Supervisory security system

spine

Fire · Voice evacuation · Intrusion · Access control · CCTV · Emergency lighting

All your security systems in one picture. Spine connects fire alarm, intrusion alarm, access control, cameras and emergency lighting, whatever the make, and shows everything on the building's own floor plans.

A top layer over existing panels. Per-make drivers dial out to a site server, every point gets a stable id and every command is confirmed by read-back from the panel.

14makes and channels
< 1 sfrom button press to confirmation from the panel
481 of 481addresses placed automatically on a real drawing
10 yearsof security updates per version
How it works

From existing systems to a live floor plan

The customer does not need to replace any panels. Spine reads what is already there, builds the site by itself and makes it controllable from one place.

Connect

A small piece of software is connected to each existing panel or access control system. It contacts Spine outbound, so the customer's network never has to be opened inbound.

Create points automatically

Every detector, door and camera is created from the panel's own export file or directly from the system. Nobody types in thousands of addresses by hand.

Place automatically

Spine reads the addresses on the fire drawing and puts the symbols exactly where the consultant drew them.

Monitor and control

Alarms, faults and disablements show up directly on the floor plan. The operator can reset, disable and open doors, and the panel confirms every action.

Built on top, replaces nothing

The customer's panels keep doing their job. Spine provides the overview and the link between them.

Never in the life-safety path

The fire alarm panel keeps its own path to the alarm receiving centre. Spine is a tool for operations and overview, not alarm transmission.

The panel has the final say

A command only counts as done when the panel itself shows the new state.

Unknown is never shown as green

If Spine does not know the state of a point, it says unknown. A silent connection raises an alarm, not reassurance.

Data stays with the customer

No telemetry and no inbound remote access. Spine works entirely without internet.

AI reads, people decide

An optional AI interface can answer questions but never control anything.

Modules

Three surfaces, one site

Spine is made up of modules that are licensed separately. A module that is not included does not appear at all. All modules share the same floor plans, the same journal and the same permissions.

Map

The hub. From the map of Sweden down to a single detector on one floor.

  • Map, site, building, floor and symbol in one click
  • Real PDF drawings with live symbols on top
  • Alarms that show the way to the right place
  • 3D view with the floors stacked
  • Calendar for scheduled disablement, conditions and reports
  • Test mode, test plan and test report
licence module: karta

People

One register of everyone who holds a card, across all access control systems at once.

  • The same person in ARX, RCO and Brivo appears as one person
  • Profiles, for example "Finance", that grant the right doors in every system
  • Preview before anything is sent
  • Block a lost card everywhere at once
  • Nightly check that the systems show what was decided
licence module: iam

CCTV

Cameras linked to what they actually see.

  • Video wall from 1×1 to 4×4 with sequencing
  • The camera covering an alarm moves to the top and is marked red
  • A still image is captured when the alarm arrives and is attached to the notification
  • Integrates with the existing video system, no new VMS
licence module: cctv

Add-on: Analysis

licence module: analys

Ask an AI assistant questions about the site, for example which detectors have not been tested this year. The assistant can only read. Without the module there is no AI interface at all, so the customer can show that no AI touches their data.

Alarms

The alarm shows the way there

A fire alarm takes the operator from the map, via the site and the building, to the detector in alarm on the floor plan. The journey takes a couple of seconds and can be cancelled with one click.

01The map shows where the alarm is02The site and the building light up red03The floor plan opens04The detector pulses, the camera is shown alongside

Screen recording from the demo site Kvarteret Björken, which ships with Spine.

Acknowledge and take ownership

Acknowledge means you have seen the alarm. Handle means you take responsibility for it. If the person handling it loses the connection, the alarm sounds again, so no alarm is ever left without an owner.

Acknowledge"Seen". Can require a statement or a checklist.
HandleOwnership. Dies with the operator's socket, and then the alarm sounds again. Handover only to a live, authorised session.
Alarm inactiveSilences only your own screen, 30 min default, max 8 h. Notifications are still sent.
StationsLocked view and timeout. A wall screen can acknowledge but not handle.
JournalAppend-only JSONL per day, compressed after one week

Notifications to the right person

Each user chooses which alarms, which buildings and which times should trigger a notification, and how. An image from the camera or the floor plan is attached.

Auto-create & auto-place

The drawing and the export already know where everything is

The consultant's fire drawing and the panel's export describe the same building. Spine reads both and builds the site by itself. What used to take days of manual work takes minutes.

Where the points come from

The panel's export file

Spine reads the export file from the panel's programming tool and creates every detector, section and control output. Works before the panel is even connected.

