Why Four differentiators

Why choose D6 Labs?

We built our platform from the ground up with security, reliability, and simplicity as core design principles.

01 Differentiator #1

Secure By Design.

Across the publicly reported attacks on US water systems, nobody defeated sophisticated protections. Attackers found controllers reachable from the public internet, used passwords that were still the factory default or shared across a crew, and logged in through consumer remote-access software with no second factor.

Every one of those is a property of the architecture as much as of the utility. You can harden a conventional system a long way, and you should, but hardening cannot change what the system fundamentally is. Our platform removes the property instead of patching the instance.

01 / 05

Outbound-only connectivity

Field devices open connections outward to the platform and keep them open. Nothing at your utility listens for inbound connections: no port to forward, no service waiting for a login attempt, no address that answers a probe. A scanner sweeping the internet finds nothing to talk to.

  • No open inbound ports at your sites
  • No port-forwarding to maintain
CLOUD OUTBOUND · TLS SMARTCONTROLLER™ scan → 0 open ports · nothing listening

02 / 05

Encryption on by default

Traffic between your sites and the platform travels inside TLS, and the message itself is encrypted a second time with a per-device key. It cannot be switched off. That is the direct answer to unencrypted radio, where somebody within a few miles can listen to your telemetry and send commands your controllers accept as genuine.

  • Two independent layers of encryption
  • A unique key for every device
  • No setting to forget, no toggle to misconfigure
DATA 3F A9 07 C2 AES-256PER-DEVICE KEY TLSTRANSPORT ENCRYPTION

03 / 05

Certificates, not passwords

Each device holds a certificate issued when it is deployed. It is never typed, never spoken, and never travels in a form anybody could reuse. There are no default device passwords to leave unchanged, and revoking access for a departing employee is an administrative action that takes effect immediately, not a trip to every site.

  • No default device passwords
  • Certificate issued at deployment
  • Revoke a departing employee in one step
DEVICE CERTIFICATE SUBJECTwell-02 ISSUERyour org's private CA ISSUEDat deployment PASSWORDnone ACCESS OperatorVALID SupervisorVALID Former employee REVOKED

04 / 05

Locked-down local access

No USB. No Bluetooth. No Wi-Fi. Where a controller does have a port, like the Ethernet ports on the Nexus.io AC, it is locked down. Cut the padlock at a remote site, open the panel and plug in a laptop, and you get nothing without a valid certificate issued for that system. The lock stops being the only control.

  • No USB, Bluetooth or Wi-Fi to exploit
  • Ethernet ports accept certificate-holding devices only
  • Programs and configs arrive signed, through the cloud
NEXUS.IO AC FIELD I/O ETH NO CERT · REFUSED NO USB NO BLUETOOTH NO WI-FI ETHERNET:CERT ONLY

05 / 05

Per-person access, fully logged

Everyone gets their own login with role-based permissions; shared crew accounts are not needed to make it work. Every action is written to an audit trail, so you can answer who changed what, and when.

  • Role-based permissions
  • Individual accounts, never shared logins
  • Full audit trail

Nothing listening. Nothing that trusts a stranger. Nothing to steal and reuse.

Outbound-only connectionsCertificate-only local portsRevocable certificates

Secure By Design, applied

Your audit findings, answered.

The problems a security audit typically turns up at a water system, and what each one becomes under this architecture.

Typical audit findings and what each becomes on the D6 Labs platform
Typical audit findingUnder this architecture
Equipment reachable from the internetNothing listens, so there is nothing to find by scanning
Default passwords on controllers or radiosNo device passwords to leave at their default
One shared login the whole crew usesPer-person credentials; shared logins are not needed to make it work
Access still active for somebody who leftRevoke that person’s credential; device credentials are unaffected
Remote-access software with no second factorNo inbound remote-access tool; access is through the platform, per person
Unencrypted radio between sitesEncrypted cellular; interception yields nothing usable
A panel anyone could open and plug intoNo USB, Bluetooth or Wi-Fi, and Ethernet ports accept certificate-holding devices only; the lock stops being the only control
Equipment that no longer receives firmware updatesSupported equipment that updates itself, remotely, as fixes are released
Nobody has tested a backup in yearsConfiguration and programs are retained centrally and continuously

Don’t know which of these apply to you? That is what the self-audit workbook below is for.

Honest by design

What still needs you.

No architecture removes the need to do a few things well: phishing awareness, your business network and billing systems, physical protection of the equipment, and an emergency plan that lets you run manually. We would rather say so than pretend otherwise.

Phishing awareness

Help your staff recognize suspicious emails, links and calls. People are still a target.

Business & billing network

Office computers, billing and email systems need their own protection, separate from SCADA.

