D6 Labs Brand Logo

Why Choose D6 Labs?

We built our platform from the ground up with security, reliability, and simplicity as core design principles.

Differentiator #1

Secure By Design

Across the publicly reported attacks on US water systems, nobody defeated sophisticated protections. Attackers found controllers reachable from the public internet, used passwords that were still the factory default or shared across a crew, and logged in through consumer remote-access software with no second factor.

Every one of those is a property of the architecture as much as of the utility. You can harden a conventional system a long way — and you should — but hardening cannot change what the system fundamentally is. Our platform removes the property instead of patching the instance:

  • Outbound-Only Connectivity

    Field devices open connections outward to the platform and keep them open. Nothing at your utility listens for inbound connections — no port to forward, no service waiting for a login attempt, no address that answers a probe. A scanner sweeping the internet finds nothing to talk to.

  • Encryption On By Default

    Traffic between your sites and the platform travels inside TLS, and the message itself is encrypted a second time with a per-device key. It cannot be switched off. That is the direct answer to unencrypted radio, where somebody within a few miles can listen to your telemetry and send commands your controllers accept as genuine.

  • Certificates, Not Passwords

    Each device holds a certificate issued when it is deployed. It is never typed, never spoken, and never travels in a form anybody could reuse. There are no default device passwords to leave unchanged, and revoking access for a departing employee is an administrative action that takes effect immediately — not a trip to every site.

  • No Local Attack Surface

    The device offers nothing to connect to locally: no USB, no Bluetooth, no Wi-Fi, no programming port. Cut the padlock at a remote site and open the panel, and there is still nothing to plug a laptop into. It is the only control that does not depend on the lock holding.

  • Per-Person Access, Fully Logged

    Everyone gets their own login with role-based permissions — shared crew accounts are not needed to make it work. Every action is written to an audit trail, so you can answer who changed what, and when.

Nothing Listening
Nothing To Plug Into
Nothing To Steal And Reuse

Your Audit Findings, Answered

The problems a security audit typically turns up at a water system, and what each one becomes under this architecture.

Equipment reachable from the internet
Nothing listens, so there is nothing to find by scanning
Default passwords on controllers or radios
No device passwords to leave at their default
One shared login the whole crew uses
Per-person credentials; shared logins are not needed to make it work
Access still active for somebody who left
Revoke that person's credential; device credentials are unaffected
Remote-access software with no second factor
No inbound remote-access tool; access is through the platform, per person
Unencrypted radio between sites
Encrypted cellular; interception yields nothing usable
A panel anyone could open and plug into
Nothing to plug into; the lock stops being the only control
Equipment that no longer receives firmware updates
Supported equipment that updates itself, remotely, as fixes are released
Nobody has tested a backup in years
Configuration and programs are retained centrally and continuously

Don't know which of these apply to you? That is what the self-audit workbook below is for.

What still needs you. No architecture removes the need to do a few things well: phishing awareness, your business network and billing systems, physical protection of the equipment, and an emergency plan that lets you run manually. We would rather say so than pretend otherwise.

Free Security Guides

Two workbooks for water systems, written to be useful whether or not you ever buy anything from us. Neither one names a product — including ours.

Start here

Water System Security Self-Audit

A guided walkthrough that finds the problems which cause real incidents: how people log in from outside, the passwords on your equipment, and what protects your unmanned sites. You do it yourself, at your own pace, with no special tools and no IT background. Everything in it is looking, reading and writing down — never probing or changing — so nothing in it can take your plant down.

  • For Operators, superintendents, managers
  • Takes 6–10 hours, spread over several days
  • Includes Per-site inspection sheets and a prioritized fix list
Download PDF

Then this

Upgrading Security: Moving to Cloud-Based SCADA

Some audit findings cannot be fixed with a setting change. This guide is about those. It explains what cloud SCADA actually is, why hardening has a ceiling, and how to specify and buy a system so that what you get is genuinely secure rather than merely modern — including the ten requirements to write into your bid and the red flags to watch for in the answers.

  • For Anyone building the case, going to market, or living with it after
  • Covers The security case, costs, objections, and taking it to your board
  • Includes Requirements checklist, proposal scoring sheet, cost worksheet
Download PDF

Both documents are free to use, copy and share within your utility and with other water systems.

Differentiator #2

Hot-Swap Capability

Traditional SCADA systems require a programmer to configure each device. When a device fails, you need to schedule a site visit, bring a laptop, and spend hours reconfiguring the replacement.

Our platform eliminates this problem entirely:

  • Configuration Stored in Cloud

    All device configuration is stored securely in the cloud. The field device is simply a connector between your equipment and the cloud.

  • Automatic Configuration

    Install a new device, power it on, and it automatically downloads its configuration from the cloud. No laptop required. No programming.

  • Minutes, Not Hours

    Lightning strike? Equipment failure? Any trained operator can swap a device and have the site back online in minutes.

Swap Device
Power On
Done

Differentiator #3

Lower Total Cost

Traditional SCADA requires purchasing PLCs, RTUs, radios, and software from multiple vendors, then paying an integrator to make it all work together.

Our integrated approach dramatically reduces total cost:

  • All-In-One Solution

    Hardware, software, connectivity, and support all from one vendor. No integrators needed. No finger-pointing when something goes wrong.

  • 10-Year Warranty

    Every device comes with a 10-year warranty. If it fails, we replace it. No questions asked. No service contracts required.

  • 20-Year Availability Guarantee

    We guarantee parts availability for 20 years. Your investment is protected for the long term.

Traditional D6 Labs

Lower Total Cost of Ownership

Differentiator #4

Built & Supported in the USA

When you call D6 Labs, you're talking to the engineers who design and build our products. We don't outsource manufacturing. We don't outsource support.

  • US Manufacturing

    Every device is designed and built by our team in Oklahoma City. Quality control at every step.

  • Direct Support

    Call us and talk to an engineer who understands your system. No call centers. No scripts.

  • Fast Replacement

    We keep stock on all parts. Need a replacement? It ships same day.

Made in USA

D6 Labs vs. Traditional SCADA

Feature D6 Labs Traditional
Security Architecture Outbound-Only Open Ports/VPNs
Device Credentials Revocable Certificates Shared Passwords
Device Replacement Hot-Swap Reprogramming
Warranty 10 Years 1-3 Years
Integration Required None Expensive
Support Direct from Engineers Multiple Vendors
Data Storage 10 Years Included Limited/Extra Cost

Ready to See the Difference?

Talk to our team about your specific application and see how D6 Labs can help.

Call 1-844-365-8647
Logo badge of D6 Labs Made In USA

Built & Supported in the USA

All D6 Labs' products are designed and built by our team of engineers and technicians in the heartland of the USA. We do not outsource any part of our business so when you need support, you are talking directly to the people who design and build our product. We maintain stock on all parts so a replacement is just a phone call away.

Request Information

Tell us about your project and we'll get back to you promptly.