EFO · SecuriFire · Consilium · ARX
Directly from the system

Spine asks the system itself what it contains and creates the points when the driver connects.

Hedengren · RCO · Brivo · Eagle Eye · WAVE
The installer's map

For IO units and building services, the installer writes a simple list of names and addresses.

Generic Modbus
  1. Import the export

    The points are created with the same id the panel will report later. They show grey as planned until the panel responds.

    Id: <driver>/<kind>/<address>. At handover the panel's list applies, and everything is journalled.

  2. Upload the drawing

    The fire drawing as a PDF, the same file that is printed and handed to the fire and rescue service.

    Vector PDF with a text layer is required for auto-placement. Scanned sheets are displayed and placed by hand. No OCR. Page 1 only.

  3. Find the addresses

    Spine finds every address text on the drawing, for example 01.001 or 70/12, and places the symbol where the consultant drew the detector.

    EFO ^\d{1,2}\.\d{2,3}$, SecuriFire ^\d{1,4}/\d{1,3}$. The symbol is placed 1.6 label heights below the label centre. Rotated sheets are handled.

  4. Find the sections

    Large section numbers in circles get Spine's section symbol on top of the consultant's circle.

    Conditions: at least twice the size of the address label, more than 8 % from the edge, and the section exists in the driver.

  5. Check against the export

    Every address must exist in the panel's export. Spine never guesses from names.

    No confidence score, only exact matches. The same address in several places becomes several devices with the same id.

  6. Review and adjust

    Everything can be moved, rotated and scaled in the same editor. A new drawing only moves what Spine placed itself, and hand-placed symbols are left untouched.

OFFICE 2.14 STAIRWELL B 70 70/1270/1370/14 1.6 h section 70 · exists in the panel

Simplified drawing. 70/12 means section 70, address 12. The dashed circle is Spine's section symbol.

481/481addresses on the sheet found in the export
526address texts read on one sheet
1 648detectors, zero deviations from the export
60 fpssmooth zoom on large A1 sheets
69symbols to SB 20.1
0guesses from device names

Measured on a real sheet from a SecuriFire installation.

Symbols, states & commands

What Spine sees and what Spine can do

The symbols follow the Swedish standard SB 20.1, so the drawing looks the way the fire and rescue service is used to. The catalogue has 69 symbols. The colour shows the state and the shape shows what equipment it is.

One symbol, many states

Detector health: spot dirty detectors before they cause false alarms

Modern detectors measure all the time. Spine reads the values, stores a trend per detector and lists the dirtiest first, so service staff can replace the right detector in time.

MakeValuesStatus
Schneider Esmi / EFOContamination 0–100 %, raw value 0–255in service
Hedengren FirescapeContamination, monthly reportbuilt
Hedengren NeptoluxBattery capacity in minutes, temperaturebuilt
ConsiliumSmoke as % of alarm level, temperature, contaminationbuilt
Securiton SecuriFireSmoke, temperature, CO, contamination, airflow in aspirating pipesplanned
01.014
78 %
02.103
61 %
01.007
44 %
03.021
23 %

Example. Step curve per detector, change over the last 30 days.

Spine does not judge the values itself. Limits are only set where the manufacturer specifies them. Otherwise the value is shown neutrally.

Planning & testing

The whole year's testing, planned and proven

Fire alarms must be tested regularly, and not just the detectors. Fans, lifts, doors and dampers controlled by the fire alarm must also work. Spine plans the year, disables what must not activate during the test and writes the report while the technician walks round.

1. Plan the year in quarters

Spine suggests a Q1–Q4 split that covers the whole site in one year. The suggestion goes floor by floor, splits large floors and evens out the quarters. You can also choose yourself:

  • Select symbols directly on the floor planand choose "add to test plan"
  • Choose from a list: building, floor, devicedevices already tested are marked
  • Add functionsfans, lifts, doors and dampers controlled by the fire alarm
  • Specify what should be disabledfor example alarm transmission and evacuation control, so the test does not start an evacuation
  • Write manual steps and notesfor things done on site

Q1 2027

Building A · Floor 142 devices · 3 functions
2 disabled
Building A · Floor 238 devices

Q2 2027

Building A · Floor 3 part 1/240 devices · 2 functions
1 disabled

Q3 2027

Building A · Floor 3 part 2/239 devices
Garage24 devices · 4 functions
3 disabled

Q4 2027

Building B61 devices · 2 functions

Example. The bar shows how much of the floor has been tested.

2. Carry out the test

  1. Start from the plan

    Choose how long the round should last (default 2 hours, max 12) and whether notifications should be sent during the test.

