Wiresheet.ai

Architecture & security

The browser never touches the station.

Every read and every write goes through this server, which holds the station's own credentials. The browser has no route to a JACE and no account on one — so what a person can do is what this server will do on their behalf, and that is a far shorter list than a Workbench session.

Your network

reached by the server

JACE / Supervisor

wiresheetDriver-rt.jar

Field devices

BACnet · Modbus · Lon

server → station
HTTP(S) · station account

Wiresheet.ai

holds the credentials

Server

the only thing that logs in

Agent runtime

proposes · never auto-applies

AuditHistory

read from the station

Security properties

The browser holds no credentials

It has no route to a JACE and no account on one. Every read and write goes through the server, which holds the station's own login — so a tab left open on a train is not a way into the station.

Per-station credentials, sealed

Each station carries its own address and account, encrypted with AES-256-GCM before it is stored. Change one and only that station is affected.

Read-only by default

Commissioning is an explicit per-session mode gated by role. Without it, the API refuses every write, including the agent's.

Nothing applied silently

The agent produces a diff against real ORDs. A human presses apply. There is no autonomous-write mode to turn on.

The station's own audit trail

Niagara records every change in the station's AuditHistory. The workspace reads that rather than keeping a second log beside it, so an agent edit and a hand edit appear the same way, in the record your auditor already trusts.

Histories stay where they are

Trends are read on demand from the station that recorded them. Nothing bulk-copies a history out of the JACE.

What we hold

The credentials for the stations you pair, sealed with AES-256-GCM, plus the component structure, slot metadata and point values read back from them. A browser is never given any of the credentials.

What we log

Nothing you cannot already see. Niagara writes every change to the station's own AuditHistory, and the workspace reads that rather than keeping a second record beside it — so the log an auditor trusts is the one the station kept.

What we never do

We do not bulk-copy histories, and we do not change control logic without a person pressing apply. The agent has no autonomous-write mode to switch on — its edits go through the same gated path a hand edit does.

Compatibility matrix

Niagara versions
4.10 · 4.11 · 4.12 · 4.13 · 4.14 · 4.15
Platforms
JACE-8000 · JACE-9000 · Niagara Supervisor · Workbench
NiagaraAX
Reachable through an N4 bridge station
Field protocols
BACnet/IP · BACnet MS/TP · Modbus TCP/RTU · LonWorks · oBIX
Station module
wiresheetDriver-rt.jar · standard station module
Station link
HTTP(S) from the server · the station's own account

Let it build your first sheet.

Tell us which station you want to start with and we'll set it up with you. Pairing takes about ten minutes once the account exists.

Niagara 4.10 → 4.15 · credentials server-side · writes human-gated