Secure remote access without open ports
The device at the machine establishes an outbound WireGuard tunnel. There is no inbound firewall rule, no port forwarding and no exposed IP - from the outside there is simply no open door for an attacker. This is the same pattern NetBird and RustDesk rely on.
Browser HMI without a client install
Technicians open the HMI in the browser - RDP, VNC and SSH run over HTML5 via Apache Guacamole. No VPN client on the laptop, no plugin, no software rollout. Works for classical VNC panels and modern web HMIs alike.
Remote Maintenance Software for Machines & Plants
Self-hosted remote maintenance for machine fleets with outbound WireGuard tunnels, browser-based HMI access, role-based permissions and traceable audit logs. The architecture supports technical privacy and NIS2 requirements; overall compliance depends on the deployment and operator processes.
- WireGuard
- HMI in the browser
- RBAC & Audit
- Self-hosted
- TunnelWireGuard outbound
- HMIin the browser
- Auditsession logged
Why self-hosted?
Remote maintenance does not belong in a foreign vendor cloud
Commercial remote-access boxes like Ewon with Talk2M, IXON or Secomea work - but:
Every session runs through the vendor cloud
Every session to your machine runs through the vendor’s cloud, on the vendor’s terms and with the vendor’s data flow.
Per-device fees
Per-device fees scale with your machine fleet.
A third party in the tunnel
For a critical-infrastructure plant a third party sits right inside the tunnel.
What the software delivers
Six building blocks of secure remote maintenance
Your own remote maintenance software hands control over tunnels, permissions and data residency back to you. It builds on proven open-source components - WireGuard, NetBird and RustDesk - and fits into your existing VPN and zero-trust structures.
RBAC and a traceable audit trail
Role-based permissions per user, machine and site. Every session is logged - who, when, which plant, from which IP, optionally with session recording. This is the evidence base NIS2 and ISO 27001 audits demand.
Self-hosted and sovereign
Remote maintenance runs on your infrastructure or in an EU data center - no vendor cloud, no US SaaS in the tunnel to your plant. You keep data sovereignty, satisfy the GDPR and stay independent of a vendor’s pricing and roadmap decisions.
Ewon, IXON and Secomea alternative
You are locked into Ewon Talk2M, IXON Cloud or the Secomea ecosystem and want out of the foreign cloud and the per-device fees. We build the equivalent, self-hosted solution and migrate your machine fleet site by site.
NIS2 and IEC 62443 ready
Segmented access, documented permissions, encrypted tunnels and complete logs - built for the requirements of the NIS2 directive and the industrial security standard IEC 62443 for secure remote access to OT networks.
These capabilities are already shipping in production industrial projects we built - we adapt them to your machine fleet instead of starting from zero each time.
Use cases
Who benefits
Anywhere machines sit distributed, must be serviced, and access has to be secure and traceable, your own remote maintenance software pays off.
Machine builders with service contracts
OEMs maintaining shipped machines remotely - from a single plant to a worldwide fleet. Response times drop, the on-site field visit is avoided in most cases, and every access is cleanly documented.PLC and HMI remote maintenance
Remote access to controllers and operator panels - Siemens S7 (TIA Portal, S7-1200/1500), Beckhoff, B&R, Rockwell. Push a program, change parameters, diagnose faults, without the PLC ever being directly reachable from the internet.Critical infrastructure and utilities
Energy, water, wastewater, telecommunications. Here remote maintenance is NIS2 and critical-infrastructure relevant: documented access, complete audits and EU data residency are mandatory, not optional. We deploy on European hosting providers using open-source components.Field service and remote diagnostics
Service teams connect to the plant from headquarters, see live data and HMI, and resolve a large share of tickets remotely. If an on-site trip remains necessary, the technician arrives with a clear diagnosis and the right spare part.
AB-View · ABCO Water Systems
See the ABCO Water case studyProcess
From pilot site to a serviced machine fleet
- 01
Assessment & pilot
We map controllers, HMIs, network and compliance duties and set up a pilot site with an outbound tunnel and browser access. You service the first machine securely from afar - typically within two to three weeks.
- 02
Rollout & migration
Rollout across the machine fleet, including migration from Ewon Talk2M, IXON or Secomea. Roles, permissions and audit trail are set up centrally; old and new solutions run in parallel until the handover is complete.
- 03
Operations & support
Optional managed-operations contract: monitoring, patch management, CVE response and onboarding of new sites. Or handover to your team with documented runbooks and handover tests.
Scoping Sprint
Define scope and price before development
Requirements, target architecture and effort are clarified. The result is a fixed-price offer for implementation.
Looking for something else?
Remote Management Platforms
You want to build a multi-tenant platform for hundreds of end customers, each accessing their own plants? Then the platform build is the right entry point.
Learn more →IoT & edge software
You need the device, gateway and edge software that captures and pre-processes data from the machine? That is IoT software development.