  2. Spine disables

    What the plan specifies is disabled with the reason "Testing" and automatic re-enable. Everything is journalled.

  3. Everyone can see it is a test

    A yellow-striped banner is shown on every screen.

  4. The technician tests

    Every activation is marked as a test in the report. A real fire alarm still sounds and must be acknowledged as usual.

  5. Spine re-enables

    When the round ends or the time runs out, what Spine disabled is re-enabled, and only that.

Test mode marks, it does not silence

An alarm during a test sounds, escalates and is recorded in the journal as an alarm. The test is written as a separate line alongside. This means testing can never hide a real fire.

Scopesite:, building: or floor:, any discipline
CheckThe server checks every minute, journal line when the time has run out
JournalKind test, "Test mode ON from plan {name}"
DisablementIf there is no write path the step is marked "manual", and the round starts anyway
API/api/provplan, /forslag, /:id/starta, /api/provning/markera

3. Three ways to "tested"

panelThe panel's test mode

The panel itself reports that the device has been tested, for example Hedengren's walk test.

testLive activation during a round

The device activated while it was in a test round. Also works for makes without a test mode.

manualMarked by hand

Mark one or more devices as tested, with date, note and name. Works without a round in progress.

4. Report and coverage

Tested

With method, time and who.

No activation

Was in the round but never responded. Reveals a faulty detector.

Not tested

Shown as a dashed circle on the floor plan until it has been tested.

Each floor gets an "n of m tested" bar. The report is downloaded as CSV or PDF per calendar year or rolling 12 months, and older periods can be opened afterwards.

Integrations

The makes Spine talks to

Each make has its own package that speaks that system's language. Click a make to see what Spine can do with it.

MakeStatusShows statesControlsCreates pointsAuto-placementMeasured values
YesBuilt, being tested against a real sitePlannedNot applicable
Architecture

One way out of the customer network

Spine is installed on the customer's premises, on an ordinary Windows server. The small piece of software at each panel dials out to the server. That is why no ports need to be opened inbound to the panels' network, which most IT departments require.

The same code runs on one machine or split. Only the driver configuration differs. On-prem is primary and Spine can run entirely without internet.

Every command is confirmed by the panel

before = trueAlready done

The state was already the requested one.

before ≠ true · after = trueConfirmed

The panel shows the new state. Measured at 400–640 ms against a real fire alarm panel 400 km away.

after ≠ trueFailed

The state never changed. The operator sees it at once.

Technical

The north link

Transportws:// or wss://, the driver initiates, full resync on every reconnect
AuthenticationShared token, compared in constant time. An allowlist of known drivers can be switched on.
Key pinningnorth.pin: pinned, first, off, plaintext
Public addressesUnencrypted ws:// is refused towards public addresses
Rate per socketDriver 2 000 frames/s (burst 8 000), client 100/s, 600 ms CPU/s, max 16 MiB per frame
WatchdogRedials after 100 s without ping
Desired stateThe calendar says what should apply. A driver that has been down gets the command when it comes back up.
Technical

Close codes

CodeCause
4001Frame before hello
4002The frame threw an exception
4003A live id already exists
4008Rate exceeded
// the point id is the whole contract
arx-1/door/17   efo-1/p0/01.001   cons-1/u2/10/10
// the agent's remote control of drivers
agentCmd { reqId, op, what, by, args } → agentResult
Server requirements

The right server for the site

Spine needs no database and no special hardware. An ordinary virtual Windows server is enough. The recommendations below include headroom. The measurements come from a load rig on 2 cores.

S

One building

School, office, smaller property

Points
2 000
Clients
5
Cores
2
Memory
4 GB
Disk
40 GB SSD

idle 1 % CPU · 94 MB · 200 events in 3 ms

M

Several buildings

Campus, shopping centre, property company

Points
5 000
Clients
20
Cores
2
Memory
8 GB
Disk
60 GB SSD

idle 3 % · 134 MB, peak 216 MB · connect 0.5 s

L

Large site

Hospital, airport, larger industry

Points
20 000
Clients
100
Cores
4
Memory
16 GB
Disk
120 GB SSD
Network
1 Gbit

idle 17 % · peak 518 MB · 100 clients in 6.6 s · storm 1 000: p50 1.1 s

XL

Portfolio

Municipality or region with many sites

Points
50 000
Clients
100
Cores
8
Memory
32 GB
Disk
250 GB SSD

idle 22 % · peak 829 MB · connect 16 s

Sized together with us.

