---
title: "GridBit Cloud: device management for industrial gateways"
description: "Cloud management for fleets of industrial gateways: self-activation, over-the-air updates, alarms and remote access, with no access to your production data."
url: "https://www.gridbit.tech/solutions/gridbit-cloud"
language: "en"
translation: "https://www.gridbit.tech/bg/solutions/gridbit-cloud"
---

# Manage thousands of industrial gateways as one device

Enrolment at first power-up, configuration, applications, over-the-air updates, alarms and remote access in one cloud console. No servers of your own, and no access to your production data.

- Works with the GWU-5 gateway today
- Managed service, nothing to install
- Hosted in the EU

[Request a demo](https://www.gridbit.tech/contact?product=GridBit%20Cloud)

- **devices: the scale the architecture is designed for**: 1 000 000+
- **bytes of production data pass through the platform**: 0
- **fully separate channels: management and data**: 2
- **to switch to a standby broker when a node drops\***: < 4 s

\* Laboratory measurement on a two-node cluster.

Illustration: a fleet of 10 000 devices, one dot each.

The problem

## Who will look after 10 000 boxes in the field for the next 10 years?

Connecting the equipment is the easy part. The hard part starts after the installation.

01 / 07

### Every update is a site visit

A technician, a car, a laptop, a cable. With thousands of devices it does not happen, and the devices stay on old software for years.

02 / 07

### You do not know what is in the field

Which device is alive, which version it runs, which one has been silent for a week.

03 / 07

### Updating is a gamble

Everything at once, and you hope. One bad version stops the whole fleet.

04 / 07

### Commands get lost

A device that was offline at that moment never learns that it had to change.

05 / 07

### The data passes through a foreign platform

That means fees by volume, data processing agreements and questions from the security department.

06 / 07

### Remote access is a hole

Open ports, a VPN to every site, shared passwords and no trace of who did what.

07 / 07

### Regulators already ask

From December 2027 a connected product cannot be offered in the EU without secure updates through its whole life cycle (Cyber Resilience Act). NIS2 requires operators of important infrastructure to prove risk management down to the field device.

The answer

### Your fleet. Your data. Our care for the devices.

### Self-activation

Scan the code from the box. The device connects by itself.

### Desired state

Describe what must be there. The fleet brings itself in line.

### Safe updates

In stages, with automatic stop and rollback.

### The data is yours

Production data does not pass through the platform.

### Remote access

No open ports. With permission, recording and audit.

### Audit

Every action, ours included, in an immutable log.

### Scale

From ten devices to a million, in one console.

Two channels

## We manage the devices, not the data

The gateway keeps two fully separate secured connections to two different servers. The first goes to GridBit Cloud and carries management only. The second goes straight to your broker, cloud or SCADA system and carries your production data. This is not a policy or a promise in a contract. It is how the system is made: your data physically does not pass through our infrastructure.

GridBit Cloud

Health, versions, configuration, applications, alarms

Platform unavailable

GWU-5 on site

Two secured connections

Your broker, cloud or SCADA

Measurements and process data

The management channel: what the device is and how it should run. The data channel: straight to your system, never through ours. If the platform is down, your data keeps flowing. Management catches up at the next connection.

0 bytes of production data through the platform

- The data stays in your infrastructure, under your control.
- No fees by data volume, because the data does not pass through us.
- A simpler talk with the security department and less personal data in processing.
- A platform outage does not stop the data flow to your system.

GWU-5 gateway

How it works

## From the box to the end of its life, without a technician on site

A gateway goes through four states in GridBit Cloud. None of them needs keys, passwords or server addresses typed in the field.

01 Added

### Added to your organisation

Scan the QR code from the box with a phone, or type the serial number and the claim code. For a whole batch, upload a CSV file. The device joins your organisation and nobody else can add it after that.

