The problem enterprise security
products were never designed to solve.
Pumping stations. Electricity substations. Gas governors. Tens of thousands of them — unmanned, power-constrained, running legacy OT protocols with no authentication or encryption — now connected to IP networks. Enterprise firewalls don't fit in DIN-rail cabinets. They can't inspect a Modbus command. And they require on-site IT staff that doesn't exist.
The sites
No IT staff. No server room. No mains-reliable power. Cabinets designed for RTUs, not rack-mount equipment.
The protocols
Modbus, DNP3, IEC 60870-5-104 have no native security. A standard firewall is blind to the commands passing through it.
The deadline
DWI e-CAF: March 2028. Ofgem RIIO: April 2028. Gas networks: in force now (since April 2026). These are licence conditions, not recommendations. Scotland, Wales and other sectors run their own timelines.
Further reading
What we do
A hardened gateway at each site.
One console for all of them.
Isolate your OT assets
Every customer gets its own network segment on the platform, and every site is isolated, with its own encrypted tunnel and credentials. OT equipment is never directly reachable from the internet — even if a credential is stolen.
Inspect OT protocol commands
Deep packet inspection at the application layer. Remote commands can be inspected and logged before they reach your equipment, with commands outside policy blocked and unusual behaviour flagged.
Manage thousands of sites centrally
One console. Remote software updates with automatic rollback, automated certificate rotation, health monitoring. No routine site visits after installation.
Generate compliance evidence automatically
CAF-aligned evidence generated continuously. Network segmentation proof, access logs, audit trails. Ready before your regulator asks.
Under the hood
Security-first from the ground up.
The gateway is rugged industrial hardware — DIN-rail mounted, with 4G where needed — built to sit unattended in a roadside cabinet for years. Everything below is what keeps it, and your sites, secure.
Your sites can't be reached from the internet
Connections only ever go outward — outbound-only, no inbound ports, no inbound attack surface.
Nothing is trusted by default
Zero-trust architecture across every site, device and connection.
Every device proves what it is before it is trusted
Hardware-backed mTLS device authentication.
Protected today against the code-breaking computers of the next decade
Post-quantum encryption (ML-KEM-768).
Certificates renew themselves — no expiry outages, no site visits
Automated certificate rotation from a private certificate authority.
Run from a UK data centre, not the public cloud
Platform hosted in the UK; off-site backups encrypted with keys only Exhale holds.
A dropped connection never opens a way in
Fails closed: if the link drops, remote access to the site stops. Your own controllers keep running the process as normal.
Built to the standards your regulator assesses you against
Designed to NCSC CAF 4.0 and IEC 62443 principles.
Working with us
How a pilot works.
We're actively taking on first water sector pilots in 2026. Here's what the process looks like. The risk sits with us. You evaluate.
A 30-minute conversation
Tell us about your estate — number of sites, current setup, timeline pressure. We'll tell you honestly whether we're a fit right now. No pitch deck.
We start with a small pilot
We start small: a bench trial, then a handful of sites of your choice. We pre-provision every gateway before it ships — field engineers connect power and Ethernet, the gateway calls home and self-configures. Typically under 30 minutes per site.
You see your CAF evidence
Within 8 weeks of deployment, we run a compliance evidence workshop with your team. You see exactly what the platform generates for your regulator’s assessment — before committing to anything.
You decide
If it works, we discuss full rollout on commercial terms. If it doesn't, you've invested a few hours of your team's time and learned something useful. We'd rather earn your confidence than lock you in.
Indicative pricing
Enough to put a number in your budget submission.
Gateway hardware
from £800
per site, one-time — includes provisioning
Managed platform
from £600
per site per year — security, fleet management, compliance evidence
Indicative. Volume pricing applies at scale. We'll send you a detailed budget estimate within 24 hours of a conversation — including total cost for your estate, phased rollout options, and a like-for-like comparison with alternatives.
Who we are
Two founders. Thirty years
of building infrastructure systems.

Gareth Williams
Co-Founder & CEO
25 years in technology leadership. Co-founded YellowDog — the world's largest distributed computing platform, coordinating unreliable compute nodes across multiple providers for major hedge funds. The architecture directly transfers: coordinating thousands of unreliable edge gateways is the same problem. Previously VP Product at Arieso through its acquisition by JDSU (now Viavi Solutions).

Simon Ponsford
Co-Founder & CTO
30+ years in distributed systems and real-time infrastructure. Previously held SC and DV security clearance; has architected UK secure government projects including the Police National Computer. Founder of Tivarri, providing UK sovereign data centre facilities to banks, hedge funds, and energy sector operators. 30+ technology patents.
"We're a small team. That means when you talk to Exhale, you talk to the people who built it — not an account manager reading from a slide deck. We'll tell you what we can do, what we can't yet, and what we'd recommend."
Gareth Williams, Co-Founder
Get in touch
The shortest path
to a conversation.
Tell us about your estate. We'll be straight with you about whether we're the right fit, what a pilot looks like, and what it costs. No pressure, no pipeline.

Gareth Williams
Co-Founder & CEO
Sector briefs (PDF)
Securing your battery assets Securing your pumping stationsExhale Systems Limited · Bristol, UK · Co. no. 16808856