Outbound-initiated
An encrypted tunnel from the edge to the platform, started from the edge on port 443.
EmberFLUX delivers zero-trust network security and a remote device maintenance tunnel to every node on the EmberNET platform: no exposed ports, no VPN configuration, and no firewall rules to manage.
Traditional OT networks rely on perimeter defense: keep threats outside the fence and trust everything inside. EmberFLUX assumes no connection is trusted by default.
Every node must authenticate before it communicates. Access is granted by identity, not by network location, and it's scoped to exactly what's needed.
The mesh network discovers services automatically. When you add a new node, it joins the encrypted fabric: no firewall rules to write, no VPN gateway to configure, and no ports to open.
All traffic across the EmberFLUX fabric uses post-quantum encryption. Your OT network is protected against the threats that exist today and the ones that don't exist yet.
EmberFLUX includes a remote device maintenance tunnel that gives your team secure access to every node in the fleet, from initial setup through ongoing maintenance, without creating an inbound attack surface.
The tunnel is outbound-only from the edge, on port 443. No port forwarding, no static IPs, no jump hosts. You reach the device; the device does not reach back.
Edge node
No open inbound ports, so there's nothing for the internet to reach.
The overlay
Checks identity, scopes access per session and per operator, and logs every session.
Your engineer
Reaches the node through the overlay, never through a hole in the firewall.
An encrypted tunnel from the edge to the platform, started from the edge on port 443.
Access is scoped per session and per operator.
Every remote maintenance session goes into the audit log.
Through NAT, firewalls, and cellular uplinks.
EmberFLUX is not an add-on product. It's part of every EmberNET deployment: EmberRTOS nodes carry it at the OS level, and the EmberNET Endpoint brings the same overlay to the Linux and Windows machines you already run. Security isn't configured later; it's the default state of every node from the moment it enrolls.
When you deploy EmberNET, you're not deploying an OS and then figuring out networking. Every enrolled node already knows about the other nodes in your deployment and talks to them securely from day one.
Talk to us about your network topology, and we'll show you how EmberFLUX fits.