What you see above

Reach every device in your plant — securely, from anywhere

Mirox gives your team a single, audited path to the real devices on site: a personal VPN for any tool, and an agentless browser proxy for device web interfaces. No more separate dial-ups for every plant.

Personal VPN

One personal profile for every plant

Each user issues a single personal certificate that reaches every plant network they are authorized for. The reachable routes are derived automatically from their roles — when access ends, the route disappears.

  • One personal certificate per user — issued in your profile, valid for every plant you are authorized for
  • Routes managed automatically from your roles and cooperations
  • Reach inverter, tracker, logger and control-cabinet UIs, SSH and Modbus tools
  • Rotate or revoke your certificate yourself, at any time
  • Dual-stack IPv6 reaches plants that have no usable public IPv4, and the entry points rate-limit scanning and probing

Your own VPN profile — issued in one click

The screen below is the VPN tab of a user profile in the real product. Everything you need is in it: issue, download, connect.

1

Issue the certificate

One click in your profile creates your personal WireGuard certificate and downloads the ready-to-use .conf file. It is shown exactly once — on issue and on every rotation.

2

Open it in WireGuard

Import the config file into the WireGuard client on your laptop. Nothing else to set up: no endpoints to type, no separate profile to maintain per plant.

3

Every authorized subnet is already routed

The reachable subnets follow your plant permissions — listed by organization, portfolio and plant, with a status per route. Two plants sharing the same LAN range are flagged as a conflict, and one switch decides which park that route points at. Nothing to request, nothing to enter by hand.

4

Stay in control

Recent connections show when, from where and with how much traffic your certificate was used. See something you don’t recognize? Rotate it — the old key stops working at the next sync.

Browser Proxy

Device web interfaces without a VPN client

Open the original web interface of an inverter or datalogger straight from your browser over a unique <id>.proxy.mirox.io address. No VPN client, no jump host, nothing to install — the tunnel to the device already exists through the on-site agent.

  • Agentless — just your Mirox login and a browser
  • The original device UI — the auto-detected default interface plus any extra web targets your plant’s technical team exposes
  • Two-factor is enforced at the gateway — without it the proxy button stays inert
  • Device logins live in an encrypted vault — stored once, rotated centrally, never handed out in plaintext, and every use is audited
  • Each web target can be enabled or disabled individually

VPN or Browser Proxy — when to use which

Personal VPNBrowser Proxy
Best forSSH, Modbus, scripts, any toolQuickly opening a device web UI
SetupInstall one VPN profileNothing — just a browser
From any machineYour own deviceAny browser with your login
Security gateYour personal certificate, routes from your permissionsTwo-factor required, every session in the audit log

Audited and compliant by default

Remote access is one of the tasks Mirox handles for you — and it is built to stand up to scrutiny.

Full audit trail

Every VPN and proxy session lands in one chronological feed: who connected, which device, over which channel, how long and how much data — with secret query parameters redacted.

KRITIS & NIS2 ready

Tamper-resistant records retained for at least 730 days, visible only to the plant operator.

Role-based access

Access follows the same organization, job-role and cooperation permissions as the rest of the platform.

Read-only by design

Mirox never writes to your devices — access is for diagnostics and configuration through the device’s own login.

A summary of every session

On top of the raw connection record, each access session gets a short written summary of what actually happened on the device — a configuration change on an inverter rather than just a timestamp and a byte count. A review reads like a logbook.

Reachable when it matters

The VPN entry points run in several independent regions with more than one server each: if one becomes unavailable, your connection re-attaches to a healthy entry point, and the on-site agents supervise and restart themselves.

Frequently asked questions

Can I open an inverter web UI without installing anything?

Yes. The agentless browser proxy opens the device’s original web interface over a unique *.proxy.mirox.io URL using only your Mirox login.

Is the remote access KRITIS- and NIS2-compliant?

Every VPN and proxy session is captured in a tamper-resistant audit trail retained for at least 730 days, accessible only to the plant operator.

What happens to access when a colleague leaves?

Access follows permissions. When a role or cooperation ends, the route disappears automatically and open connections drop at the next sync.

Do I need a separate VPN profile for each plant?

No. One personal certificate reaches every plant you are authorized for. Its configuration is shown once — when the certificate is issued and on every rotation — and you can rotate or revoke it yourself at any time.

Ready to Simplify Your Operations?

See how Mirox can bring your team together and save you money. Free pilot available — connect your first plant at no cost.

welcome@mirox.de
+49 (0) 40 76619191
Hamburg, Germany

60%

Cost Savings1

<24h

To Connect2

60 Days

Free Trial3