The secure data bridge
your plant
has been missing.

Built for utilities, district heating, and industrial production. MOFF moves your PLC data to IT with cryptographic proof of every value. Signed. Audited. Tamper-evident.

MOFF reads. It never writes to your OT network. All data stays on your machine, on your network. If MOFF stops, your plant does not notice. Fails safe by design.
Your PLCs → MOFF → Your IT
PLC Sources
OPC-UA
Modbus TCP
S7comm
IEC 60870-5-104
BACnet/IP
Rockwell EtherNet/IP
HMI systems
Destinations
InfluxDB
REST Pull API
MQTT / UNS
SIEM / Splunk
OSIsoft PI
MES / PAS-X
Azure / AWS IoT
Your PLCs → MOFF → Your IT systems
PLC Sources
OPC-UA
Modbus TCP
S7comm
IEC 60870-5-104
BACnet/IP
Rockwell EtherNet/IP
HMI systems
Destinations
InfluxDB
REST Pull API
MQTT / UNS
SIEM / Splunk
OSIsoft PI
MES / PAS-X
Azure / AWS IoT
The Problem

Sound familiar?

“Your operator still exports CSV manually every morning.”
Twelve PLCs, one USB stick, and an Excel sheet as your historian. The data exists. It just never leaves the plant floor without a human touching it.
“Who changed that setpoint at 03:17?”
Something went wrong. The SCADA log says nothing useful. You have a PLC, four vendors, and no tamper-proof audit trail. And the authorities want to know exactly what happened.
“4 vendors. 4 contracts. None of them talk to each other.”
Your PLCs run. Your IT system waits for data. Between them sit an OPC aggregator, a historian, an integrator, and a compliance consultant. All with their own licences. No shared audit trail.
MOFF solves all three. One layer. One contract.
Installed in hours. No rip-and-replace. Works alongside your existing SCADA.
How It Works

Six steps.

01
Discover
Auto-detect PLCs and sensors. Config validated before the pipeline starts.
02
Poll
Async parallel read of all tags. One device offline never blocks the rest.
03
Process
Type-validate and normalize. Bad data blocked before it enters the chain.
04
Validate
Every value checked against your alarm limits. Rules update without stopping the pipeline.
05
Sign
ECDSA-signed SHA-256 block. Dual chain: system and process data separate.
06
Deliver
Forward to all configured destinations simultaneously. SQLite buffer. Zero data loss.
Platform

Built different.
For critical infrastructure.

01
Blockchain Audit Chain
Every datapoint is a SHA-256 linked block. Tamper is mathematically detectable. Not a policy, a proof.
block #48291 · prev 9f2a…c41d · sha256 e77b…03aa · chain verified ✓
02
ECDSA E-Signatures
Every operator action in MOFF signed with identity, timestamp, and source IP. Every polled value signed and chained, so a setpoint change is provable: what changed, and exactly when. 21 CFR Part 11 and ALCOA+ by design.
signed operator.id · 03:17:42 · 10.0.2.14 · ecdsa signature valid ✓
03 · Protocols
Where data comes from
Live now
OPC-UA: Siemens S7-1200/1500, Beckhoff, any OPC-UA server
Modbus TCP/RTU: all four byte orders, every register type
S7comm: legacy Siemens S7-300/400 direct
IEC 60870-5-104: utility SCADA and RTU telemetry
BACnet/IP: building systems and HVAC
Rockwell EtherNet/IP: ControlLogix, CompactLogix
HMI systems: any HMI exposing OPC-UA or Modbus
Roadmap
DNP3: energy and water SCADA
IEC 61850: substations and grid
04 · Destinations
Where data goes
Live now
InfluxDB: your time-series historian. Local buffer, zero data loss
MQTT / UNS: retained tag state + signed chain blocks. Sparkplug B supported
SIEM: signed audit chain to Splunk (HEC) or any JSON/HTTPS SIEM
REST Pull API: SAP, ERP, Power BI, Tulip. Any IT system pulls signed data
Connector ready · activated in pilot
OSIsoft / AVEVA PI push
MES: Tulip, PAS-X, Opcenter, SAP DM
Further destinations are built customer-driven.
05 · Optional
AI-assisted tag mapping
Classifying and routing hundreds of PLC tags by hand is the slowest part of any OT/IT project. MOFF can suggest signal type, unit, and destination mapping for every tag in one pass. Runs locally in your DMZ by default: process data never leaves the site. Every suggestion is chain-logged, and nothing is applied without human approval.
Industries

Built for your sector.

Water & Utilities

Mandatory NIS2. Cryptographic proof of every setpoint change. CFCS incident report ready in seconds.

