Building Automation Services

BMS Cloud Integration

Most BMS-to-cloud projects fail for one of three reasons. The data arrives without context, so nobody can use it. The connection drops and the gap is never backfilled, so the dataset cannot be trusted. Or the security model requires inbound access to the OT network, and IT refuses — correctly. We design around all three.

Discuss your architecture

How We Build It

Edge Gateway

An edge gateway sits alongside the BMS, reads points over BACnet, Modbus or the supervisory platform's own interface, and publishes outbound only. No inbound ports, no VPN into the control network, no remote desktop left running.

MQTT v5 Transport

We publish over MQTT v5 with TLS. Version 5 matters here — shared subscriptions let you scale consumers without duplicating messages, message expiry stops stale telemetry arriving after a reconnection and corrupting your history, topic aliasing reduces bandwidth on high-frequency estates, and negative acknowledgements tell you why a publish was rejected instead of silently dropping it.

Store and Forward

The gateway buffers locally when the link drops and backfills on reconnection, in order, with original timestamps. This is the difference between a dataset you can bill from and one you can only browse.

Payload Design

Payloads are structured and tagged at the edge, not left as bare numeric values to be reassembled in the cloud. Where UDMI or a client schema applies, payloads are validated against it before publishing.

Cloud Landing

We integrate to Google Cloud, Microsoft Azure and AWS, and to self-hosted stacks where the client prefers to keep data on their own infrastructure. Time-series storage in InfluxDB, TimescaleDB or the platform's native service, with retention and downsampling policies set deliberately rather than left at default.

Writeback, Where It Is Wanted

Closed-loop control from the cloud is possible and occasionally appropriate. It is also the fastest way to create a serious incident. Where writeback is in scope we implement it with explicit point-level permissions, value clamping, command logging and a local override that always wins. Where it is not needed, we make the link read-only and say so in the design document.

Security

  • Outbound-only connections from the OT network
  • TLS with certificate-based authentication and a documented renewal process, because expired certificates are the single most common cause of silent data loss
  • Credential storage outside the application configuration
  • Network segmentation between control, gateway and enterprise networks
  • Least-privilege access at the broker and at the cloud endpoint
  • Full audit logging of configuration changes and any command written back

Deliverables

  • Integration architecture document with data flow and network diagram
  • Point mapping specification from source system to published topic
  • Gateway configuration, backed up and version-controlled
  • Security design note for the client's IT team to review
  • Connectivity and data-integrity test records, including a simulated outage and backfill test
  • Runbook covering restart, certificate renewal and fault diagnosis

Tell us about the building.

Send us the specification, the point list, or just a description of what is not working. You will get a reply from an engineer within one working day.