Tethyr by Exact Automation

Managed SCADA connectivity

Secure remote access and alarm callouts for VTScada.

Give your operators access to VTScada from anywhere, and make sure every alarm gets through to a person, without putting your control system on the internet. A small connector at your site makes one connection out to Tethyr, so nothing is left exposed, and you are up and running without a long IT project.

The connection only goes out from your site. Nothing comes in.

Built forVTScada by Trihedral
NO INBOUNDVTSCADAFIELDTETHYRCALLOUTOPERATOR
The problem

A 2 a.m. alarm should not force a security decision.

You run wells and facilities hours from anyone. An alarm still has to reach a person in the middle of the night. An operator still needs to see the HMI from town. The usual ways to do that each ask you to give something up: an opening to the internet, a standing IT project, or a risk that lands on you alone.

Expose it

Put VTScada on the internet so it can be reached. Every IT and IS professional you have says no, and they are right.

VPN dance

Stand up a VPN and file a firewall change every time someone new needs in. It works until it does not, and it never scales.

Drive out

Send a person to site to read one screen or clear one alarm. Hours of windshield time for a two minute look.

There is a better way to do both, without opening your network to anyone.

The idea

One connection out. Nothing open to the internet.

A small connector at your site makes a single, encrypted connection out to Tethyr. Nothing on your network is left open for anyone outside to get to. Alarm callouts and remote access both run over that one connection. The direction is the whole point: the connection only goes out to us, and nothing comes back in. That is the answer your IT and IS team is looking for, and it is why your operators can get to VTScada from anywhere without the usual risk.

Built for VTScada

One SCADA platform, done properly.

Tethyr is not a general remote-access product pointed at a control network. It is built for VTScada, by the integrator that already configures VTScada in the field. That is why setup is measured in minutes, and why the answers your IT team asks for are specific instead of generic.

VTScada by Trihedral

VTScada is a registered trademark of Trihedral Engineering Limited. Tethyr is a product of Exact Automation and is not affiliated with or endorsed by Trihedral. The mark identifies the platform Tethyr works with.

Purpose-built, not adapted

Every screen, default, and setup step assumes VTScada, because that is the only platform Tethyr connects.

Configured by people who know it

Exact Automation configures VTScada in the field. The same team builds and supports Tethyr.

Works with what you already run

Alarm callouts and browser access work with your existing VTScada application. No rework, no migration.

The alternatives

Every other way in leaves something open.

Callouts and remote access each come with their own shortcuts, and most of them cost you an open port, a standing project, or a risk you now own outright. Pick a stream and see the honest comparison.

Getting a real alarm to a real person, with no way back in.

TWILIOVTSCADAOPEN INTERNET

Expose a callback

Dangerous

Open a public endpoint so Twilio can reach your callout logic. You opened it for one provider, but the whole internet can hit it, and a spoofed callback looks exactly like a real one.

TWILIOPROXYVPNVTSCADA

Roll your own

On you

Wire up Twilio behind a hand-built proxy, then a VPN to reach VTScada safely. It can work, but that is two moving parts you build, run, and answer for at 2 a.m.

TWILIOTETHYRVTSCADANO INBOUND

Tethyr Callouts

Managed

Twilio and VTScada both dial in to Tethyr. It validates every callback cryptographically and relays only genuine ones. Spoofed calls die at the door, and nothing reaches into your SCADA.

ApproachExposeRoll your ownTethyr
Keeps your control network closed
Rejects spoofed callbacks
Nothing custom to build or maintain
SLA and real support behind it

Rolling your own is the smart version of the hard way. It can be just as closed as Tethyr, but it is code you build, run, and answer for at 2 a.m. Tethyr is that same secure idea, finished, for both streams: a product you can trust instead of a project you babysit.

Why Tethyr

A product, not a project.

01

Self-service from the first click

Provision a site yourself in the browser. No professional-services engagement, no ticket queue, no waiting on us.

02

Live in minutes

The connector dials out, the tunnel forms, and you are running. Not a quarter. Not a weekend. Minutes.

03

An SLA behind every site

This is a supported product with a service level, not a script you maintain and pray over at 2 a.m.

04

Built by SCADA people

From Exact Automation, the integrator that already runs VTScada in the field for operators like you.

How it works

Four steps, one direction.

  1. 01

    The connector dials out

    Install one package on the VTScada box or a small separate host. It only dials out. Your IT opens no ports and changes no firewall rules.

    connector: outbound only
  2. 02

    The tunnel forms

    The connector builds a WireGuard-encrypted tunnel to Tethyr over an ordinary outbound connection. Nothing on your side ever listens for inbound traffic.

    wireguard: encrypted, outbound
  3. 03

    Callouts flow

    An alarm places a callout through Twilio. Tethyr verifies the request cryptographically and forwards only genuine callbacks over the tunnel. Nothing spoofed gets through.

    callouts: validated, forwarded
  4. 04

    Access flows

    An operator signs in and launches VTScada in a browser. The session is brokered over the tunnel with MFA on every login. The browser is never on your network.

    access: brokered, mfa
A look at the product

One dashboard for the whole fleet.