SHA-256 tamper-evident history: what changed and exactly when. Signed operator identity on every MOFF action.
Works alongside existing SCADA: IGSS, WinCC, iFIX, ACOWA. No rip-and-replace.
One-click compliance export: signed evidence bundle for the 24h/72h deadlines.
Built for the Danish water sector: 280+ utilities in NIS2 scope.
MOFF for Water Utilities
NIS2 incident reportIn seconds
Setpoint change auditEvery change
MOFF actions signedIdentity + IP
SCADA disruptionNone
Pipeline cycle per PLC10 seconds
Data loss on outageZero

District Heating

~400 Danish utilities. NIS2 critical infrastructure, Modbus-heavy, almost no existing OT/IT integration targeting them.

Same NIS2 framework as water: identical audit and incident reporting requirements.
Substation and pump monitoring: temperature, pressure, flow signed every 10 seconds.
Works alongside DIMS, TERMIS: no rip-and-replace.
Same go-to-market as water: Dansk Fjernvarme network effect.
MOFF for District Heating
NIS2 incident reportIn seconds
Utilities in Denmark~400
SCADA disruptionNone
Pipeline cycle per PLC10 seconds
MOFF actions signedIdentity + IP
Data loss on outageZero

Energy & Wind

Tamper-evident chain on every process value. If a regulatory investigation follows an incident, your evidence is audit-grade and independently verifiable.

Parallel polling: one turbine offline never blocks the fleet.
IEC 60870-5-104 supported now: IEC 61850 on roadmap, bridge via OPC-UA today.
On-site AI: zero internet egress by default. No data leaves the fence.
Cloud destinations: Azure IoT Hub, AWS, Grafana Cloud.
MOFF for Energy & Wind
Devices blocked on failureZero
AI inference locationOn-site DMZ
Independently verifiableEvery event
Cloud destinationsAzure, AWS
NIS2 incident reportIn seconds
Data loss on outageZero

Food & Beverage

Unbroken traceability from raw material to finished product.

HACCP traceability: every CCP measurement signed.
MES integration: SAP ME, Plex, Opcenter via REST.
Cold chain alerts: deviation fires to Email, Teams, or webhook within the next cycle.
Recall-ready: any batch traced in seconds.
MOFF for Food & Beverage
Sensor readings signed100%
MES integrationVia REST
Deviation detected withinOne 10s cycle
Custom developmentNone needed
Recall investigationImmediate
Data loss on outageZero

Healthcare

NIS2 essential entities. HVAC, medical gas, power: almost none of it audit-logged today.

NIS2 essential entity: any OT supporting critical care needs an audit trail.
HVAC and medical gas: every alarm acknowledgement chain-logged.
Modbus and BACnet/IP supported now: chillers, AHUs, and BMS read directly.
Structured procurement: NIS2 audit trail sells itself to compliance teams.
MOFF for Healthcare
NIS2 classificationEssential entity
Alarm acknowledgementsChain-logged
Operational disruptionNone
NIS2 incident reportIn seconds
Modbus TCPSupported now
Data loss on outageZero

Manufacturing

PLCs to MES and ERP in one signed pipeline. Add a device in seconds. Every batch dispute resolved with tamper-evident data.

Per-PLC flow diagram: real-time status, auto-refreshed.
Rockwell EtherNet/IP supported now: ControlLogix and CompactLogix read directly.
SAP S/4HANA: OEE and quality via REST/OData.
Zero-downtime: add a PLC, picked up next cycle.
MOFF for Manufacturing
Add new PLCSeconds
Pipeline restart neededNever
SAP integrationVia REST/OData
Batch dispute resolutionImmediate
OEE data latency< 10 seconds
Data loss on outageZero

Pharma & Life Sciences

21 CFR Part 11 e-signatures on every intervention. Out of the box. No integration project.

21 CFR Part 11: ECDSA e-signatures on every intervention, by design.
22 intervention types: all ECDSA-signed and chain-logged.
PAS-X on roadmap: signed batch events to pharma MES.
Air-gapped AI: on-site inference by default. Data never leaves the GMP boundary.
MOFF for Pharma
E-signature standardECDSA / PKI
Intervention types logged22 types
AI data boundaryOn-site DMZ
Audit trail verified onEvery read
ALCOA+ data integrityBy design
Integration project neededNone
GMP tier available2027
Plant Fit Report
0%
FIT
Professional
Analysing your stack...
Protocols
Compliance
Destinations
MOFF Insight

See MOFF in your plant.

30 minutes. Real PLC data. No slides.

REPORT ON ITS WAY: CHECK YOUR INBOX

No commitment. No sales pressure.

Missing something?
RECEIVED: GOES STRAIGHT TO THE ROADMAP
Deployment

From install to audit-ready.

