IT & Security

Key technical details to consider when implementing SiteWorx

SiteWorx Technical Requirements

SiteWorx is an Internet of Things (IoT) cloud platform that helps large buildings save energy and money. Through a customizable and easily expandable network of smart sensors and meters, SiteWorx provides advanced monitoring and controls for nearly every system and machine that consumes resources – water, air, gas, and electricity. Key capabilities include advanced lighting control, occupancy based HVAC and load controls, alerts when environmental readings go out of range, and monitoring of the energy and dollars saved across every site, globally.

System Architecture

  1. IoT Edge Device Layer

    Electrical contractors install SiteWorx IoT devices onto equipment, like lights, temperature sensors, and electrical panels. These sensors form a low-power, low-bandwidth 802.15.4 wireless mesh network that doesn’t interfere with 802.11 (Wifi) traffic. Each device communicates with a SiteWorx cloud gateway, designated at the time of installation/commissioning.

  2. Connection Layer

    SiteWorx cloud gateways are installed near the center of the devices they control. The cloud gateways are the interface between the sensors onsite and the SiteWorx cloud. The gateways are connected to the internet using the facility’s network via a CAT6 PoE connection.

  3. Cloud Layer

    Communication occurs between the gateways onsite and the SiteWorx cloud using a persistent web socket that only requires outbound firewall access. SiteWorx encrypts data in motion with 128-bit AES TLS 1.3 encryption or better, and data at rest with 256-bit AES encryption.

SiteWorx IT network architecture diagram

Multi-Tiered Security

  • Cloud-Level Security

    Data at rest is secured with 256-bit AES encryption, and backed-up daily. SiteWorx supports major SSO authentication providers, and natively allows customer admins to delegate role-based access rights by user.

  • Connection-Level Security

    Gateways utilize an outbound-only authentication request to establish a persistent websocket for bi-directional communication. The connection is protected by TLS 1.3 encryption and 3rd party penetration validation.

  • Device-Level Security

    Gateways contain tamper-proof, hardware-based cryptography chips to ensure connection security. There is no onsite access or maintenance mode.

Configuration & Data

  • Cloud-based

    SiteWorx runs in the cloud, on Amazon Web Services (AWS) – there are no on-site servers to maintain or fail.

  • Data control

    Customers retain ownership of their data. Customers approve all user account requests, including resellers and installers. Site configuration and user interaction data is available only to SiteWorx Support and Engineering teams, and is never shared with other organizations and never used for sales and marketing purposes.

  • Audit

    System access and changes are tracked for audit purposes. Backups occur daily.

SiteWorx Wireless Mesh Network

  • Based on IEEE 802.15.4 standard

    IEEE 802.15.4 is a low-power, low-bandwidth communications protocol that minimizes the time the radio transmitter is on, specifically designed to limit interference with 802.11 (Wifi) traffic.

  • Resilient mesh network

    The SiteWorx mesh is self-healing and line-of-sight – if a node in the network is removed, the message will take the next best route to its destination. It is designed to require minimal power (1mW) with a sight range of about 50 ft (15 m).

  • Secure from the start

    Communication on the SiteWorx wireless mesh network can be encrypted using AES-128 during commissioning – just ask your installer.

Network and Gateway Requirements

  • Physical connection requirements

    Gateways should each be connected directly back to a PoE network switch using CAT6 wiring, with runs under 328ft (100m). They require standard Type 1 PoE (802.3af) power.

  • Connection requirements

    Gateways require reliable high-speed internet, and utilize an average of <10kB/s in bandwidth. Cellular modem connections are not supported. By default, gateways are configured for DHCP IP addressing, but may be configured with static IP addresses during installation and commissioning.

  • Connection specifications

    • 443 (HTTPS – TCP): Secure HTTP, used for SiteWorx Core services
    • 8444 (WAMP – TCP): Web Application Messaging Protocol, used for SiteWorx Core services
    • 6514 (syslog over TLS – TCP): Secure Syslog used for SiteWorx logging and diagnostics
    • 123 (NTP – UDP): Network Time Protocol, used for synchronizing time between sensors and SiteWorx *may use internal server
    • 53 (DNS-TCP): Domain Name Server, used for DNS lookup *may use internal server

Frequently Asked Questions

Ready to see SiteWorx in your facility?

Talk with our team about a demo, or get started with a reseller near you.