Architecture
TagLake sits between the systems that produce plant data and the applications that consume it. It is deliberately source-agnostic: Core knows about transports, never about specific DCS or historian products.
Where TagLake sits
Below TagLake is everything that already exists and is not going to be replaced: the control systems, the historians, the databases that a plant has run for a decade and will run for another. Above it is everything that wants contextualised plant data and currently cannot get it.
TagLake's job is to be the one well-defined layer in between, and to be replaceable. Everything it holds is exportable and everything it speaks is a standard. A platform you cannot leave is a platform you should not enter.
Interfaces
What TagLake reads, what it serves, and how it reaches each one.
| Interface | How TagLake reaches it | Status |
|---|---|---|
| OPC UA | Connects to OPC UA servers. Browses their address space, reads values and subscribes to changes, over signed and encrypted connections. | Available now |
| MQTT and Sparkplug B | Connects to MQTT brokers over TLS, with client certificates. Reads Sparkplug B edge nodes, and plain topics carrying scalar or JSON payloads. | Available now |
| Microsoft SQL Server | Reads from SQL Server with a SQL login or Windows authentication. Read-only. | Available now |
| REST / HTTP JSON | Reads HTTP JSON endpoints with GET requests, using no authentication, basic, bearer or an API key, over TLS. | Available now |
| DCS · PLC · SCADA | Through whatever they already expose: an OPC UA server, MQTT or Sparkplug B on a broker, or a historian database TagLake can query. | Available now |
| Time-series storage | InfluxDB 2.x for history. Optional. | Available now |
| MES · ERP · BI · cloud applications | A REST and WebSocket API described by OpenAPI, protected by roles and API keys, plus CSV export from trends. | Available now |
Whichever source a value comes from, it arrives as the same record, so everything downstream treats it the same way.
How a value travels
One path for every value. A new source type adds a normaliser and changes nothing after step 03.
| Step | What happens |
|---|---|
| 01 | A source connection receives or fetches a value: an OPC UA subscription, an MQTT message, a SQL row or a REST response. |
| 02 | TagLake reads the value and its quality in the source’s own terms. |
| 03 | It becomes one record in TagLake’s data model. From here on, it no longer matters which source the value came from. |
| 04 | The value is placed in your Unified Namespace and stored as history. |
| 05 | Calculations that depend on it update. |
| 06 | Screens and applications that subscribed receive the new value, limited to what each user is allowed to see. |
Deployment
One process. Adding a product later does not add infrastructure to Core.
| Aspect | Detail |
|---|---|
| Process model | One process. No microservices, no orchestration, no message bus of its own. |
| Required infrastructure | Whatever your sources need: a broker for MQTT, nothing extra for OPC UA, SQL Server or REST. InfluxDB is optional, for history. |
| Windows | Self-contained x64 package; runs portably or as a Windows service. |
| Linux | Docker image and Compose. |
| Network | Binds to localhost by default. A token is required when it listens on a network interface. |
| Configuration | Stored as JSON documents, exportable and importable. |
| Verification | Tested automatically on Windows and Linux on every change. Each release publishes the SHA-256 of the Windows package. |
Security
Built against OWASP ASVS Level 2, with the role requirement enforced route by route in the test suite.
-
Accounts, roles and sessions
Viewer, engineer and administrator, built against OWASP ASVS Level 2. Every API route requires a role, passwords are stored hashed and checked against known breaches, sign-in is throttled, and idle sessions end.
-
The audit log names a real user
It records the authenticated account. Signing out, or an administrator disabling a user, ends their live connection at once.
-
HTTPS and HTTP hardening
Your own certificate over HTTPS, with the usual browser protections. Core warns whenever it serves a network without TLS.
-
API keys for programs
Per owner, hashed and expirable, so a script does not need a person’s password.
-
It reads your plant
TagLake has no way to write a value or change a setpoint, so there is no switch to flip by mistake.
-
Dependencies checked for known vulnerabilities
Checked automatically on every change.
Need to defend this choice internally?
We will give you the detail your OT and IT teams will ask for, including the parts that are not finished.