Security

Designed to pass
an OT security review.

SypinIQ was built by a PI administrator who has to live with the firewall rules. This page covers what your IT and OT security teams will ask about.

Architecture

One service in your network. Read-only to PI.

USERS AND CLIENTSYOUR NETWORKPI Vision in the browserSypinIQ-Pro chat + symbolsMicrosoft 365 CopilotSypinIQ-X agent (Teams, Outlook)AI agents over MCPClaude, Copilot Studio, customAdmin workstationSypinIQ admin consoleTCP 8443 · TLSSypinIQ-Plus✓ Windows service✓ Entra ID sign-in✓ Encrypted credentials (DPAPI)✓ Audit log of every query✓ Offline, machine-bound licenseHTTPS 443PI Web APIread-only service accountPI Data ArchivePI AFOUTBOUND 443Entra ID token checkAI provider (Pro only)NEVER OPENS PI INTERNAL PORTS (5450, 5457)DEFAULT PORT 8443, CONFIGURABLE 1024–49151
Security controls

What's built in.

Microsoft Entra ID authentication

Every request carries a signed Entra ID token. Access can be open to any signed-in employee or limited to one Entra group, read from the token with no LDAP connection.

PI permissions stay in charge

SypinIQ reads through PI Web API with a read-only service account. Users can only ever see what PI allows.

Encrypted credentials

PI Web API credentials are stored encrypted with Windows DPAPI in the local configuration database.

HTTPS with your certificate

Drop in a certificate from your own PKI and the service switches to TLS on the same port.

Audit log

Every query is recorded with the signed-in user, action, target tag and result, filterable in the admin console.

No control-system access

SypinIQ never talks to the DCS and never opens PI's internal ports. It reads PI only through PI Web API on 443.

Firewall rules

Traffic flows to plan for.

The flows you need depend on which products you license. Symbols-only deployments need none of the AI flows.

PortFromToPurposeNeeded for
TCP 8443User workstations (browsers)SypinIQ-Plus serverAssistant calls from PI VisionSypinIQ-Pro
TCP 8443Microsoft 365 cloudSypinIQ-Plus (published endpoint)Copilot agent data callsSypinIQ-X
TCP 443SypinIQ-Plus serverPI Web APIRead PI dataAlways
TCP 443SypinIQ-Plus serverlogin.microsoftonline.comVerify Entra ID tokensProduction sign-in
TCP 443SypinIQ-Plus serverYour AI providerAI answersSypinIQ-Pro
TCP 8443Admin workstationSypinIQ-Plus serverAdmin consoleAlways
Deployment options

Three ways to install.

A · Single server

SypinIQ-Plus and the PI Vision assistant installed together on the PI Vision server. The simplest option for one site.

B · Split servers

SypinIQ-Plus on its own Windows server, with only the assistant files placed on PI Vision. The same installer handles both.

C · Copilot only

SypinIQ-Plus on a standalone server for SypinIQ-X. No PI Vision changes and no AI provider key, since Copilot supplies the AI.

Requirements

What you need on site.

ServerWindows Server 2019 or 2022 for SypinIQ-Plus (Windows 10 or 11 for evaluation)
PIA reachable PI Web API endpoint on HTTPS and a read-only service account
PI VisionPI Vision 2023 for the symbols and SypinIQ-Pro
Microsoft 365Microsoft 365 Copilot licenses for SypinIQ-X users, and an admin to upload the agent package
Entra IDOne app registration for production sign-in
AI providerAzure OpenAI, OpenAI or Anthropic key, for SypinIQ-Pro only

Send us your security questionnaire.

We answer vendor security and OT questionnaires directly, and can join a call with your IT, OT and cybersecurity teams.