Architecture

Architecture

TagLake sits between the systems that produce plant data and the applications that consume it. It is deliberately source-agnostic: Core knows about transports, never about specific DCS or historian products.

Enterprise and cloud applications
MES · ERP · BI · data platforms · your own tools
TagLake IQ
Advanced analytics and AI over contextualised, historised data
TagLake Core
One process. It reads every source above itself.
IngestionNormalisationUNSProcessingHistoryAPI
Transport and protocols
MQTT broker · Sparkplug B · OPC UA · SQL Server · HTTP/JSON
Plant systems
DCS · PLC · SCADA · Historians · Databases
Data moves upward. The two bands with a status are TagLake; everything above and below is what a plant already runs.
Position

Where TagLake sits

Below TagLake is everything that already exists and is not going to be replaced: the control systems, the historians, the databases that a plant has run for a decade and will run for another. Above it is everything that wants contextualised plant data and currently cannot get it.

TagLake's job is to be the one well-defined layer in between, and to be replaceable. Everything it holds is exportable and everything it speaks is a standard. A platform you cannot leave is a platform you should not enter.

Compatibility

Interfaces

What TagLake reads, what it serves, and how it reaches each one.

InterfaceHow TagLake reaches itStatus
OPC UA Connects to OPC UA servers. Browses their address space, reads values and subscribes to changes, over signed and encrypted connections. Available now
MQTT and Sparkplug B Connects to MQTT brokers over TLS, with client certificates. Reads Sparkplug B edge nodes, and plain topics carrying scalar or JSON payloads. Available now
Microsoft SQL Server Reads from SQL Server with a SQL login or Windows authentication. Read-only. Available now
REST / HTTP JSON Reads HTTP JSON endpoints with GET requests, using no authentication, basic, bearer or an API key, over TLS. Available now
DCS · PLC · SCADA Through whatever they already expose: an OPC UA server, MQTT or Sparkplug B on a broker, or a historian database TagLake can query. Available now
Time-series storage InfluxDB 2.x for history. Optional. Available now
MES · ERP · BI · cloud applications A REST and WebSocket API described by OpenAPI, protected by roles and API keys, plus CSV export from trends. Available now

Whichever source a value comes from, it arrives as the same record, so everything downstream treats it the same way.

Internals

How a value travels

One path for every value. A new source type adds a normaliser and changes nothing after step 03.

StepWhat happens
01 A source connection receives or fetches a value: an OPC UA subscription, an MQTT message, a SQL row or a REST response.
02 TagLake reads the value and its quality in the source’s own terms.
03 It becomes one record in TagLake’s data model. From here on, it no longer matters which source the value came from.
04 The value is placed in your Unified Namespace and stored as history.
05 Calculations that depend on it update.
06 Screens and applications that subscribed receive the new value, limited to what each user is allowed to see.
Deployment

Deployment

One process. Adding a product later does not add infrastructure to Core.

AspectDetail
Process model One process. No microservices, no orchestration, no message bus of its own.
Required infrastructure Whatever your sources need: a broker for MQTT, nothing extra for OPC UA, SQL Server or REST. InfluxDB is optional, for history.
Windows Self-contained x64 package; runs portably or as a Windows service.
Linux Docker image and Compose.
Network Binds to localhost by default. A token is required when it listens on a network interface.
Configuration Stored as JSON documents, exportable and importable.
Verification Tested automatically on Windows and Linux on every change. Each release publishes the SHA-256 of the Windows package.
Security

Security

Built against OWASP ASVS Level 2, with the role requirement enforced route by route in the test suite.

  • Accounts, roles and sessions

    Viewer, engineer and administrator, built against OWASP ASVS Level 2. Every API route requires a role, passwords are stored hashed and checked against known breaches, sign-in is throttled, and idle sessions end.

  • The audit log names a real user

    It records the authenticated account. Signing out, or an administrator disabling a user, ends their live connection at once.

  • HTTPS and HTTP hardening

    Your own certificate over HTTPS, with the usual browser protections. Core warns whenever it serves a network without TLS.

  • API keys for programs

    Per owner, hashed and expirable, so a script does not need a person’s password.

  • It reads your plant

    TagLake has no way to write a value or change a setpoint, so there is no switch to flip by mistake.

  • Dependencies checked for known vulnerabilities

    Checked automatically on every change.

Need to defend this choice internally?

We will give you the detail your OT and IT teams will ask for, including the parts that are not finished.