Physical protection

Fences, locks and site checks still matter for pumps, tanks and treatment equipment.

Emergency manual-operation plan

Know how your crew will run the system by hand, and practice it before you ever need it.

Free resources

Free security guides.

Two workbooks for water systems, written to be useful whether or not you ever buy anything from us. Neither one names a product, including ours.

Start here

Water System Security Self-Audit

A guided walkthrough that finds the problems which cause real incidents: how people log in from outside, the passwords on your equipment, and what protects your unmanned sites. You do it yourself, at your own pace, with no special tools and no IT background. Everything in it is looking, reading and writing down, never probing or changing, so nothing in it can take your plant down.

  • ForOperators, superintendents, managers
  • Takes6–10 hours, spread over several days
  • IncludesPer-site inspection sheets and a prioritized fix list

Then this

Upgrading Security: Moving to Cloud-Based SCADA

Some audit findings cannot be fixed with a setting change. This guide is about those. It explains what cloud SCADA actually is, why hardening has a ceiling, and how to specify and buy a system so that what you get is genuinely secure rather than merely modern, including the ten requirements to write into your bid and the red flags to watch for in the answers.

  • ForAnyone building the case, going to market, or living with it after
  • CoversThe security case, costs, objections, and taking it to your board
  • IncludesRequirements checklist, proposal scoring sheet, cost worksheet
Download PDF PDF

Both documents are free to use, copy and share within your utility and with other water systems. All security guides, including the Engineer Edition →

02 Differentiator #2

Hot-swap capability.

Traditional SCADA systems require a programmer to configure each device. When a device fails, you need to schedule a site visit, bring a laptop, and spend hours reconfiguring the replacement. Our platform eliminates this problem entirely.

  • Configuration stored in the cloud. All device configuration is stored securely in the cloud. The field device is simply a connector between your equipment and the cloud.
  • Automatic configuration. Install a new device, power it on, and it automatically downloads its configuration from the cloud. No laptop required. No programming.
  • Minutes, not hours. Lightning strike? Equipment failure? Any trained operator can swap a device and have the site back online in minutes.
  1. 01Swap deviceAny trained operator
  2. 02Power onConnects outbound
  3. 03DoneConfig pulled from cloud
CLOUDCONFIG v42 · SIGNED SITE PANEL · LIFT STN 3 FAULT CONFIG REPLACEMENT UNIT

03 Differentiator #3

Lower total cost.

Traditional SCADA requires purchasing PLCs, RTUs, radios, and software from multiple vendors, then paying an integrator to make it all work together. Our integrated approach dramatically reduces total cost.

Illustration, not to scale: traditional SCADA stacks PLCs and RTUs, radios, software and an integrator from several vendors; D6 Labs is one vendor covering hardware, software, connectivity and support. TRADITIONAL · SEVERAL VENDORS PLCs & RTUs Radios Software Integrator D6 LABS · ONE VENDOR Hardware · software · connectivity · support NO INTEGRATOR NEEDED Lower total cost of ownership · illustrative, not to scale

All-in-one solution

Hardware, software, connectivity, and support all from one vendor. No integrators needed. No finger-pointing when something goes wrong.

2-year warranty

Every device comes with a 2-year warranty, extended for as long as you keep the Uptime Plan. If it fails, we replace it.

20-year availability guarantee

We guarantee parts availability for 20 years. Your investment is protected for the long term.

Prefer an operating expense to a capital purchase? See the Flex Plan →

04 Differentiator #4

Built & supported in the USA.

When you call D6 Labs, you’re talking to the engineers who design and build our products. We don’t outsource manufacturing. We don’t outsource support.

  • US manufacturing. Every device is designed and built by our team in Oklahoma City. Quality control at every step.
  • Direct support. Call us and talk to an engineer who understands your system. No call centers. No scripts.
  • Fast replacement. We keep stock on all parts. Need a replacement? It ships same day.

About D6 LabsOur SMT line

Digital Six Laboratories: Made in USA, Oklahoma Proud

Designed, built and supported in Oklahoma City

Side by side

D6 Labs vs. traditional SCADA.

Comparison of D6 Labs and traditional SCADA
FeatureD6 LabsTraditional SCADA
Security architectureOutbound-only connectionsOpen ports and VPNs
Device credentialsRevocable certificatesShared passwords
Device replacementHot-swap, config from the cloudReprogramming
Warranty2 years, extended with the Uptime Plan1–3 years
Integration requiredNoneExpensive integrator
SupportDirect from engineersMultiple vendors
Data storage1 year includedLimited or extra cost

Get started

Ready to see the difference?

Talk to our team about your specific application and see how D6 Labs can help.

Call 1-844-365-8647