Custom Software for Energy — Field Ops, Assets, and Compliance, Built to Respect the OT Boundary
Utility field operations, renewables asset management, oil-and-gas tooling, and compliance reporting — built by a US-based, founder-led team that keeps the IT and data layer cleanly separated from operational technology and scopes any SCADA-adjacent work case-by-case.
In energy, the IT and OT divide is a hard line. We respect it.
Energy software splits into two worlds with very different rules. There is operational technology — the SCADA systems, PLCs, RTUs, and safety-instrumented systems that actually run the grid, the plant, or the well. And there is information technology — the field-ops apps, asset registries, analytics, dashboards, and compliance reporting that the business runs on. The most important thing a responsible software firm can do in this sector is know which side it belongs on and never blur the line.
We build on the IT and data side, and we keep a clean boundary with operational technology. We do not write control logic for SCADA, PLCs, or safety systems — that is a specialized engineering discipline with safety and reliability stakes we will not pretend to own. When our software needs data that originates in OT, such as generation figures from a historian, we design a tightly controlled, segmentation-respecting data path rather than reaching into the control network. Any SCADA-adjacent work is scoped case-by-case, with explicit boundaries and your OT and security teams in the room.
Why energy is a special case
The IT-OT boundary is the defining constraint. Energy security frameworks insist on strong segmentation between corporate networks and the operational environment that runs critical infrastructure, and the consequences of getting it wrong range from a compliance violation to a safety incident. Software that casually bridges the two is a liability. We treat the boundary as sacred, build firmly on the IT side, and design any data exchange to honor the segmentation your architecture requires.
Compliance and the field environment compound it. NERC CIP governs the bulk electric system with strict cyber and access rules; FERC, EPA, and state agencies layer on environmental and market reporting; emissions and methane rules keep tightening. Meanwhile the work happens at remote substations, well pads, and turbine sites where connectivity is poor and devices take a beating, so field software has to work offline and sync reliably. A generic team underestimates the compliance weight and over-assumes the network — and may not even register the OT boundary as the hazard it is.
What we build for energy operators
- Field-operations apps — work orders, mobile data capture that works offline, inspections, and crew scheduling
- Asset and equipment management — registries, maintenance history, condition tracking, and GIS-aware mapping
- Renewables asset management — solar and wind production monitoring, portfolio dashboards, and PPA settlement
- Oil-and-gas tooling — field-data capture, production accounting, and land-and-lease management
- Compliance and regulatory reporting — emissions, environmental, and market-filing workflows with audit trails
- Analytics and historian reporting — reading approved OT data into IT-side dashboards across a controlled boundary
- Customer and billing tools — usage portals and billing for utilities and distributed-energy providers
Common energy projects we scope
- Offline-capable field-inspection app. A mobile app that works without connectivity at remote sites, captures structured inspection data and photos, enforces required fields, and syncs clean records to a central dashboard when the device is back online.
- Work-order and crew-scheduling system. Dispatch, work packages, asset linkage, crew and equipment scheduling, and completion capture — getting field crews accurate jobs and clean data back without paper.
- Renewables portfolio dashboard. Production monitoring across a solar or wind portfolio, performance-versus-expected analysis, downtime tracking, and PPA settlement, pulling generation data across a controlled boundary.
- Production accounting for oil and gas. Field-data capture, allocation, production accounting, run tickets, and the reporting upstream and midstream operators need for partners and regulators.
- Compliance and emissions reporting. Workflows for EPA, state, and market filings — data collection, validation, submission tracking, and an audit trail that survives a regulator's review.
- Asset registry with maintenance history. A single source of truth for equipment, maintenance history, warranty, inspection cycles, and condition, with GIS-aware mapping for geographically distributed assets.
- Controlled historian-to-IT reporting layer. Where appropriate and explicitly scoped, a tightly controlled data path that brings approved historian or sensor data into IT-side analytics without reaching into the control network.
- Customer usage and billing portal. A usage portal and billing system for a utility, co-op, or distributed-energy provider, with payments handled through a tokenized gateway.
