SCADA Open Platform

The platform

One database for the whole plant.

One Postgres for the plant and one historian beside it, joined by one key that follows a signal from the PLC register to the pixel, the trend, the batch, the work order and the printed sheet.

One platform. Born integrated.

SCADA, Execution Manufacturing System, Equipment Performance System, maintenance and Enterprise Reporting are not five products that talk to each other through connectors.

They were born on one database, in the same transaction, under the same rights: what the operator watches, what the line runs, what maintenance plans and what the auditor signs are the same rows — so they cannot disagree, and there is nothing to connect, because there is nothing to connect.

  • Nothing to reconcile. The tile on the wall, the sheet in the auditor's hand and the export in the analyst's spreadsheet read one server-side answer — not three that agree on a good day.
  • Nothing to integrate. The next module is a migration on infrastructure you already run, not a connector, a licence and a services engagement.
  • Nothing stranded. Start with screens and alarms; add performance, then maintenance, then production — without re-engineering a single page you already drew.
  • The difference is not what they do — it is where the data lands.
  • The work order and the PLC tag are rows in the same place, under the same security, in the same transaction. Adding the next is a migration.
  • Nothing to connect, because there is nothing to connect.

The architecture

One database. One history. One key, from the controller's register to the signed sheet.

The edges beside their controllers, live channels both ways, two servers with one address, one database with the plant's whole history compressed beside it — and every screen, order, job and signed sheet drawn from the same rows.

The controllers · the outer ringthe plant's PLCs and field devices, on the machines they drive
The edges · the inner ringone beside each controller, some in pairs · reads · judges · keeps · serves
The channelsevery edge to the core · readings in, commands out · live, both ways
The pairduty and standby · one address the plant dials
The coreone database, Postgres · the history compressed beside it, TimescaleDB
01/06

The edge

One program beside the PLC: it reads the machines, judges the alarms, keeps the data and serves the pages; it runs redundant against the same devices.

the line running in the foreground with its wall panel alive, the server rack dark behind the glass
  • The edge runs the line. The server only receives. One executable sits beside the controller and does the work the line depends on, which is why a server that stops is an inconvenience and never an outage.
  • It polls, judges and writes back. It polls the devices, judges the alarms and writes the operator's commands back.
  • All major drivers. SOP supports all major drivers — Modbus, OPC DA, Siemens S7 and OPC UA among them.
  • Cut the network and the readings wait on its own disk, then fill the gap in.
  • A dead server loses no plant data, by construction.
  • Where a line cannot afford to lose its edge, a second one stands on the same devices and takes over.
  • Proven in anger. A day-long cut of the history link: the lines still running on the plant's own edge, the missing hours back-filled in seconds when it returned — unattended.
  • Not one of these changes a screen anybody uses: the edge buffers on every install, and the pair and the emergency password are set once by the administrator.

Inside the SOP Edge Device

The SOP Edge Device — the collector beside the PLC — cut open: eight stations from the port to the page, drawn; every count exact. The link to the server is cut for a third of every cycle: watch the safe brighten and the plant's own screens come alive.

The portsit speaks the plant's own protocols — all major drivers; Modbus, OPC DA, Siemens S7 and OPC UA among them
The bencha raw count becomes a real number: scaled to its unit, a noise band, a quality mark on every reading
The watchmanthe alarm limits are judged beside the machine, on every good reading; a rule changed in the editor reaches it live, no restart
The safethe readings wait on the edge's own disk through a cut of the network, then fill the gap in when the link returns
The delivery runone reading feeds two places from one gate: the live page now, the history behind it, in batches
The order deskan operator's setpoint is taken by exactly one box, held within its limits, written, read back and stamped done
The spare control roomwhen the server goes dark the plant keeps its own pages on the LAN — armed once by the administrator, refused while the server is healthy
The pulse and the paper traila heartbeat every few seconds, and the box's own log lines readable from the console without walking to the cabinet
02/06

The server and the pair

Where every SCADA engine used to need its own standby — or a ring of servers standing by for each other — SOP protects dozens of lines with two: one duty, one standby, one address the plant dials.

The standby takes the address the moment the duty stops, with nothing lost; a planned handover is a button that refuses unless both are in step; and the standby is part of the platform, not a second purchase.

  • The server, on the substrate you choose. From scripts, in a single session, on plain hardware in your own plant, air gapped if your rules say so, or on a cloud backbone when a group runs several sites.
  • The plant and its history stand on the same box, never two systems to reconcile.
  • Duty and standby, one address that moves. Two identical servers, one address the plant dials. A planned handover is a button that refuses unless both are in step, and a standby that cannot see the plant stands down.
  • A server that stops loses no plant data: it never lived only there. One store, nothing to reconcile.
  • Adding a way to stay up costs a setting, not a licence.
the four ways the line stays up: the edge, the server, the pair, the plant's own pages on the LAN
the four ways the line stays up: the edge · the server · the pair · the plant's own pages on the LAN
03/06

The emergency HMI — we know of no other platform that does this.

