Why MOFF

A log is not proof.

Your historian has the numbers. Neither it nor the log beside it can tell you whether anyone changed them on the way.

MOFF signs each value where it is read. Anyone can check the record without taking your word for it.

Why now

Industrial sites have more data than ever, but most still reach for SCADA logs, historian exports and spreadsheets when someone asks what actually happened.

01 · NIS2
Audit trails are no longer optional
Critical infrastructure operators are expected to explain incidents, actions and changes under strict reporting timelines. Reconstructing events from multiple systems is slow. Evidence needs to be ready when requested.
02 · Compliance
Auditors expect proof, not screenshots
Whether the requirement is GMP, ISO 27001, internal quality reviews or external investigations, the burden is increasingly on proving what happened and when.
03 · AI & analytics
Trustworthy output starts with trustworthy input
Dashboards, analytics and AI systems only add value when the underlying data can be trusted. Proven lineage matters more than another dashboard.
04 · OT → IT
Manual processes do not scale
CSV exports, local logs and disconnected systems work until someone asks for a complete picture. Most plants already have the data. They lack a single verifiable record.

Against what you already run

Against the connectivity layer you probably already run, whether that is Kepware, Ignition, Cogent DataHub or PI Interfaces.

Traditional gateway or connectorMOFF
Primary jobMove dataMove data and prove it was not altered
Audit trailApplication logs, editable by anyone with server accessSHA-256 linked chain, ECDSA-signed at the moment of capture
VerificationTrust the system that wrote the logStandalone verifier the auditor runs on their own machine
ComplianceAn add-on, or assembled by hand for each auditOne-click evidence bundle: chain, config, CSV, verifier
DestinationsUsually one primary targetSeveral destinations from the same signed record
Trust modelThe vendor's wordCryptographic proof, checkable without us

Run MOFF alongside it. It reads from the same PLCs and does not touch your existing integration.

And in-house middleware
Middleware you built yourself is cheap to start and expensive to defend. The scripts work. The problem arrives the day someone asks who changed a value at 03:17, and the answer is a log file that anyone with server access could have edited.

What changes in practice

Manual CSV exports and USB sticks are replaced by automatic, signed delivery every cycle.
Audit evidence is exported in one click instead of assembled by hand from three systems.
Setpoint changes stop being a question of memory: the chain shows what changed and exactly when.
One layer and one contract replace an aggregator, a historian and an integration project.

Who this is for

Operations
OT manager · automation manager · site engineering
Wants data off the plant floor without touching the control system.
Asks: will this disturb production?
Compliance and quality
QA · CSV · data integrity lead
Wants an audit trail that holds up under inspection.
Asks: can this be verified independently of us?
Management
Plant manager · production director · digitalization lead
Wants fewer vendors, faster reporting, less personal exposure under NIS2.
Asks: what does this replace, and what does it cost?

Where this goes

The trusted data layer between industrial operations and enterprise systems.
Industrial data is moving into cloud platforms, SIEM systems and AI models faster than the proof of where it came from. The record of what actually happened on the plant floor is still assembled after the fact, from logs that anyone with server access could have edited. MOFF exists to close that gap: every value signed where it is captured, so that whatever the data feeds downstream, its origin can be verified independently.

Want to see it running against your own protocols?