Security and compliance considerations
IT-OT segmentation. This is the first principle. Our software lives on the IT side and never reaches into the control network. Where a data exchange with OT is genuinely needed, we design a one-way or tightly controlled, monitored path that respects the segmentation your security architecture mandates. We do not build anything that could become a pivot into operational technology.
NERC CIP. For utilities subject to NERC CIP, most CIP scope sits in the OT environment we deliberately stay out of. Where our IT-side software touches CIP-relevant data or evidence, we build the access controls, logging, and audit trails that support your compliance program. We are not your CIP compliance authority — we build software that helps you meet it.
Environmental and market reporting. EPA, state environmental agencies, FERC, and ISO and RTO market rules impose specific reporting obligations. We do not give legal or regulatory advice, but we build the data capture, validation, and audit trails your compliance and regulatory teams need to file with confidence.
Critical-infrastructure threat landscape. The energy sector is a top target for nation-state actors and ransomware groups, and incidents like the 2021 Colonial Pipeline attack showed how an IT-side compromise can cascade into operational shutdown. We harden the IT systems we build and map pentests to the techniques those adversaries use.
Field-device and access security. Field apps run on devices in the wild. We enforce strong authentication, encrypt data at rest on the device, and design sync so a lost or stolen device does not become a data breach.
Tech stack we recommend for energy
Next.js 16 on the App Router with React and TypeScript end-to-end for dashboards and back-office systems. For field apps, React Native or an offline-first progressive web app with a local store and conflict-aware sync so crews can work without connectivity. Postgres for the system of record, with a time-series store when production or sensor data volume demands it. Prisma or Drizzle as the type-safe ORM, and a mapping layer for GIS-aware asset and field views.
Background workers (Inngest or a self-hosted queue) handle sync reconciliation, report generation, and analytics rollups. Where an approved OT data path is in scope, it runs through a tightly controlled, monitored boundary — never a direct connection into the control network. Strong authentication and on-device encryption protect field data. Sentry plus a log aggregator for observability, with audit-grade logging where compliance requires it. The IT-side web tier deploys to Vercel or a hardened cloud environment matched to the operator's security posture; sensitive systems move to a controlled VPC.
Pricing transparency
Focused MVP
A single high-value IT-side workflow shipped clean — an offline-capable field-inspection app that captures structured data and photos at remote sites and syncs clean records to a dashboard. 4 to 8 weeks.
Production platform
A real operational system — work-order and asset management, a renewables portfolio dashboard, or a compliance-reporting workflow, with audit trails and field-device security. 10 to 16 weeks.
Platform with controlled data paths
A full field-ops or asset platform, potentially including a tightly scoped historian-to-IT reporting boundary, with the segmentation and audit posture critical-infrastructure software demands. 16 to 28 weeks with phased delivery.
Discovery is paid separately at $2,500 and is creditable against any full engagement. See the contact page for the full scoping flow, or the pricing page for engagement models.
Pitfalls we have seen
First, blurring the IT-OT boundary for convenience. A team wires an IT dashboard straight into the control network to grab a live value, and quietly creates a path an attacker could ride into operational technology. The convenience is never worth the risk. Approved data crosses the boundary through a controlled, monitored path or it does not cross at all.
Second, assuming connectivity. Field software designed for an office network fails at a substation or well pad where signal is intermittent. Offline-first is not a nice-to-have in energy field ops — it is the baseline, and bolting it on after the fact means rebuilding the data layer.
Third, underestimating compliance reporting. NERC CIP evidence, EPA and state environmental filings, and market reporting are specific and unforgiving, and a system that did not plan for the audit trail forces a painful retrofit. We build the validation and audit trail in from the start so a regulator's request is a query, not a scramble.
Why founder-led matters for energy
Energy is critical infrastructure, and the IT-OT boundary is not something you want an anonymous offshore contractor improvising around. You need a senior who understands why the segmentation exists, will say no to the convenient shortcut, and is accountable for the architecture. We are US-based and founder-led, and the person who designs your data paths is the person who can explain them to your security team and your regulators.
