Security & reliability
Control you can defend
to your own engineers.
You're letting the internet start and stop a pump. That deserves straight answers. Below is exactly what the platform does today. No jargon, no aspirational claims.
01Security overviewArgus Automation is designed with industrial cybersecurity principles in mind. This page describes the controls that exist in the platform today. Nothing aspirational, nothing implied.
02AuthenticationSign-in is token-based and every link in the path is encrypted in transit (TLS to the platform, an encrypted mesh from the pad). There are no shared logins. Every session belongs to a named user. Login throttling, token expiry with refresh, and every rejected command recorded with user, time and IP.
03User rolesAccess is set per person. Accounts are view-only by default; control rights are granted deliberately, per user, by an administrator.
04Command confirmationEvery start, stop and setpoint change takes an explicit, deliberate confirmation before it is sent to the drive. There are no one-tap destructive actions.
05Audit trailRemote commands are recorded with the user, timestamp, requested value and device response. The history is available for review, an operator action is never anonymous.
06Edge-to-cloud communicationThe pad connects outbound over an encrypted link. It works over Starlink and behind carrier-grade NAT. The VPN router lives inside the field unit and is managed by Argus — nothing for you to configure on site.
07No inbound portsNothing on the pad opens an inbound port to the internet. No static IP, no port forwarding, nothing at the wellsite listening for an inbound connection.
08Local control during communication lossControl is local and authoritative: the field unit runs the pump on its own setpoints. If the link or the cloud drops, the pump keeps running exactly as set. The gap is shown on the chart as no-data — never filled in — and live readings resume when the link returns. Crew field-log entries made during an outage are queued on the phone and posted when it is back.
09Remote-control safeguardsSetpoint changes are validated against per-well limits before they reach the drive, and a site-wide safe lock forces the whole field read-only in one action.
10Data handlingTelemetry, alarms and reports are stored in the cloud and belong to the customer. Every reading is exportable to CSV. Raw telemetry is kept at 15-second resolution for 90 days. Alarm history, field-log entries and the command audit are retained for the term of the subscription and exported to you on request. Customer data is deleted on request.
11Deployment responsibilitiesThe site provides power and an internet uplink; Argus provides the pre-configured kit and the cloud. Standard enclosures are intended for suitable unclassified locations. Hazardous-area requirements are evaluated separately per site classification and local regulations.
12Security questionsAsk us anything about the security model before you deploy. A direct line to the engineer who built it.
Security questions before you deploy? Email info@argusautomation.tech, an engineer, not a ticket queue.
Put your field online.
First well live in days, not quarters.