Waiting for first connection

02 Activated

### Self-activation

At first power-up the device creates its own private key, requests a certificate and connects to the platform over a mutually authenticated secure channel. The private key never leaves the device. The console shows whether each device waits for its first connection, is connected or has a problem, and why.

Connected, certificate issued

03 Managed

### Managed

You set the configuration, the applications and the firmware version. You watch its health, receive alarms and open a remote console when you need one.

Online, firmware 2.4.1, in sync

04 End of life

### Transferred, replaced or retired

You sell the site, replace a faulty unit or take it out of service. The platform moves or clears everything, revokes the certificate and keeps the history.

Retired, certificate revoked

Desired state

## The fleet repairs itself

In most systems you "send" a configuration or an application. If the device was offline at that moment, the change is lost and nobody notices. In GridBit Cloud you describe how the device, the site or the whole fleet should look. The device compares that with its real state and brings itself in line: after hours or days without a link, after a change of the SD card, after reprogramming.

- No change is lost because of a broken link.
- No manual retries and no lists of "which ones did not update".
- A new unit on the site automatically gets everything that is set for the site.

GWU5-2607-000187 Online
Application Desired Actual State
modbus-reader 1.4.2 1.4.2 In sync
mqtt-bridge 2.1.0 2.1.0 In sync
lte-watchdog 1.0.1 1.0.1 In sync
pump-logic

Desired and actual match. You change the desired state while the device is offline. The console shows the difference. The device reconnects, compares and installs what is missing by itself. In sync again. Nobody repeated a command.

Illustration with sample applications.

Updates without risk

## A bad version reaches a few devices, not the fleet

Updates go out in stages, for example 10 %, 50 % and 100 % of the fleet. After each stage the platform checks the health of the updated devices. If the errors pass the threshold, the rollout stops by itself and the affected devices return to the previous version, with no human involved. Before a firmware update the platform checks which installed applications would become incompatible and refuses a silent update that would stop an application.

- Previous version**100**
- New version**0**
- Error after the update**0**
- Returned to the previous version**0**

Stage 1: a tenth of the fleet gets the new version. The health check passes. Stage 2 begins. Errors pass the threshold. The rollout stops by itself. The affected devices return to the previous version. The rest of the fleet never received it.

Illustration of one rollout over a fleet of 100 devices.

- One bad version affects a few devices, not the whole fleet.
- Night or weekend updates with nobody in front of a screen.
- A provable history: what was updated, when and with what result.

The console

## One place for the whole fleet

### The whole fleet as one tree

Organisation, regions, sites and devices in one table. Every row shows the state, the link, the firmware and when the device was last seen. Ready views such as "Offline for more than 24 hours" and "Old firmware" sit above it.

### From added to active

The activation queue shows where every added gateway stands: waiting for you with a check list, holding its new certificate, or active. A device that failed says why.

### Desired against actual, for one device

Six packages are in sync, one is missing and downloads right now, one still runs the older version. The badge counts what is behind, and the list under it shows what the device just reported.

### The private registry of the organisation

Your own packages with their builds, from a draft through the published version to a withdrawn one, each with its kernel compatibility, size and checksum.

### Parameters, key by key

Every key says where its value comes from: set here, inherited from the group, or the default of the schema. One click returns it to the inherited value, and every key keeps its history.

### A terminal in the browser

The session starts only after a stated reason, it is recorded from the first key, and it closes by itself after three minutes without activity. The site needs no open ports.

### Who may touch this site

Roles come down the tree, from the organisation and from the region, and a person can get a role on one site only. The list says where each right comes from.

Screens from the console with sample data. The console is in Bulgarian today, an English version is planned.

Features

## What the platform does today, and what comes next

Every function carries its status, so that this page does not promise something that is not there.

78 functions available today

21 coming soon

Adding a new device needs no technical training.

