// ARCHITECTURE

From signal to widget, with nobody reading along.

Your source seals the data before it leaves your network. The relay only passes on sealed envelopes; they are opened on the device alone. This is how it works, and how very different sources end up in one view.

Three stops, one rule: the content key never travels through the relay.

Source

Your data, your key

Your software, a Node-RED flow or a script builds a small document with the tiles and seals it. The key for it is made on your side.

  • One document per view, to a fixed schema
  • The status is decided here, the app recomputes nothing
  • The content key never reaches the relay
Envelope
Relay

A letterbox, not a postman

The relay keeps only the last envelope per view, cannot open it, and wakes the devices by push when the source asks for it in the envelope.

  • Stores sealed envelopes only
  • Wakes the devices without sending data
  • Revokes devices, renews secrets
Never holds the content key
Wake-up and fetch
Device

Pair by QR, open locally

The app scans a QR code, fetches the envelope and opens it on the device. Home and lock screen, on iPhone StandBy too.

  • Pairing by QR code, no VPN
  • The push carries a signal only, never data
  • The last state stays visible in a dead zone
// SOURCES

Many sources, one language.

Andon doesn't care where the information comes from. Every source delivers a document in the same format, and the app shows it the same way everywhere.

01

Any source

If your software can encrypt and send over HTTPS, it sends by itself. If not, something next to it fetches the numbers, such as the Node-RED package or a script.

02

Outbound only

The source sends; nobody calls in. No open ports, no VPN. Even a network closed to the outside needs just one outbound HTTPS connection.

03

Many sources, one view

Every upload replaces the whole view. So several sources are merged in front of it, for example by the Node-RED package with MQTT, PLC and database in one flow. Or each source gets its own view, and the app shows them all.

04

One picture for everything

Machine, server or heating: the same tile kinds, the same four statuses. The source decides what is good or bad; the app shows it the same way everywhere.

05

A silent source turns the view grey

When nothing new arrives, the app turns the view grey. When a source has failed, nothing is faked.

// SECURITY

Four keys, cleanly separated.

Each key does exactly one thing. None can be derived from another.

01

Write secret

Lets your source send envelopes and manage the view. Nothing else.

Held bysource
02

Invite secret

Sits in the QR code and pairs devices. Renewed automatically on every revocation.

Held byQR code
03

Device secret

Identifies a paired device on fetch. Lives in the keychain and goes to the relay only.

Held bykeychain
04

Content key

Opens the envelope. Created on your side and travels only by QR code to your devices. Never reaches the relay.

Held bysourceQR codedevice
// ENVELOPE

What the relay sees.

The relay sees which view an envelope is for, which key version sealed it, whether it should wake the devices, how big it is and when it arrives. It never sees the content, and any change to the content, the view or the key version shows when it is opened.

// PUSH

A push only says: there is something new.

The push is a wake-up call, not a message. The device then fetches the envelope again and opens it itself.

01

Your source decides

Devices are woken only when your source asks for it, usually on a status change. A temperature drifting from 80.2 to 80.3 wakes nobody. The widget picks it up on its next refresh by itself.

02

Easy on the battery

At most one wake-up per view and minute; a missed one is caught up. A flickering status still costs battery, so a threshold with some slack belongs in the source.

03

Nothing for Apple to read

The wake-up goes through Apple's push service. All Apple learns is that there is something new, never what.

// PAIRING

Treat the QR code like a password.

The pairing link carries everything a device needs: relay address, view, invite secret and content key. That makes it as confidential as a password. Show it only to people who may see the view.

When a device is revoked, the relay renews the invite in the same step. Old QR codes no longer pair new devices; paired ones stay. A photographed code only becomes worthless once you generate a new content key: your source gets it, there is a new QR code, and every device scans again.

  1. 01The app validates the link. If anything is off, it stops without contacting the relay.
  2. 02The first time, it registers and receives its device secret. That goes into the keychain.
  3. 03It redeems the invite. The device name travels encrypted; the relay does not see it.
  4. 04It fetches the envelope and opens it with the key from the QR code.
// RELAY

Kept small, on purpose.

Operated by SMARTR.solutions

You need no infrastructure. We run the relay, hosted in Germany, reachable by HTTPS and REST.

Only the last envelope

At most one envelope per view, up to 256 KiB, sealed. Every upload replaces the last. No history, no archive.

30 days without upload

A view that receives nothing for 30 days is deleted, one that was never used after just 10. What nobody feeds does not lie around.

Start with one number.

One tile is enough to start. In the configurator you build your first view and send it to your device with a test envelope, before your data source is even ready. For the connection, your IT finds everything on the developer page.