Designed to pass
an OT security review.
SypinIQ was built by a PI administrator who has to live with the firewall rules. This page covers what your IT and OT security teams will ask about.
One service in your network. Read-only to PI.
What's built in.
Microsoft Entra ID authentication
Every request carries a signed Entra ID token. Access can be open to any signed-in employee or limited to one Entra group, read from the token with no LDAP connection.
PI permissions stay in charge
SypinIQ reads through PI Web API with a read-only service account. Users can only ever see what PI allows.
Encrypted credentials
PI Web API credentials are stored encrypted with Windows DPAPI in the local configuration database.
HTTPS with your certificate
Drop in a certificate from your own PKI and the service switches to TLS on the same port.
Audit log
Every query is recorded with the signed-in user, action, target tag and result, filterable in the admin console.
No control-system access
SypinIQ never talks to the DCS and never opens PI's internal ports. It reads PI only through PI Web API on 443.
Traffic flows to plan for.
The flows you need depend on which products you license. Symbols-only deployments need none of the AI flows.
| Port | From | To | Purpose | Needed for |
|---|---|---|---|---|
| TCP 8443 | User workstations (browsers) | SypinIQ-Plus server | Assistant calls from PI Vision | SypinIQ-Pro |
| TCP 8443 | Microsoft 365 cloud | SypinIQ-Plus (published endpoint) | Copilot agent data calls | SypinIQ-X |
| TCP 443 | SypinIQ-Plus server | PI Web API | Read PI data | Always |
| TCP 443 | SypinIQ-Plus server | login.microsoftonline.com | Verify Entra ID tokens | Production sign-in |
| TCP 443 | SypinIQ-Plus server | Your AI provider | AI answers | SypinIQ-Pro |
| TCP 8443 | Admin workstation | SypinIQ-Plus server | Admin console | Always |
Three ways to install.
A · Single server
SypinIQ-Plus and the PI Vision assistant installed together on the PI Vision server. The simplest option for one site.
B · Split servers
SypinIQ-Plus on its own Windows server, with only the assistant files placed on PI Vision. The same installer handles both.
C · Copilot only
SypinIQ-Plus on a standalone server for SypinIQ-X. No PI Vision changes and no AI provider key, since Copilot supplies the AI.
What you need on site.
| Server | Windows Server 2019 or 2022 for SypinIQ-Plus (Windows 10 or 11 for evaluation) |
| PI | A reachable PI Web API endpoint on HTTPS and a read-only service account |
| PI Vision | PI Vision 2023 for the symbols and SypinIQ-Pro |
| Microsoft 365 | Microsoft 365 Copilot licenses for SypinIQ-X users, and an admin to upload the agent package |
| Entra ID | One app registration for production sign-in |
| AI provider | Azure OpenAI, OpenAI or Anthropic key, for SypinIQ-Pro only |
Send us your security questionnaire.
We answer vendor security and OT questionnaires directly, and can join a call with your IT, OT and cybersecurity teams.