DAY0
Install
One Windows machine in your DMZ or server room. Read-only network access to your PLCs: no agents on controllers, no firmware changes, no SCADA downtime. Production never notices.
DAY1
Data flows, signed
The setup wizard discovers your PLCs and maps your tags. From the first poll, every value is ECDSA-signed into the audit chain and lands in your historian and IT systems. 10-second cycles.
DAY2
Everything flows
PLC to historian to IT: every value moving automatically, signed, around the clock. No operator touches a USB stick again. And when the auditor asks: one click exports the signed proof. MOFF runs silently in the background.
Deployed by your own team, by us, or by your integration partner. Days, not quarters. No rip-and-replace. No six-month integration project.
Pricing

Simple pricing.
No surprises.

All prices DKK excl. VAT · NIS2-ready audit trail included in every plan

Plan
Scope
Price / yr
Essentials
5 PLCs · 2 destinations
49.000 DKK
Professional
15 PLCs · 5 destinations
119.000 DKK
Enterprise
Unlimited PLCs · unlimited destinations · fair use
249.000 DKK
GMP
COMING 2027
FDA · 21 CFR Part 11 · Pharma · Unlimited
349.000 DKK
Enterprise+
White-label · system integrators · custom SLA
Contact us
Included in every plan
Full management dashboard (live trend, chain view, alarms) · NIS2 compliance export · Backup & Restore.
0 DKK
Priority Support
4-hour response guarantee in business hours, named contact.
Trend History
Local history database inside MOFF: track and compare beyond live values.
Custom Connector
Your protocol or destination, built to order. Fixed quote.
Add-on pricing on request.
Onboarding: 35.000 DKK fixed price, any tier, remote. On-site deployment: fixed quote · Multi-year discounts: ask us.
Example: Professional, 3-year view
Licence
119.000
+
Onboarding
35.000
=
Year 1
154.000 DKK
Year 1
154.000
Year 2
119.000
Year 3
119.000
Onboarding falls away after year 1. Prices excl. VAT.
Plant Fit

Does MOFF fit your plant?

2 minutes. Personalised fit report for your site.

Step 1 of 616%
Your Role

What is your role?

Operations / Production
Day-to-day plant operation
OT / Automation Engineer
PLC programming, instrumentation
IT / OT Security
Network, compliance, cybersecurity
Management / Director
Strategy, budget, compliance ownership
Industry

Which sector?

Water & Utilities
District Heating
Energy & Wind
Food & Beverage
Pharma & Life Sciences
Healthcare
Manufacturing
Other
Protocols

Which protocols does your plant use?

Select all that apply. Not sure?

OPC-UA
Siemens S7-1200/1500, Beckhoff
Supported now
Modbus TCP / RTU
Schneider, Danfoss, generic
Supported now
S7comm
Siemens S7-300/400 legacy
Supported now
PROFINET
Siemens S7-300/400
Roadmap
Rockwell / EtherNet/IP
Allen-Bradley ControlLogix & CompactLogix
Supported now
IEC 60870-5-104
Utility SCADA, RTU telemetry
Supported now
IEC 61850
Power grid / substations
Roadmap
BACnet / IP
Building automation, HVAC
Supported now
Destinations

Where should data go?

InfluxDB
Time-series database
Supported now
REST API / Webhook
Any HTTP endpoint, external pull
Supported now
MQTT / UNS
Unified Namespace, Sparkplug B
Supported now
OSIsoft PI / AVEVA
Process historian
Pilot-ready
MES / PAS-X
Tulip, Opcenter, SAP DM
Pilot-ready
SAP S/4HANA
OEE, quality via REST/OData
Roadmap
Azure / AWS
IoT Hub, Kinesis, S3
Roadmap
Grafana / Prometheus
Visualization, monitoring
Roadmap
Splunk / SIEM
Signed audit chain, HEC/JSON
Supported now
Compliance

Which compliance frameworks apply?

NIS2
EU directive, mandatory in DK since Oct 2024
Danish water sector
Sector requirements, drinking water regulation
GMP / 21 CFR Part 11
Pharma, FDA compliance
ISO 27001
Information security management
HACCP
Food safety
None / Not sure yet
Pain Points

What is the biggest challenge today?

No audit trail for OT changes
Cannot prove who changed what and when
NIS2 / compliance pressure
Deadline approaching, no structured solution
OT and IT are siloed
Data stuck in the plant, IT cannot access it
Manual data collection
Operators typing readings into spreadsheets
Incident investigation takes days
No structured log to search through
Who is behind MOFF
MOFF is built by Mikkel, a Danish OT/IT engineer with 20 years in automation and regulated production: utilities, pharma, and industrial manufacturing. MOFF exists because moving PLC data to IT should not require four vendors and four contracts. Registered in Denmark, CVR 44047918.

See MOFF in your plant.

30 minutes. Real PLC data: collected, signed, audited. No slides. No sales theatre.

WE WILL BE IN TOUCH WITHIN 24 HOURS

No commitment. moffbridge.com · CVR 44047918

Not ready for a call? Download the 1-page overview (PDF) →