William Beltz writes or reviews every line, and personally owns the decisions about where our software sits relative to your operational technology. NDAs are mutual and signed before discovery. Source code lives in your GitHub organization, not ours. The handoff is documented for either ongoing collaboration or in-house ownership — your call.
MITRE ATT&CK pentests tied to energy-sector threat models
The energy sector is a top target for nation-state actors and ransomware groups, and the 2021 Colonial Pipeline incident showed how an IT-side compromise can force an operational shutdown. We run penetration tests on the IT systems we build and assess, mapped to the MITRE ATT&CK techniques those adversaries actually use, then deliver a heatmap of which techniques succeed, which get detected, and which get blocked.
For the field-ops apps, dashboards, and reporting systems on the IT side, web application penetration testing covers authentication, authorization, and the controlled data boundaries that separate IT from operational technology. We focus on the IT and application tier and coordinate with your OT security specialists on the operational environment. Every finding maps to ATT&CK technique IDs so your team knows what to alert on.
FAQs
Do you write software that controls grid or plant equipment?
No. We build the IT and data layer — field-ops apps, asset management, analytics, dashboards, and compliance reporting — kept cleanly separated from operational technology. We do not write control logic for SCADA, PLCs, RTUs, or safety systems. Any SCADA-adjacent work, like reading historian data into reporting, is scoped case-by-case with explicit boundaries and your OT and security teams in the room.
How do you handle the IT and OT boundary?
Carefully and explicitly. Our software lives on the IT side. When it needs data originating in OT, such as generation figures from a historian, we design a one-way or tightly controlled data path that respects your segmentation, rather than reaching into the control network.
What about NERC CIP and other energy compliance regimes?
For utilities subject to NERC CIP, most CIP scope sits in the OT environment we stay out of. Where our IT-side software touches CIP-relevant data or evidence, we build the access controls, logging, and audit trails to support your compliance team. We do not act as your CIP compliance authority.
Can you build field-operations software for a utility or service company?
Yes — a core build. Work-order management, mobile field apps that function offline in remote locations, asset tracking, inspection workflows, crew scheduling, and GIS-aware mapping, so crews get accurate work packages and clean data flows back even where connectivity is poor.
Do you work with renewables and oil-and-gas operators?
Yes. For renewables, asset-management and production-monitoring platforms, PPA and settlement tooling, and generation analytics. For oil and gas, field-data capture, production accounting, regulatory and emissions reporting, and land-and-lease tooling — all on the IT and data side, separate from control systems.
Why is energy software a special case?
The IT and OT divide is a hard security boundary responsible software must respect, the compliance regimes (NERC CIP, FERC, EPA and state reporting) are heavy and specific, and the field environment is harsh with remote sites and poor connectivity. A generic build mishandles all three, and the OT boundary mistakes can be dangerous.
What does a $25,000 energy build look like?
A focused MVP on the IT and data side — a mobile field-inspection app that works offline, captures structured data and photos at remote sites, and syncs clean records to a central dashboard when connectivity returns. Scoped tight, it ships in 4 to 8 weeks.
Related services
Custom Business Software
Field ops, asset management, and compliance tooling built on the IT and data side.
Mobile App Development
Offline-first field apps for remote substations, well pads, and turbine sites.
API Development
Controlled, segmentation-respecting data paths and integrations on the IT side.
Penetration Testing
MITRE ATT&CK-aligned testing of IT systems for critical-infrastructure threats.
Web App Pentest
Dashboards and reporting tools tested for authentication and boundary flaws.
DevOps Engineering
Hardened, auditable infrastructure matched to an energy operator's security posture.
Energy engineering & security reading
All postsWhat Is Penetration Testing? A Founder's Buyer Guide
What a pentest actually is, the five types you can buy, and what a real report looks like.
Read postBuild vs Buy Software: A 2026 Decision Framework
Three-year TCO math, the 80/20 rule, and a 12-question checklist.
Read postCustom CRM Development Guide
When custom CRM beats Salesforce, HubSpot, and Zoho — and what the build looks like.
Read post
Build energy software that respects the boundary.
Call William Beltz directly at (770) 652-1282 or book a 20-minute scope call. Mutual NDA signed before discovery. Founder-led from quote to handoff.