If both servers are unreachable, the operators keep running the plant from the edge itself.

No extra HMI panel, no second application — the same SCADA pages the server designed are already stored on the edge, and the edge serves them directly to the operators, with the same symbols, the same commands, live values and standing alarms, until the centre is back.

the edge · the emergency HMI
A drawing with two coloured routes: green from two dark servers through the collector to the operator's station, cut at the servers; orange from the collector to a gated emergency HMI tablet on the plant LAN; four machines on a conveyor behind
green, the normal route — server, collector, HMI — cut at the dark servers; orange, the emergency route — the collector serving the gated emergency HMI on the plant LAN. Drawn, every count exact
  1. The plant's own pages, on the LAN.If the server cannot be reached, the edge serves the pages the operators trained on: the same drawing, the same symbols, the same commands, live values and standing alarms.
  2. It refuses a login while the server is healthy.
  3. Armed once by the administratorand refused while the server is healthy.
  4. The synoptics, not the business capabilities.The emergency HMI serves the plant's designed HMI synoptics with their live values and standing alarms, and the operator can send commands.
04/06

The engine under the history

PostgreSQL 17 with TimescaleDB — the same open engine crypto exchanges and trading platforms keep their tick data in. Your plant is a smaller problem than an election night.

The history is part of the platform, not a product beside it: the same database the screen is already drawing from, and every operator already has it.

the history · one tower, two rollup tiers, one trend
A drawing: a tall tower of slices, bright and loose at the top and packed and dark toward the base, on a plinth under a ring of light; a collector at the left feeding readings into its crown; two smaller stacks of plates at the right fed from its flank; a trend screen in front fed from the stacks
readings land raw at the crown and pack as they age; the minute and hour tiers keep themselves up to date from the tower's flank; the trend answers from the tier the window deserves — drawn, every count exact
the trend studio · two cursors
the trend studio with two cursors and the deltas between them
the trend studio on that history: two cursors and the numbers across the span, answered from the tier the window deserves
  1. The engine, namedPostgreSQL 17 with TimescaleDB beside it: the full community engine, hyperfunctions and all, not a private file format and not a cut-down edition.
  2. What its makers publish80 to 95 per cent compression on industrial workloads; rollups that answer in under a millisecond where the raw query took a quarter of a second to a second and a half — hundreds of times faster on compressed history. Their figures, on their own pages — we did not invent a benchmark.
  3. Who else runs itA prediction market that ramped up fourfold through an election night to carry 3.7 billion dollars of trades; an infrastructure company at a hundred thousand rows a second; a trading venue at five hundred million dollars a day and 88 per cent compression. A bottling line is a smaller problem than that.
  4. What we do with itReadings land raw and fold into a compressed column store as they age; a minute rollup and an hour rollup keep themselves up to date; the trend answers from the tier your window deserves. Ask for a month of a slow signal and it draws as fast as an hour, and the chart names the resolution it answered from.
  5. Averages weighted by countNever an average of averages; time-weighted where time is what matters. Numbers that survive an audit.
  6. A quality byte rides every readingA stale or bad value is dressed as stale or bad, never drawn as a fresh number, and never quietly averaged into a good one.
  7. Correct a value from years agoEvery total since corrects itself. No second copy to migrate, no cube to rebuild, no report to re-issue by hand.
  8. It is still just PostgresOne key from the PLC register to the pixel, the trend, the batch, the work order and the printed sheet; the history in an open database you can query with any SQL tool and back up like any database. Nothing in the stack is sunsetting.
  9. What already stands on itThe trend studio, the replay of any synoptic with no second recorder, the OEE, the batch record and the report engine: not one of them is another store. The report is computed from the rows the operator watched, so the tile and the paper cannot disagree.
  10. Proven in angerA 24-hour network cut of the historian door: the collectors kept the line running, and back-filled unattended when the door came back.
05/06

One key, from the register to the signed sheet

One key follows a signal from the PLC register to the pixel, the trend, the batch, the work order and the printed sheet. Nothing is mapped a second time.

one key · six stations, one thread
A drawing: six lit stations on a diagonal - a PLC rack, a synoptic screen with one tile gold, a trend screen with one point ringed gold, a stack of bound sheets with one gold band, a job card with one gold line, and a signed sheet with a gold seal - joined by one gold thread with a key token travelling along it
the controller's register, the synoptic pixel, the trend, the batch record, the work order and the signed sheet — one gold thread through all six, one key travelling the whole way; nothing mapped a second time — drawn, every count exact
  1. Security lives in the database and reaches the report.
  2. One signal, followed through every module.Every page, trend, alarm, report block, formula and condition that uses it — counted live, before anything is changed.
  3. We know of no other platform that follows one tag through every module of the plant.
  4. One clock, one key, one archive:the same shift on every module, one signal one identity, every sheet filed side by side.
the one key, six stations: the controller's register, the synoptic pixel, the trend, the batch, the work order and the signed sheet, joined by arrows, one amber thread over all six and the same key on every card
the six stations of the one key: the register · the pixel · the trend · the batch · the work order · the signed sheet — the same key on every card, nothing mapped a second time

For regulated plants: the technical controls Part 11 and Annex 11 require.

