Welcome to ControlSphere

Enterprise-grade Supervisory Control and Data Acquisition platform for industrial monitoring, control, and automation.

Checking system status...
Enterprise Security

Security Features

Industrial-grade security built for critical infrastructure protection

Multi-Factor Authentication

TOTP-based 2FA with Google Authenticator support, 8 recovery codes, configurable time windows, and escalated lockout after failed attempts to prevent brute force attacks.

Enterprise SSO

OAuth 2.0 (Microsoft, Google), SAML 2.0 (Azure AD, Okta), and LDAP/Active Directory integration. MFA enforcement continues after SSO authentication.

Command Signing

HMAC-SHA256 cryptographic signing of all control commands with unique nonces and 60-second timestamp windows, preventing replay attacks on critical operations.

Role-Based Access Control

Spatie Permission-based RBAC with organization and site-level isolation. Granular permissions per feature with hierarchical role inheritance.

Audit Logging

Hash-chained tamper-proof audit trail with full request logging, sensitive data masking, and 5-year retention for compliance and forensic analysis.

Gateway Security

API key + IP allowlisting, mTLS certificate authentication, constant-time verification preventing timing attacks, and rate limiting per gateway.

Compliance

Standards & Certifications

Built to meet industrial cybersecurity and operational standards

IEC 62443
Industrial Cybersecurity

Human/software identification (SR 1.1-1.2), authorization (SR 2.1), audit events (SR 2.8), communication integrity (SR 3.1)

ISO 27001
Information Security

Access control (A.9), operations security (A.12), incident management (A.16), compliance monitoring

NIST 800-82
ICS Security Guide

Network segmentation, error handling, comprehensive audit logging, defense-in-depth architecture

ISA-18.2
Alarm Management

4-tier severity levels, alarm shelving, escalation workflows, flood detection, rationalization support

NERC CIP
Critical Infrastructure

BES categorization, security management controls, personnel training, recovery planning

Architecture

System Architecture

Secure, scalable architecture designed for industrial environments

Field Devices

PLCs, RTUs, Sensors

Gateway Agent

Modbus, OPC-UA, DNP3

ControlSphere

Laravel, InfluxDB, Redis

HMI / Dashboard

Vue 3, WebSocket
TLS 1.3 Encryption Command Signing mTLS Authentication Real-time Monitoring
Capabilities

SCADA Features

Comprehensive industrial monitoring, control, and automation

Real-Time Monitoring

Live data from PLCs, RTUs, and sensors with sub-second updates via WebSocket connections.

Alarm Management

ISA-18.2 compliant with 4 severity levels, escalation workflows, shelving, and flood protection.

Secure Control

ARMED/SAFE operational modes, two-step confirmation, and supervisor approval workflows.

Historical Trends

InfluxDB time-series storage with trend analysis, dashboards, and report generation.

Multi-Protocol Support

Modbus TCP/RTU, OPC-UA, DNP3, and IEC 61850 protocol drivers for diverse device connectivity.

Digital Twin & HMI

Visual HMI builder with drag-drop components, live data binding, and digital twin simulation.

AI-Powered Insights

Anomaly detection, predictive maintenance alerts, and intelligent operational recommendations.

Fleet Management

Multi-site, multi-gateway management with centralized monitoring and configuration.