NEXO LABS CLOUD

The hub connects to us.

The Internet does not enter the plant.

Remotely you program and use Nexo Hub as you do on site. The plant, however, is not published on the Internet: the hub is the one that comes forward to the cloud.

THE CONNECTION

Nothing to open
on the plant.

To work from afar you do not open ports on the router, publish an address, or stand up a VPN. From the field network the hub opens a channel to the Nexo Labs servers on its own.

From the outside the plant does not offer a service to query. Anyone probing the field network does not find the hub listening on the Internet.

  • No ports to open on the router
  • No public address, no VPN
  • The hub is the one that opens the channel, outbound
  • From the outside the plant is not listening
HOW IT IS BUILT

Two channels. One verdict: the hub’s.

App and device do not share the same wire. The cloud forwards, the plant decides, data stays where it was born.

Two channels

App and browser speak HTTPS only with the portal. They do not hold the device’s transport credentials and they do not open a direct channel to the hub. The hub, on its own, keeps an encrypted channel open outbound, with mutual authentication.

Programming

Remotely you program the hub from the same screens you use on site. The cloud does not rewrite the interface: it forwards requests to the hub, encrypted, and stops there. The rest of the LAN stays off the path.

Identity

Each Nexo Hub receives its own certificate, issued by Nexo Labs. It is not the same key for the whole fleet. Plants share the servers, not the data: one hub does not see another’s state.

Authority

When you sign in remotely, the cloud does not decide whether the password is right. It forwards it to the hub and waits for the verdict. Who may see or command is always decided by the device.

Access

Sign-in attempts are limited. After a run of failures access closes for a period, on the cloud and on the hub. Sessions expire if you do not use them.

Video

Camera passwords do not leave the hub. The hub uses them on site and bridges the stream; the cloud does not store them and does not pass them to the app. Live from afar goes through a relay; the path to the player can run encrypted.

Device

On the hub the firmware is encrypted in flash, with a different key for each board. Identity stays on the device: it is not a file you copy onto another board to present yourself to the cloud in its place.

Without the cloud

If-this-then-that logic runs on the hub. If the cloud is unreachable the plant keeps going: status, rules and on-site commands stay there.

HOW YOU USE IT

On site or from afar,
the same screens.

01

App and browser

They speak only with the portal, over HTTPS. They do not open a channel to the plant and they do not hold the device’s transport credentials.

02

The cloud forwards

It does not rewrite the interface and it does not decide access. It carries requests to the hub and returns the reply.

03

The hub decides

It opens the channel on its own, checks passwords and permissions, keeps video and logic in the field. If the cloud is missing, the plant keeps running.

IN THE FIELD

The plant does not live on the server.

The cloud is the channel for programming and using from afar, not the place where the plant lives. On site, installation practice still matters: password, users, field network.

NEXO HUB

The cloud is the channel. The hub is the product.

Same device, same application, same logic. Remotely you only change the path, not the way of working.

See Nexo Hub
NEXT STEPS

Bring remote access
to your plant.

If you are evaluating Nexo Hub and want to use it from afar as well, we start from how the field network is built.

We reply in person. If it makes sense, we look together at how the Nexo Labs cloud fits into your plant.

See Nexo Hub

Prefer a quick reply? Message us on WhatsApp

Your data is safe. We always reply personally.

By submitting this form you confirm that you have read and accepted our Privacy Policy.