  • Unique accounts. A signature names a person, not a device; no signing door on a shared station.
  • Role-based authority checks. Who may open a page or send a command is decided in the database, from a whole site down to one screen.
  • Append-only audit journals. Every command, acknowledgement and shelving across the fleet, each with its moment; nothing deleted.
  • Electronic signatures with re-authentication. The signer's own password at the moment of signing; name, capacity, moment and time zone on the sheet; never withdrawn.
  • Frozen manifestation. Each run computed once, frozen on arrival, given a document number, sealed with a hash.
  • Tamper-evident records. A hash anyone can check outside the building; run it again and a second document is filed beside the first, never a refresh.
  • Compliance is achieved together with your own procedures and training.
06/06

Rights decided in the database

Who may open a page and who may send a command is decided in the database, not in a menu on a screen.

What a user may not see never reaches them — not the screen, not the export, not the printed sheet.

the page's list · the audit journal
one page narrowed to one crew — for everyone else it is gone, not greyed; and the audit journal across the whole fleet, in four lenses, filtered and exported
  1. Rights in one console, read in the database.A screen a person may not open is never sent to their browser, their export or their sheet.
  2. Why this is not a menu setting.A right set in a client menu can only withhold the drawing, because the data has already travelled. Here the rule that hides a screen is the same rule that filters the export and the printed sheet, because there is one database under all three.
  3. Row-level security in the database, not a hidden menu in the client.
  4. From a whole site down to one screen, one signal and one module.The same console reaches that far, and it keeps the record of every act that follows.
  5. Off a list a page goes away, not grey.It leaves the operator's page browser, it leaves the editor's tree, and every button that led to it goes with it; a global administrator is the one who can hand it back.
  6. The record of acts.Every command, acknowledgement, shelving and grant across the fleet, each with its moment, narrowed and exported.
the rights ladder, six rungs, each with the console word it is set in
the rights ladder: the licence · the switch · the role and the scope · the group · the list · the record, each with the console word it is set in

From the request to the running line.

Two roads, one portal: a complete VPS of your own within 24 hours, or a box in your plant installed by one command. Then the same next step: link your SOP Edge Devices and draw the first line.

Two roads, one portal

The journey drawn: the cloud road above, the plant road below, both from your portal, both ending at the running line.

Your portalrequest the licence: in the cloud, or in your plant
Our team confirmsand sends your URL and the admin access
Your server, readywithin 24 hours — a complete VPS, yours alone; nothing to install
Our team replieswith the install link and the instructions
One box, one commanda Windows machine with a fixed address; everything installs, unattended
Activate the licenceagainst your installation, once
The running linelink your SOP Edge Devices, draw the line in the editor — its pages run

In the cloud

  • A complete VPS, yours alone. Not a shared resource: one server for your plant, nothing else on it.
  • Within 24 hours. Our team confirms and sends your URL and the admin access.
  • Nothing to install on your side. Your SOP Edge Devices link to it from the plant; the editor and the pages run in a browser.
  • Hosted in Germany, in the EU. A German provider's data centre in Nuremberg, certified ISO 27001 and ISO 27701 and audited every year. A GDPR data processing agreement on request.

In your plant

  • Your own hardware, your own network. Air-gapped if your rules say so; the same product, the same database.
  • One command installs everything and asks nothing on the way; the access details it creates are yours to keep.
  • A duty and standby pair when a line cannot afford a stop; your partner or your own IT runs it.
  • Your data never leaves your premises. The server and the SOP Edge Devices sit on your network; nothing goes out unless you decide. Backed up like any database.

Capabilities

Five capabilities. One platform.

SCADA first — the plant's screens, alarms, trends and history — then the four business capabilities born on the same rows: Execution Manufacturing System, Equipment Performance System, maintenance and Enterprise Reporting.

SCADA

One page, every screen it is opened on.

The pages, the alarms, the trends and the record are the same rows — and the line's own edge keeps serving them when the centre cannot.

Execution Manufacturing System

The line runs its own orders.

Nobody presses start: the line begins and ends its own jobs from two signals, stamped with the plant's own clock.

Equipment Performance System

Lost hours stop being an opinion.

Every one has a name: the stop is named at the restart, in two taps.

Maintenance

A maintenance system that needs no data entry.

It opens on a plant that is already there: the machines, their kinds, their run history and their alarms.

Enterprise Reporting

The paperwork writes itself, sealed and signed.

A reporting engine, not a report server: the numbers on the sheet are the same rows the operator was watching.