- Available QR code from the box Scan it with a phone or type the serial number and the claim code. The code works once and wrong attempts are limited.
- Available Batch import with CSV Hundreds of devices at once, with a report row by row and a file of the failed ones.
- Available First-steps assistant Leads a new client from the first added device to a working unit: network, configuration, first application.
- Available Activation queue For every added device: waiting for first connection, connected, or error with the reason.
- Available Self-activation at first power-up The device creates a key, gets a certificate and becomes active by itself.

- Available Fleet list with filters By state, site, group, hardware revision and firmware version.
- Available Ready views For example "Offline for more than 24 hours" and "Old firmware".
- Available Fleet health at a glance Total, online, offline, with an alarm.
- Available Device detail Identity, state, versions, last connection, technical telemetry, history of commands and events.
- Available Online and offline status within seconds
- Available Live messages from the device You see what the device sends to the platform at the moment it arrives.
- Available A team in sync When a colleague changes something, your screen updates by itself.
- Soon Own names and tags for devices

Technical telemetry is about the health of the device itself: uptime, memory, versions, connectivity. It is not your production data.

- Available Sub-organisations Companies, cities and sites in a tree of any depth. Every device is in exactly one site.
- Available Device groups Independent of the structure: by production line, type of facility or any attribute.
- Available Inheritance downwards Configuration, applications and rights set for a company apply to all its sites, unless a site changes them.
- Available The most specific wins A device setting beats the group, the group beats the site, the site beats the organisation. Conflicts are shown, not settled silently.
- Available Switching between organisations For people who work for several.

- Available Configuration as desired state It is applied, stored and survives a restart. A device that was offline gets it at the next connection.
- Available Four levels Organisation, site, group and device.
- Available Form for the device parameters WiFi, Bluetooth LE, Ethernet, LTE modem, telemetry, logs, NTP, power.
- Available Validation before sending An invalid configuration is refused in the console before it reaches a device.
- Available Versions and rollback Every change is a version with an author and a date. One action returns to a previous one.
- Available Protected secrets Passwords and tokens are stored encrypted and are never shown back in the console.

GridBit applications are WebAssembly packages. They run in an isolated environment on the device and reach only what they are allowed to.

- Available Declarative applications You set which applications and versions an organisation, site, group or device must have. The device installs, updates and removes by itself.
- Available Desired against actual Missing, different version, not wanted, in sync.
- Available Locks and application parameters per level
- Available Protection from switching itself off The management agent and the system applications cannot be removed by mistake, even with a wrong list. The device refuses.
- Available Private registry of the organisation You upload your own applications from the console. Before the upload you see what the device will get: name, version, permissions, memory, state of the signature.
- Available Versions Draft, published, deprecated. Groups can be pinned to one version.
- Available Catalogue of system packages from GridBit The mandatory ones arrive automatically. The optional ones are switched on by the owner or an administrator, per organisation, site or device.
- Available Compatibility with the kernel Every application declares the firmware versions it works with.
- Soon Dependencies between packages An application that needs a library or a driver gets them automatically.

- Available Kernel releases Every release is checked at upload (size, order of versions) and needs explicit approval before it goes out.
- Available An image encrypted for each device
- Available Resumable download A broken link does not restart the download.
- Available Hardware revision check An image for another revision does not reach the device.
- Available Compatibility check with the applications An update that would stop an installed application is refused, unless you accept it knowingly.
- Available Result report Successful, failed and rolled-back devices, with the reason.
- Soon Safe update through recovery A separate recovery partition writes the new kernel. If something goes wrong the device stays in recovery and reports, instead of turning into a brick.
- Soon Mandatory secure boot signature check at upload
- Soon Stable and beta channels
- Soon Your maintenance window You set when devices may restart, per organisation, site or device. Outside the window there is no restart.
- Soon Postponing with a ceiling You can postpone an update. Security releases keep a hard deadline, so that the fleet does not stay unprotected.

