See what needs attention
One operational view of asset condition, overdue work, active faults and compliance gaps.
Pointnode gives engineering teams one live operating picture for asset condition, inspections, work, records and handover.

Controlled
asset records
Traceable
engineering decisions
Field-ready
mobile workflows
Defensible
compliance evidence
Built around the shift
Pointnode organises the day around what engineers and operations leaders actually need to know next.
One operational view of asset condition, overdue work, active faults and compliance gaps.
Engineers receive clear priorities, complete controlled work and leave an auditable record.
Inspection reports, evidence, service history and sign-off stay attached to the asset.
Operations overview
A calm briefing surface makes exceptions obvious and keeps routine work compact. Leaders can scan it; engineers can act from it.


Asset passport
Identity, condition, inspections, defects, maintenance, documents and telemetry stay in one navigable history—from commissioning to handover.
No separate folders, inbox archaeology or duplicate asset registers.
Telemetry supports the engineering record instead of becoming another dashboard silo.
Every job can trace back to the defect, inspection or signal that created it.
Edge gateway · and every other way in
The Pointnode Edge Gateway sits on the plant network, reads what your existing controllers already hold, and carries it outward to Pointnode Cloud. No PLC firmware change, no inbound firewall rule, no VPN into the site. Where the equipment can send for itself — a wireless sensor, a controller that speaks MQTT — it comes straight to the platform instead, with no Pointnode hardware on site at all.
Pointnode reaches out and reads
Holding registers, input registers, coils and discrete inputs from PLCs, drives, meters and protocol gateways — with a unit ID per device behind a serial gateway. Read-only: the driver contains no write function codes at all.
Classic read-only S7 over ISO-on-TCP — data blocks, markers, inputs and outputs, addressed by rack and slot on S7-300, 400, 1200 and 1500. Read-only by construction: there is no write path, no control and no program access.
Certificate-verified, encrypted sessions — Basic256Sha256, sign-and-encrypt, no automatic downgrade — addressed by namespace-URI node IDs. Reads scalar process values; writes and method calls are not present.
The data comes to us — nothing of ours on site
For the assets that will never justify a PLC — tanks, pumps, compressors, switchgear. Uplinks arrive from your own network server (The Things Stack, ChirpStack, or a bridge posting the documented JSON) at a webhook address and secret you generate yourself in the app. Register the device against the asset, map its fields to metrics, and the readings land on the same dashboards as PLC telemetry.
A controller or gateway you already own publishes to us directly, authenticated by a certificate issued per asset from Pointnode’s own certificate authority and revealed once when the asset is created. A customer asset runs this way in production today, with no Pointnode hardware anywhere on the site.
Not yet — and we would rather say so here than have you discover it during an integration. Tokens can be generated in the app and the reference documents the first endpoints, but the gateway behind them is not switched on, and version one reads rather than writes: there is no ingest endpoint even in the planned set. Until it lands, an HTTPS integration comes in through the LoRaWAN webhook, against a device registered to the asset.
Those states are read out of the gateway’s driver registry and out of what is actually deployed, not from a roadmap. A driver that has not passed its hardware validation is refused by the gateway rather than quietly connecting and returning nothing, and anything we have not switched on yet says so above — we would rather tell you a route is not ready than have you find out from a flat line on a chart.
The gateway dials Pointnode over mutual TLS. Pointnode never dials the gateway. No inbound firewall rule, no port forward, no VPN into the plant — and the gateway’s own management interface binds to localhost unless someone deliberately widens it.
Each gateway generates its own private key, which never leaves the appliance, enrols it with a single-use setup code, and renews the certificate automatically before expiry. A shared broker password is refused outright in production mode.
Commissioning records the exact address and port of every device the gateway may reach. With that boundary enforced the gateway opens no other socket, and it resolves, checks and dials the same address so a changed DNS answer cannot move the connection.
There is no write path from Pointnode to your plant. The Modbus implementation contains no write function codes at all — not unused, absent — so “we never call it” is a structural fact rather than a convention.
Native iOS · field work
Today’s priorities, the asset, the task and the next action stay obvious. Work is designed to continue offline and sync clearly when coverage returns.
Compact visually, dependable physically.
Move from QR or tag to the live passport.
Evidence, notes and sign-off stay in sequence.
No guessing whether field work is safely stored.

Enterprise control
The platform keeps day-to-day work direct while preserving the controls, traceability and evidence expected in industrial estates.
Role-based access and organisation boundaries
Complete audit history and controlled records
Offline-capable engineer workflows
Operational states that never rely on colour alone
Bring the operation into one view