SIMSY makes it easy to securely access remote devices and assets.
Reaching equipment in the field has gone from a convenience to a requirement. Estates have grown, engineers have not, and the equipment now expects to be patched, monitored and reconfigured throughout its life. Remote access is how any of that happens.
SIMSY approaches it differently. Rather than building a route across to your devices, we allow you to integrate them as you do any other device on your network.
Remote assets are no longer a special case.
Charge points, screens, controllers, cameras, sensors, robots. The number of remote devices managed by organisations is increasing, and every one of those things needs looking after for years.
Site visits are the cost
A van, an engineer and half a day, often to change a setting or read a log. Anything fixable from a desk is money that never needed spending.
Uptime is contracted
Availability commitments assume you can intervene quickly. Waiting for someone to reach the site is not a response time anybody accepts.
Patching is now an obligation
Regulation increasingly expects connected equipment to be updated across its life. That is only realistic if you can reach it.
Estates keep spreading
Deployments that started as a handful of sites become hundreds. Manual attention does not scale with them.
Machines act on their own
Robots, edge inference and autonomous systems make decisions in the field. Understanding what they did means getting to them.
Diagnosis needs depth
A dashboard tells you a device is unhappy. Finding out why usually means getting inside it.
Four familiar approaches
Each of these works, and each is in wide use. It is worth looking at what they have in common.
VPN (tunnel to a gateway)
You stand up a gateway with a public address, the devices dial into it, and traffic runs through an encrypted tunnel. You own the gateway, the keys, the client configuration and the patching, for as long as the deployment lasts.
Software agents (phone home to a cloud)
An agent installed on each device holds a connection open to a hosted service, and you reach the device through that service. The vendor runs the infrastructure. The agent has to be maintained on every device, and the route into your estate lives in somebody else’s cloud.
Reverse tunnels (device dials out and waits)
The device opens an outbound connection to a server you run and keeps it there, so you can travel back down it. Effective, and it means a persistent connection per device plus a server that has to stay up.
Public addressing (reach the device directly)
Give the device a public address and connect straight to it. Rarely available on cellular, because devices sit behind carrier-grade NAT, and where it is available the equipment is then sitting on the open internet.
All four exist for the same reason.
Your device is on somebody else’s network. Every one of those approaches is a bridge built over that fact, and everything they cost you afterwards is the price of maintaining the bridge.
SIMSY does not build a bridge. We operate the mobile core, so the network your devices attach to is one you control: your APN, your IP ranges, your subnets, your routing policy, set by you and changed whenever you like.
Once that is true, the problem stops being a remote access problem. Your devices are on your network, and you can use the techniques you would use on any network you own. Address them directly. Put them on a subnet together. Extend a segment of your existing estate to include them. None of that requires a tunnel, because there is no gap left to cross.
The methods below are not products we invented. They are ordinary local networking, made available to equipment that happens to be three hundred miles away on a cellular connection.
Local network techniques, at any distance.
Three ways of working, from reaching a single device through to your estate becoming part of your own network. Use one, or all three across different parts of a deployment.
Direct access, on demand
On a local network you would type in its address
Generate a secure link to a device’s interface, use it, and close it. Nothing stays open between sessions and nothing is left listening. Do it from the portal, or from the API so it happens inside an automated support workflow.
Suits equipment an engineer needs to look at occasionally rather than continuously.
SIMSY Proxy in detailDevices on a shared subnet
On a local network they would be on the same switch
Put SIMs onto a private subnet together and they talk to each other directly, with external traffic denied by default. Sites spread across a country behave as one LAN, with no hardware in the middle and nothing crossing the public internet.
Suits edge clusters, distributed sites, and machines that coordinate between themselves rather than reporting to a centre.
Cellular Private LAN in detailYour network, extended
On a local network they would be another VLAN
Drive the SIM addressing from your existing plan and the equipment joins your network properly. Your ranges, your routing, your monitoring tools, applied to devices in the field the same way they apply to anything on site.
Suits network teams who would rather absorb the estate than manage a second one alongside it.
SIMSY Extend in detailWhat you stop having to do
No gateway
Nothing to stand up, size, licence or keep patched for the life of the deployment.
No agents
Nothing installed on the device, so nothing to update on every device when it changes.
No public entry point
Nothing of yours facing the internet, so nothing exposed for anyone to find.
No third party in the path
The route to your equipment does not live in somebody else’s cloud.
VPNs are not insecure, and plenty are run well. They are also, increasingly, the way in: a gateway sits on a public address by definition, which has made gateways among the most consistently targeted infrastructure in the field. Removing the gateway removes the target.
Try it on one device.
Get a SIM, put it in something, and reach it from your desk. You will know within the hour whether this page is telling the truth.