- Available Stages For example 10 %, 50 %, 100 %, with a pause between them.
- Available Choice of scope Organisation, region, hardware revision, firmware version or an explicit list of devices.
- Available Automatic stop on errors Health is checked after every stage.
- Available Automatic rollback When the rollout stops, the affected devices return to the previous version. If the return fails, you get an alarm.
- Available Resilience The rollout continues from where it stopped, even after a restart of the service.
- Available Control from the console Pause, resume, abort.
- Available Planned start In a set time window.
- Soon The time zone of each device is taken into account

- Available Commands to a device Restart, diagnostics, start and stop of an application, list of processes.
- Available A confirmation for every command You see whether it was executed, refused or expired without an answer. Nothing disappears silently.
- Available History of commands What, by whom, when and with what result.
- Available Group commands To a group or a filter, with progress per device, a summary and a retry for the failed ones only.

- Available A terminal to the device in the browser
- Available No open ports The device dials out by itself, so access works behind CGNAT, a corporate firewall and a mobile LTE operator.
- Available Administrators only Users with limited rights cannot open a session. Every session needs a reason.
- Available Switch-off per organisation or site For critical sites remote access can be forbidden completely. The server enforces the ban, it does not just hide a button.
- Available Access for GridBit only with your permission A request, your approval for up to 7 days, automatic expiry and an end at any time. Everything is in the audit log.
- Available Session recording The input and output of every session are recorded and kept for 90 days.
- Soon Viewing and downloading the recordings from the console

- Available Alarm rules By metric, condition, threshold and time window, with a severity, for the whole organisation or one device. The alarm closes by itself when the value returns to normal.
- Available A webhook for every rule With retries on failure.
- Available Slack and Microsoft Teams Through a webhook, with a test message.
- Soon Slack and Teams connected in a few clicks
- Available E-mail notifications A grouped digest of the alarms, rollout results, invitations. Every user chooses what to receive.
- Available Muting For a period, a device or a group during planned work.

- Available Transfer of ownership The configuration, applications and data of the previous owner are cleared. Both sides see a trace in the audit.
- Available Replacement of a faulty device (RMA) The new unit inherits the site and the applications of the old one. The old one is revoked.
- Available Retirement The certificate is revoked, the history stays readable.
- Available Lost or stolen The device is refused by the network and, if you choose, wipes itself at the next connection. If it is found, the state comes back.
- Available Revocation A revoked device cannot connect.
- Soon Data retention policy per organisation

- Available Self-service registration With confirmation by e-mail. The organisation is created automatically.
- Available Invitations by e-mail with a role The invitation expires. Nobody can invite someone with more rights than their own.
- Available Roles Owner, administrator, operator, viewer. The viewer cannot change anything.
- Available Rights scoped to a sub-organisation Inherited down the tree.
- Soon Rights scoped to a group
- Available Two-factor authentication (TOTP) With backup codes. The owner can make it mandatory for the whole organisation.
- Available Sign-in with a corporate account (OpenID Connect) For example Microsoft Entra ID, Google or Okta, with automatic creation of the user and a role from the group in the identity provider.
- Soon SAML
- Available Sign-in protection Progressive delay and a temporary block on guessing attempts.
- Available Sign-out from all devices With one action.

- Available Full audit log Every action that changes something or reads sensitive data: who, when, from which IP address, on what, with what result. Refused attempts are recorded too.
- Available Immutable The records cannot be edited or deleted, even by the application. The database enforces it.
- Available The actions of GridBit are visible to you
- Available Filtering and CSV export For the owner of the organisation.
- Soon CSV export for administrators
- Available Versioned acceptance of the terms The console records which version of the terms and of the data processing agreement was accepted, by whom and when. A new version asks for a new acceptance.
- Available Deletion of the organisation (GDPR) With a grace period.

One chain of trust for everything that runs on the device: applications, drivers, kernel, recovery.