Learn more →Frequently Asked Questions
Answers to the most important questions
- This page covers remote maintenance software as the tooling you use to securely service your own machines - from a single plant to a fleet. A remote management platform, in contrast, is a multi-tenant system you build for hundreds of end customers who each access their own plants. Put differently: remote maintenance software is the access tooling, the platform is the multi-tenant product around it.
- Yes. We build an equivalent, self-hosted solution to Ewon Talk2M, IXON Cloud and Secomea - without a foreign vendor cloud and without per-device fees. Existing remote-access boxes can in most cases be reused or replaced step by step; we migrate your machine fleet site by site, running old and new solutions in parallel during the transition.
- The device at the machine establishes an outbound WireGuard tunnel to your central server. Because the connection is initiated from the inside out, no inbound firewall rule, port forwarding or public IP is required for the plant endpoint. Direct inbound access is avoided; administrative access is routed through the authenticated tunnel and browser gateway.
- It is designed to support relevant technical requirements. Segmented access, role-based permissions, encrypted tunnels and exportable audit logs are building blocks for NIS2 and IEC 62443. Whether the overall deployment meets the applicable requirements depends on architecture, processes and the operator's risk assessment.
- By default in a selected European data centre, or on request on your own Proxmox or bare-metal infrastructure. The agreed architecture documents where session data, logs and backups are processed and which subprocessors are involved.
- We start with an assessment and a pilot site that proves secure remote access on a first machine. On that basis, after a scoping sprint with a defined scope you receive a binding fixed-price offer for the rollout - predictable, instead of usage-based per-device licenses. We agree the concrete scope individually with you.
Deeper in the knowledge hub
Secure remote maintenance in detail
Background guides on the building blocks of this page - from access without a VPN client to NIS2 compliance.
Guides
- Remote maintenance without a VPN clientHow technicians reach the HMI in the browser - without installing a client on the device.
- PLC remote access without open portsThe outbound tunnel in detail: service controllers without exposing the PLC to the internet.
- NIS2 requirements for remote accessWhat NIS2 and IEC 62443 require for the remote maintenance of OT networks.
- Secure remote maintenance of machines & plantsArchitecture, risks and best practices for the remote maintenance of industrial plants.
Software development
Related Tutorials & Guides
- Self-Host RustDesk 2026: the Sovereign TeamViewer Alternative Done RightRustDesk has made unflattering headlines repeatedly in the first half of 2026: a botnet abusing the public server, a forced login on the demo server,...
- NIS2 & Remote Maintenance: What the BSIG Now Requires (as of October 2026)NIS2 is no longer an announcement, it is law in force: Germany's NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) has been in force since 6...
- Ewon Cosy 141 Loses Talk2M by End of 2026: Build Your Own Remote-Maintenance PlatformAnyone who services machines and plants remotely knows the little boxes in the control cabinet: Ewon Cosy from HMS Networks, plus the Talk2M cloud that...
- FortiGate SSL-VPN Risk in 2026: Why Internet-Exposed VPN Appliances Became a Liability and ZTNA Is the AnswerOn 26 February 2026, the US agency CISA issued a Binding Operational Directive ordering an actively exploited FortiOS zero-day to be patched or disabled within...
- NetBird vs. Twingate Comparison: Self-Hosted or Cloud ZTNA?NetBird and Twingate are both modern Zero-Trust Network Access (ZTNA) solutions aiming to replace traditional VPNs. But while Twingate relies on a proprietary cloud solution...
Reviews & projects
Software projects with reliable outcomes
Proof for modernization, API extension, architecture, deployment and ongoing operations.
WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.
Steve KirchnerManaging Director, nextGYM GmbH
International
Built in Germany's Ruhr Valley. Running worldwide.
WZ-IT designs, develops and operates infrastructure and software for clients in Germany and internationally. We deliver projects remotely and continue supporting them in ongoing operations after go-live.
Selected projects
- LiveRemote access platform for distributed water treatment plantsABCO Water Systems · Australia · Secure Access & OT
- 81%AWS migration with substantially lower operating costsEVA Real Estate · UAE · Cloud exit & infrastructure
- 98%Provision new sites in minutes instead of hoursnextGYM GmbH · Germany · Automation & IoT

Read client reviews
- Modernize your legacy software
- Ship your prototype to production
- Design an open-source AI architecture
- Plan a sovereign open-source stack
- Secure your Proxmox & backup setup
- Modernize your infrastructure - sovereign
- Integrate a local AI solution
- Cut cloud cost - up to −81%
- Build a high-availability Proxmox cluster
- Virtualize with Managed Proxmox
- Get collaboration fully managed
- Connect sites and clusters securely
Enquiry
Assess a remote maintenance solution
Describe sites, users, current access, and required operating and approval flows.
- Straight with Timo and Robin - no sales team, no pitch
- An honest take, including when we are not the right fit
- Concrete next steps for infrastructure, software or AI
No risk: worst case, you leave with a clearer understanding of your project than before.


WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.

















