The Portainer + Xiid joint architecture is built for industrial teams who need both secure connectivity and central management at scale. Deploy and manage containerized workloads at the OT edge with outbound-only secure connectivity and central operations visibility, without expanding inbound network exposure.
Industrial teams face a structural choice when modernizing OT operations: expose devices to manage them remotely, or keep them air-gapped and lose central visibility. The Portainer + Xiid joint architecture removes that tradeoff.
Portainer provides the operator control plane for containerized workloads across thousands of distributed sites. Xiid Terniion provides the secure connectivity layer underneath: outbound-only encrypted tunnels that make field devices non-addressable from the public internet while keeping them fully manageable from a central operations plane.
The result is an architecture where devices that need to stay protected stay protected, and the operations that need to be reached can be reached, through the same outbound tunnel that carries telemetry the other direction.
Field devices have no public IP presence. Inbound firewall ports stay closed. Devices cannot be enumerated or scanned by external actors.
Deploy, update, and monitor containerized OT applications across distributed sites from a single console. No site visits required for routine maintenance.
Triple-layer encryption stack (TLS 1.3 with ML-KEM-768, Kyber/Dilithium end-to-end, AES-256-GCM inner) suitable for environments with strict data-in-transit requirements.
Network access is constrained to the process level. A compromise at one device does not pivot into the broader operations network.
No SaaS dependency. No external infrastructure required. Suitable for regulated, air-gapped, and disconnected environments.
Built for the realities of industrial sites with cellular, satellite, or other unreliable network links. Operations continue during outages; updates queue and apply on reconnection.
Every OT gateway boots with a Terniion STLink agent that immediately closes all inbound firewall ports and initiates an outbound-only encrypted tunnel to the self-hosted operations plane. From any external network observer's perspective, the device does not exist.
Portainer's management plane pushes containerized workloads to the gateway through the established tunnel. Protocol adapters, monitoring applications, OT collectors, and configuration updates all deploy without anyone touching the device.
OT data flows outbound to the operator's chosen analytics, historian, or visibility layer. Management commands and updates flow back through the same tunnel. The gateway never opens an inbound port for either direction.
Learn how industrial teams can deploy and manage containerized workloads close to OT devices while keeping critical systems protected from inbound exposure. See a live demo of how Portainer simplifies distributed edge workload management and how Xiid's Terniion enables secure, outbound-only movement of telemetry and operational data from OT environments to approved destinations such as centralized databases, cloud services, peer OT systems, and enterprise applications.
Talk to our industrial team about your OT deployment.