- Soon Own signing key of the organisation Registered from the console. The client signs its own unprivileged applications.
- Soon Privileged code signed by GridBit only Drivers, system applications and the kernel, with explicit human approval that is checked outside the platform.
- Soon GridBit keys in a hardware security module In a data centre in the EU.
- Soon Key revocation for the whole organisation with one signature A revoked key stays revoked on the device. Restoring trust needs the approval of two different people.
- Soon Offline policy The organisation decides how long devices run its applications without a link to the platform. The firmware guarantees at least 72 hours, so even a wrong setting does not stop a site over a weekend.
- Soon Command line tool With the same rights and the same audit as the console.
- Soon Service accounts with API tokens Scoped to an organisation, with rotation and revocation.

Benefits by role

## What each person gets

01

### Head of operations

- One screen for the whole fleet: how many devices are online, which are not, which version they run.
- Devices arranged by your structure: companies, cities, sites, groups.
- Updates of the whole fleet in hours, without site visits.
- Alarms by e-mail, Slack or Teams before the client calls.

02

### Field technician

- Mounts the device, scans the QR code from the box with a phone, and that is all.
- Types no keys, passwords or server addresses.
- When there is a problem, a remote console to the device, without a VPN and without open ports.

03

### IT and OT security

- A device identity born in the chip and mutually authenticated connections.
- Roles, scope down to a site, two-factor authentication that can be mandatory for the organisation, sign-in with a corporate account.
- An immutable audit log that also shows every action of the vendor.
- Remote access for administrators only, with a reason and a recording, and a switch to turn it off for critical sites.
- Production data does not pass through the platform.

04

### Developer and integrator

- Own applications in Rust, C or Go, compiled to WebAssembly and run in an isolated environment with explicit permissions.
- A private registry for the applications of the organisation, without waiting for approval from GridBit.
- Versions, pinning to a version and application parameters per site.
- A command line tool with the same rights and audit as the console (soon).

05

### Finance and management

- No spending on your own infrastructure and server administration.
- No fees by data volume.
- Fewer site visits.
- Support for what the Cyber Resilience Act and NIS2 ask about updates, inventory and audit.

06

### OEM manufacturer

- Connectivity, fleet management and over-the-air updates ready to use, instead of developing them yourself.
- Every client in its own organisation, with isolated devices and data.
- Transfer of ownership at a sale, replacement requests (RMA) and retirement.

Security and trust

## A stolen GridBit is a brick. A tampered GridBit does not boot. A tapped GridBit gives nothing away.

From the chip to the cloud, link by link

1. 01 Chip The private key is created here and never leaves.
2. 02 Boot Secure Boot checks the signature of the kernel.
3. 03 Applications Signed packages in an isolated WebAssembly environment.
4. 04 Channel TLS 1.3, both sides prove who they are.
5. 05 Platform Isolated organisations and an immutable audit log.

### Identity

- The private key is created in the device and never leaves it.
- GridBit issues the device certificate at the first connection.
- The serial number, the certificate and the connection identifier must match. Otherwise the connection is refused.
- A cloned device that is not in the list of manufactured units cannot activate.

### Communication

- TLS 1.3 with mutual authentication.
- The device checks the server by a pinned public key, so it depends neither on a clock nor on external certificate authorities.
- Every device reaches only its own channels.

### Code on the device

- Secure Boot: at power-up the chip checks the signature of the kernel.
- Encrypted flash memory with a unique key for each device.
- Applications run in an isolated WebAssembly environment and reach only what they are allowed to.
- The device refuses an unsigned or altered package.
- The device has the last word. It is designed on the assumption that the cloud can be wrong, so it checks the signature and the permissions, and it refuses to remove itself.

### Platform

- Every organisation sees only its own devices and data. The limit is in the database queries themselves, not in the interface.
- Secrets in configurations and session recordings are stored encrypted.
- An immutable audit log.
- Remote access needs no open ports on the site.

### Full transparency, for us as well

GridBit cannot enter your device without your explicit permission. The request comes to you, you approve access for a set period of 7 days at most, and you can end it at any time. Every action, ours or yours, stays in an immutable audit log that you can see.

