[email protected]

Remote Maintenance Software for Machines & Plants

Self-hosted remote maintenance for machine fleets with outbound WireGuard tunnels, browser-based HMI access, role-based permissions and traceable audit logs. The architecture supports technical privacy and NIS2 requirements; overall compliance depends on the deployment and operator processes.

  • WireGuard
  • HMI in the browser
  • RBAC & Audit
  • Self-hosted
Reviews
Remote maintenance sessionExample
  • TunnelWireGuard outbound
  • HMIin the browser
  • Auditsession logged
Cloud Wolke HerausforderungServer NachhaltigkeitIT Beratung Service Consulting SoforthilfeTimo Wevelsiep Robin ZinsExperten für Innovation Migration AWSHetzner Hosting zuverlässig

Companies worldwide trust WZ-IT

  • Stadtwerke Brühl
  • DGHO e.V.
  • ABCO Water Systems
  • Golem.de
  • EVADXB
  • nextGYM
  • AInergy
  • ml&s
  • Odiseo Solutions
  • Annota
  • ARGE
  • SweetConnect GmbH
  • Aphy AG
  • CORGOS
  • Rekorder
  • SolidProof
  • Yonju
  • Keymate
  • Paritel
  • Mr. Clipart
  • Millenium
  • Negosh
  • Führerscheinmacher
  • Boese VA
Read client reviews

Why self-hosted?

Remote maintenance does not belong in a foreign vendor cloud

Commercial remote-access boxes like Ewon with Talk2M, IXON or Secomea work - but:

  • Every session runs through the vendor cloud

    Every session to your machine runs through the vendor’s cloud, on the vendor’s terms and with the vendor’s data flow.

  • Per-device fees

    Per-device fees scale with your machine fleet.

  • A third party in the tunnel

    For a critical-infrastructure plant a third party sits right inside the tunnel.

What the software delivers

Six building blocks of secure remote maintenance

Your own remote maintenance software hands control over tunnels, permissions and data residency back to you. It builds on proven open-source components - WireGuard, NetBird and RustDesk - and fits into your existing VPN and zero-trust structures.

Access
  • Secure remote access without open ports

    The device at the machine establishes an outbound WireGuard tunnel. There is no inbound firewall rule, no port forwarding and no exposed IP - from the outside there is simply no open door for an attacker. This is the same pattern NetBird and RustDesk rely on.

  • Browser HMI without a client install

    Technicians open the HMI in the browser - RDP, VNC and SSH run over HTML5 via Apache Guacamole. No VPN client on the laptop, no plugin, no software rollout. Works for classical VNC panels and modern web HMIs alike.

Control
  • RBAC and a traceable audit trail

    Role-based permissions per user, machine and site. Every session is logged - who, when, which plant, from which IP, optionally with session recording. This is the evidence base NIS2 and ISO 27001 audits demand.

Sovereignty
  • Self-hosted and sovereign

    Remote maintenance runs on your infrastructure or in an EU data center - no vendor cloud, no US SaaS in the tunnel to your plant. You keep data sovereignty, satisfy the GDPR and stay independent of a vendor’s pricing and roadmap decisions.

  • Ewon, IXON and Secomea alternative

    You are locked into Ewon Talk2M, IXON Cloud or the Secomea ecosystem and want out of the foreign cloud and the per-device fees. We build the equivalent, self-hosted solution and migrate your machine fleet site by site.

Compliance
  • NIS2 and IEC 62443 ready

    Segmented access, documented permissions, encrypted tunnels and complete logs - built for the requirements of the NIS2 directive and the industrial security standard IEC 62443 for secure remote access to OT networks.

These capabilities are already shipping in production industrial projects we built - we adapt them to your machine fleet instead of starting from zero each time.

Use cases

Who benefits

Anywhere machines sit distributed, must be serviced, and access has to be secure and traceable, your own remote maintenance software pays off.

  • Machine builders with service contracts

    OEMs maintaining shipped machines remotely - from a single plant to a worldwide fleet. Response times drop, the on-site field visit is avoided in most cases, and every access is cleanly documented.
  • PLC and HMI remote maintenance

    Remote access to controllers and operator panels - Siemens S7 (TIA Portal, S7-1200/1500), Beckhoff, B&R, Rockwell. Push a program, change parameters, diagnose faults, without the PLC ever being directly reachable from the internet.
  • Critical infrastructure and utilities

    Energy, water, wastewater, telecommunications. Here remote maintenance is NIS2 and critical-infrastructure relevant: documented access, complete audits and EU data residency are mandatory, not optional. We deploy on European hosting providers using open-source components.
  • Field service and remote diagnostics

    Service teams connect to the plant from headquarters, see live data and HMI, and resolve a large share of tickets remotely. If an on-site trip remains necessary, the technician arrives with a clear diagnosis and the right spare part.

AB-View · ABCO Water Systems

See the ABCO Water case study

Process

From pilot site to a serviced machine fleet

  1. 01

    Assessment & pilot

    We map controllers, HMIs, network and compliance duties and set up a pilot site with an outbound tunnel and browser access. You service the first machine securely from afar - typically within two to three weeks.

  2. 02

    Rollout & migration

    Rollout across the machine fleet, including migration from Ewon Talk2M, IXON or Secomea. Roles, permissions and audit trail are set up centrally; old and new solutions run in parallel until the handover is complete.

  3. 03

    Operations & support

    Optional managed-operations contract: monitoring, patch management, CVE response and onboarding of new sites. Or handover to your team with documented runbooks and handover tests.

Frequently Asked Questions

Answers to the most important questions

Deeper in the knowledge hub

Secure remote maintenance in detail

Background guides on the building blocks of this page - from access without a VPN client to NIS2 compliance.

Reviews & projects

Software projects with reliable outcomes

Proof for modernization, API extension, architecture, deployment and ongoing operations.

WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.
Steve KirchnerManaging Director, nextGYM GmbH
View project

International

Built in Germany's Ruhr Valley. Running worldwide.

WZ-IT designs, develops and operates infrastructure and software for clients in Germany and internationally. We deliver projects remotely and continue supporting them in ongoing operations after go-live.

Selected projects

Read client reviews

  • Modernize your legacy software
  • Ship your prototype to production
  • Design an open-source AI architecture
  • Plan a sovereign open-source stack
  • Secure your Proxmox & backup setup
  • Modernize your infrastructure - sovereign
  • Integrate a local AI solution
  • Cut cloud cost - up to −81%
  • Build a high-availability Proxmox cluster
  • Virtualize with Managed Proxmox
  • Get collaboration fully managed
  • Connect sites and clusters securely

Enquiry

Assess a remote maintenance solution

Describe sites, users, current access, and required operating and approval flows.

  • Straight with Timo and Robin - no sales team, no pitch
  • An honest take, including when we are not the right fit
  • Concrete next steps for infrastructure, software or AI

No risk: worst case, you leave with a clearer understanding of your project than before.

Timo and Robin, founders of WZ-IT

Where should we start?

Choose the appropriate starting point and briefly add the context.

We usually respond within one business day. Please do not send access credentials yet.

WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.
Jakob ÖschlbergerInno7 GmbH