not an accident - an expiry is not news, it is an obligation, and nobody should be able to miss it because they unticked a box.

What you get from us, and how

A hand at installation

Onboarding includes the time it takes to get you installed: setting up the hub, its TLS, its first fleet, enrolling the first machines and handing you the use of it. Nobody leaves you alone in front of an empty console.

That is real time, billed once. Beyond it, support over time is the subject of dedicated services, sized with you according to what your operations require: a yearly allowance, interventions as needed, or nothing at all if your teams run it alone.

Reporting a defect

Behaviour that does not match what the documentation says interests us, even without certainty that it is a defect. We reproduce it, and what is fixed goes into a version your hub will see: a fix is not a service, it comes back to you because your licence is alive.

What helps most: the hub's version and the agent's, what you expected, what happened, and the time - the audit log then lets us find the session.

Reporting a vulnerability

A security report takes a separate path and a faster answer than the rest. We acknowledge receipt, we tell you what we have understood, and we keep you posted on the fix until it is published.

We ask you in return to let us publish before going public: another customer's fleet may be running the same version as yours.

It is your obligation too, not only ours

If you put a connected product on the European market, the Cyber Resilience Act will ask you for a point of contact where a vulnerability can be reported to you, and a procedure behind it. We keep one for our product; your fleet helps you keep yours, by telling you what is running and where. What the regulation asks

What we do not announce

No opening hours and no response time on this page, and that is deliberate. A published commitment that the first incident would contradict is worth less than no commitment at all, and a deadline held for everyone whatever the contract is not a promise one seriously makes to thirty customers from Brittany. What we do commit to is agreed with you, and written in the contract.

What stays true in every case: the people who answer are the ones who write the code. There is no first line rereading a script before escalating, because there is no first line.

Your data goes nowhere

Your fleet's inventory, your readings, your devices' positions, your session recordings: all of it lives in your PostgreSQL database, on your machine. Not in a service we run, not at a hosting provider we would have chosen, not in some vendor's region.

The difference with a "sovereign" solution hosted in France is real and worth saying: in that case your data is indeed on French soil, but on a third party's machine, under a processor's responsibility, with a processing agreement to keep. Here there is no transfer at all. Nothing to govern, nothing to audit on our side, no extraterritorial law to invoke: there is no server on our side for it to bear on.

On a network cut off from the internet the product works identically. Updates are then dropped by hand, and the link to our portal simply does not exist.

Published by security people, in Brittany

PipeLinker is designed, written and maintained in Rennes by LOOTUS SECURITY, a cybersecurity company. It publishes the software, and it does the trade next door - which is what gives a bastion its seriousness: it is written by people who spend their days looking for how one gets in.

  • Secure design and development, IoT, IT/OT and web: the logical and physical security of systems, network architectures, applications and electronic products, taken from the design stage rather than added afterwards.
  • Security audits and penetration testing, IoT, IT/OT and web: the gap to standards and to the state of the art measured at the end of each cycle, on systems, on web applications, and by reverse-engineering embedded systems.
  • Cybersecurity consulting, one-off or yearly: supporting the processes that hold an environment's security, or a compliance validation.

And a short chain, which is not a local-produce argument: the person who takes your call is the one who reads the code, support is in French at your hours, an adaptation to your hardware is discussed with whoever will write it, and an urgent fix does not cross three time zones before being understood.

Custom work, kept separate

Our agents cover Linux, Windows and Android. When your fleet holds something else - a microcontroller board, a real-time system, a PLC, a target whose manufacturer imposes its toolchain - we write the agent that is missing, in the language the target imposes.

It comes on top of the licence and is billed in engineering days, never folded into the package: mixing it in would mean trimming it to make it fit. How we write an agent

How we discuss it

The prices are published and you read them without talking to us: that is deliberate, and rare enough in this trade to be worth saying. What you gain by writing to us afterwards is concrete sizing - processor, memory, storage, retention -, a demonstration on a case close to yours, and a straight answer about what would need adapting for your hardware.

Tell us what you run

How many devices, users and isolated fleets? We answer with a price on the same grid, and a demonstration on a case close to yours.

Understand what each piece of software does