- You know who did what to every device, when and from where.
- Control over the fleet stays with you, not with the vendor.
- An audit trail ready for inspections and regulators.

CRA, NIS2, GDPR

## Ready for the regulations that push old gateways off the market

1. Today NIS2 and GDPR already apply
2. 09.2026 CRA: reporting of vulnerabilities begins
3. 12.2027 CRA: secure updates through the whole life cycle

01

Cyber Resilience Act: secure updates through the whole life cycle (from December 2027)

Over-the-air updates of the kernel and the applications, staged rollout, automatic rollback.

02

Cyber Resilience Act: reaction to a vulnerability (reporting from September 2026)

A fix reaches the whole fleet quickly, in stages and with a result report.

03

NIS2: risk management down to the field device

Fleet inventory with versions, an immutable audit log, control of remote access, roles and two-factor authentication.

04

GDPR

Production data does not pass through the platform. Hosting in the EU. Versioned acceptance of a data processing agreement. Deletion of the organisation.

Scale and reliability

## Designed for a million devices. Measured, not assumed.

- **devices is the target around which the whole architecture was chosen**: 1 000 000 +
- **concurrent secured connections on one broker node, at 2 000 new connections per second, without a single error (laboratory measurement)**: 20 000
- **until the devices switch to a standby node when a broker drops (laboratory measurement, two-node cluster)**: < 4 s

Two broker nodes share the devices. One node drops. Its devices are on the standby node in under 4 seconds (laboratory measurement).

- High availability at every level A broker cluster, a database in three copies with synchronous replication, and stateless services that scale horizontally.
- Backups With a continuous archive of the changes, kept for 30 days.
- Economical traffic A light permanent channel for instant commands and grouped telemetry. By design estimate this cuts the number of messages 10 to 100 times.
- A console for every scale With 12 devices you look at the list. With 50 000 you work with summaries, search and ready views.
- Hosting in the EU The management data stays in the European Union.
- A managed service You install nothing and you maintain no servers, databases or brokers.

Comparison

## Own scripts, a general IoT platform, or GridBit Cloud

|  | Own scripts | General IoT platform | GridBit Cloud |
| --- | --- | --- | --- |
| Adding a new device | By hand, from a list | Through an API, with keys typed by hand | QR code from the box, self-activation |
| Device identity | Shared passwords or keys | A certificate loaded in production | A key created in the chip that never leaves the device |
| Changing an application | A file copied by hand | A command, lost when the device is offline | Desired state, the device brings itself in line |
| Updating | Everything at once | By hand, group by group | In stages, with automatic stop and rollback |
| Updating the kernel | A technician on site | Rarely supported | Over the air, encrypted for each device |
| Client data | Through your infrastructure | Through the platform, often with a fee by volume | Does not pass through the platform |
| Remote access | VPN, open ports | Depends on the vendor | No open ports, with approval, recording and audit |
| Who can run foreign code | Anyone with access | Depends on the device | Signed code only, checked by the device |
| Servers to maintain | Yours | None | None |

Industries

## Where a fleet of gateways lives

### Energy

Secondary substations, photovoltaic parks, metering points. Hundreds of sites without staff, in a sector under NIS2. Security updates for the whole fleet without site visits.

### Water

Pump stations and reservoirs in remote areas, often with LTE only. Remote access without a public IP address and without a VPN.

### Heating and buildings

Boiler rooms, HVAC systems, charging stations. Thousands of devices arranged by cities and buildings, with configuration at site level.

### Manufacturing

Old machines connected to modern systems. Your own logic at the edge of the network, rolled out to every line in hours.

### Agriculture

Greenhouses, irrigation systems, silos. Low consumption, LTE connectivity and devices that keep working when the link is down.

### OEM manufacturers

A gateway built into the machine, with fleet management, updates and transfer of ownership at a sale, without a cloud of your own.