Connector health, callouts, and access in one place. This is the product direction, shown with the real brand. It is a vision of the build, not a claim that it has shipped.

app.tethyr.network/dashboard
Connector

Fleet status

Tunnel up
Sites online

12 / 12

Callouts today

37

Active sessions

3

SiteCallouts / Access

cnrl-battery-04

10.20.4.11

healthyhealthy

tourmaline-ci-2

10.20.9.30

healthyattention

westbrick-sat-7

10.20.7.12

healthyhealthy
app.tethyr.network/onboarding
Onboarding

Bringing the site online

  1. +Account and tenant created
  2. +Connector command generated
  3. +Connector dialed out, tunnel formedonline now
  4. VTScada reachable through tunnel
  5. Independent alarm fallback confirmedrequired to go live
cnrl.tethyr.network/scada
Operator portal

Launch a session

mfa verified
  • Battery 04 HMI

    overview, trends, alarms

    Launch
  • Compressor CI-2

    runtime, suction, discharge

    Launch
  • Sat 7 Wellheads

    12 wells, statuses

    Launch

session brokered over the tunnel. the browser is never on the control network.

What you get

Two streams. Buy one or both.

Tethyr Callouts

Every alarm gets to a person. Nothing forged gets to your SCADA.

TWILIOFORGEDTETHYRVTSCADAVALIDATED IN, SPOOFED OUT

A real alarm places a callout through Twilio. Tethyr verifies every request cryptographically and forwards only genuine callbacks over the tunnel. Forged requests die at the door. Your operators get the call, your SCADA stays sealed.

  • Cryptographically validated
  • No inbound ports
  • Reliable delivery to a human
Tethyr Access

Launch VTScada from anywhere. Nothing touches your network.

BROWSERTETHYRVTSCADAMFABROKERED, NEVER ON YOUR NETWORK

Operators open a branded portal and run the HMI in a browser, brokered over the tunnel with MFA on every login. The browser never sees your control network. You delegate who gets in, and every session is audited.

  • Runs in the browser, no install
  • MFA on every login
  • Access control you delegate
Why it is safe

The security story is the architecture.

This is the answer for your IT and IS team. Facts, not fear.

Outbound-only, zero inbound ports

Your side opens nothing to the internet. The connector dials out. There is no inbound port to scan, probe, or exploit.

WireGuard-encrypted tunnel

Traffic rides a modern, audited encryption layer end to end. We do not deploy raw crypto, we manage a proven one.

Tenant isolation, fail closed

Every customer is isolated at multiple independent layers. One site's traffic can never reach another site's SCADA. When anything is uncertain, it stops.

MFA on every login

Multi-factor is required for remote access, on every tier. Access is authenticated before a session is ever brokered.

Credentials stay protected

Customer secrets are stored encrypted and every access is audited. They never sit in plain text and never travel further than they must.

Audited by design

Security-relevant actions are written to an append-only record you can review.

Pricing

Pay for what you connect and turn on. Nothing you send.

Turn on the streams you need: alarm callouts, remote access, or both, each a flat annual fee. Then pay a simple per-server fee for the servers Tethyr connects to, counted once whatever runs on them, plus a user tier for remote access. No metering, no per-message billing, no surprises. Redundancy is the recommended default, not an upsell. Figures are indicative annual pricing; a demo gets you a real quote.

Build your quote

Turn on the streams you need, count the servers Tethyr connects to, and add users for remote access. The total updates as you go, no metering, no per-message billing.

Streams

Servers you connect

Each VTScada server Tethyr securely connects to, counted once whatever streams run on it. $1,200 each.

1

Note: This is not your whole VTScada system, just the servers that host thin-client connections, which is what Tethyr connects to. I/O, historian, and alarm servers do not count unless they also serve thin clients. What is a VTScada thin-client server?

Remote access users

The first 5 come with remote access. Above that you move up a tier. You are on: Up to 5 users.

5

Options

Your quote

  • Connected servers (1 server)$1,200
  • Remote access (base, up to 5 users)$5,000
Total$6,200/ yr
Book a demo for a real quote

Indicative annual pricing. A demo gets you a quote tailored to your servers and users.

Who is behind it

Built by Exact Automation.

Tethyr is built by the team that already configures your VTScada. This is not a security startup guessing at oil and gas. It is the integrator you already trust, applying the same field-tested SCADA expertise to give your operators access while keeping your control network closed.

  • Deep VTScada and SCADA integration experience
  • Built for oil and gas operators across the Western Canadian basin
  • Support from people who understand a control room, not a call center
For your IT and IS team

The questions they will ask.

Do we have to open any ports?+

No. The connector only dials out. There is no inbound port on your side, nothing to expose, nothing to scan.

Is our SCADA on the internet?+

No. VTScada stays on your control network. It is reached only through the outbound tunnel, and only for the streams you enable.

How long does it take to go live?+

Minutes. Onboarding is self-service: you provision the site in the browser, install one connector, and watch it come online. No professional-services engagement required.

Is the connection encrypted?+

Yes. The tunnel is WireGuard-encrypted end to end. Remote access requires MFA on every login.

Can one customer reach another customer's SCADA?+

No. Tenant isolation is enforced at independent layers, from routing to the tunnel to the VTScada side. The system fails closed.

Is Tethyr the system of record for alarms?+

No. Tethyr is secure transport. Every site keeps an independent alarm fallback that does not run through Tethyr. We confirm it before you go live.

See the outbound-only model in action.

Book a short demo. We will walk the architecture, trace a live alarm callout end to end, and launch remote access in a browser, on a setup like yours.

hello@tethyr.network