How you start

## Five steps to a managed fleet

[Request a demo](https://www.gridbit.tech/contact?product=GridBit%20Cloud)

1. 01 Create an organisation Registration with an e-mail, without waiting for someone from GridBit.
2. 02 Add the devices Scan the QR code from the box or upload a CSV for the batch.
3. 03 Power them up The devices activate and appear in the console by themselves.
4. 04 Describe how they must work Configuration and applications at the level of organisation, site or group.
5. 05 Invite the team Everyone with the role and the scope they need.

What is coming

## The plan, in the open

Soon 11

- Signing of applications with a key of the organisation
- GridBit keys in a hardware security module
- Your maintenance window and postponing of updates
- Stable and beta channels for the firmware
- Viewing the recordings of remote sessions
- Tags and own names for devices
- Dependencies between packages
- SAML sign-in
- Slack and Teams in a few clicks
- Kernel update through recovery
- A command line tool and API tokens for clients

Planned 10

- An application store and a programme for publishers
- A public REST API and webhooks for fleet events
- A map of the fleet
- Setting the data channel from the console
- Export of all data of the organisation
- A console in English
- A visual editor for the logic
- Partners and distributors
- Support tickets and a status page
- Quotas for the private registry

Hardware

## Made together with the gateway

GridBit Cloud is not a general platform for any device. It was created together with the operating system of the GridBit gateway, and that is why it reaches where general platforms cannot: an identity born in the chip, code that the device checks by itself and a fleet that repairs itself after days without a link. Today it manages the GWU-5 gateway.

- [Gateway GWU-5 4G LTE gateway for Modbus devices, with Ethernet and MQTT 4G LTE Cat 1 Mobile network, 2G fallback RS485 + Ethernet Modbus RTU and Modbus TCP](https://www.gridbit.tech/hardware/gwu-5)

FAQ

## Frequently asked questions

### Does GridBit see our production data?

No. The gateway sends your data over a separate connection straight to your system. The platform sees only the technical state of the device: whether it is online, which versions it has, how much memory is free.

### What happens if the platform is unavailable?

The devices keep working and keep sending data to your system, because that channel does not pass through us. Management comes back by itself at the next connection, and the devices catch up with every change made in the meantime.

### Can GridBit enter our device?

Only with your explicit permission, for a period that you set (up to 7 days) and with a full trace in the audit log. You can end the access at any time.

### What happens if an update turns out to be a problem?

Updates go out in stages. If the errors after a stage pass the threshold, the rollout stops by itself and the affected devices return to the previous version.

### Do we need a public IP address, a VPN or open ports?

No. The device dials out by itself. Management and remote access work behind CGNAT, firewalls and mobile networks.

### What happens if a device is stolen?

You mark it as lost. It is refused at connection and, if you choose, wipes itself at the next attempt. The device itself has encrypted memory and unique keys, so the stolen box gives nothing away.

### Can we write our own applications?

Yes. Applications are written in Rust, C or Go and compiled to WebAssembly. You upload them to the private registry of the organisation and roll them out to your fleet without approval from GridBit, as long as they need no privileged access.

### Does the platform work with devices of other manufacturers?

No. GridBit Cloud was created together with the operating system of the GridBit gateway, and today it manages the GWU-5. That deep integration is what gives an identity born in the chip and a check of the code by the device itself.

### What fleet size is it for?

The same console works for 10 devices and for 50 000. The architecture is designed for more than a million.

### Where is the management data hosted?

In the European Union.

### Do we have to install anything?

No. The platform is a managed service. You need a browser.

### Can we automate the work?

A command line tool and service accounts for clients are coming soon. A public REST API is in the plan.

### What language is the console in?

Bulgarian. An English version is planned.

## Your fleet. Your data. Our care for the devices.

Show us your sites and we will show you how your fleet looks in GridBit Cloud.

[Request a demo](https://www.gridbit.tech/contact?product=GridBit%20Cloud) [office@add-bg.com](mailto:office@add-bg.com)