Applies to all sizes

Operating systemWindows Server x64. Runs as a Windows service.
DatabaseNone. A backup is a copy of a folder.
Driver machineAny Windows computer on the panel's network, about 100 MB memory per driver. Needs no licence of its own.
ClientsBrowser on a computer, wall screen or phone
JournalAbout 150 MB for 13 months at 2 000 events per day
RedundancyThrough virtualisation: the server moves between hosts. Active/active clustering is not yet supported.
Technical

Ports and operation

18080Operator interface, the drivers connect here
18081Analysis (MCP), loopback by default, 0 = off
18078Status page, read only
18079Control port, loopback only
Memory~100 MB + 10 MB per 1 000 points at idle, double at peak
In service2 415 points, 7 drivers: 145 MB flat over 8 h, event loop p95 27 ms
PackagesServer ~66 MB with embedded Node 24, driver ~43 MB
Testing & validation

Every fix proven, every release checked

A system that controls fire alarms and doors must not guess. That is why the code is tested in several layers, against real panels and against the vendors' own specifications.

2 200+automated checks in the largest test suites
128+builds in the register, traceable to every customer
6real systems tested: fire, access control, cloud
0known vulnerabilities in the dependencies at build
  • Against real panels

    Disable and enable on a real fire alarm panel, doors in real ARX, RCO and Brivo systems, Hedengren against the cloud.

  • All the way to the screen

    Tests run from the panel's file through driver and server all the way to a real browser.

  • Vendor specifications as simulators

    Before a panel is on site, the driver is tested against a simulator built from the vendor's protocol description.

  • Makes are kept apart

    A dedicated test stops the build if something that belongs to only one make ends up in the shared code.

  • Load and capacity

    A rig builds sites of up to 50 000 points and 100 clients and measures every release.

  • Security reviews

    Recurring reviews of the server, the drivers, the web interface and the packages. An external penetration test is planned for autumn 2026.

Rules that apply to all code

  • Every fix gets a testThe bug is reintroduced on purpose and the test must fail. Only then does the fix count.
  • Unknown is never greenTests require that anything that could not be read is shown as unknown, never as normal.
  • Load is measured, not assumedHow hard Spine polls a panel is measured on the wire.
  • The build stops on vulnerabilitiesCritical and high findings in dependencies stop the build.
  • Every package is signedA package with the wrong signature is never installed.
  • The manual is tested against the codeThe Swedish and English versions must not drift apart.
Technical · assertions per test suite
CRA & GDPR

Built for the regulations from the start

The EU Cyber Resilience Act sets requirements for all products with digital elements. The General Data Protection Regulation governs how personal data in access control systems is handled. Spine is built for both and produces the documentation itself.

Cyber Resilience Act EU 2024/2847

The regulation requires secure development, vulnerability handling and security updates throughout the product's lifetime.

  • Bill of materials in every packageAn SBOM in CycloneDX format lists all components
  • Signed updatesTwo keys, checked on the machine doing the install
  • 10 years of security updatesThe support period is stated in the product
  • Updates are never blocked by the licenceAn expired licence does not stop a security update
  • Contact route for vulnerabilitiessecurity.txt and SECURITY.md in every installation
  • CRA documentation from the installationVersion, build number, keys and encryption state per connection
11 Sep 2026Reporting of actively exploited vulnerabilities
11 Dec 2027Full application and CE marking

Own assessment: important product class I (Annex III p. 1). No formal ruling yet. Remaining: Annex VII documentation, declaration, TLS by default.

GDPR EU 2016/679

The customer is the data controller. Spine helps the customer keep things in order and show what is held.

  • Everything stays with the customerNo telemetry. Spine never contacts the vendor on its own.
  • Only what is neededName, department, contact details, card and validity period. Personal identity numbers are not stored.
  • Retention limits by defaultJournal 400 days, deregistered people 90 days, images 90 days. All configurable.
  • A person card per individualShows everything Spine holds about a person, making subject access requests easier
  • Passwords and PINs are protectedPasswords are stored only as a hash. A PIN is never shown afterwards.
  • Input for the record of processingSpine generates Article 30 documentation in Swedish and English

Secrets for the vendor systems are encrypted with DPAPI. The journal cannot be edited. Corrections are made with a new line. Data processor only under a support agreement with access.

Sign-in and permissions

Two-factor sign-inCode in app, SMS code, passkey and backup codes
RolesPer discipline: read, operate, technician, administrator
Per buildingThe operator only sees the buildings they are authorised for
ManagementSeparate day-to-day operation (floor plans, symbols) from system responsibility
LicenceWorks fully offline. Moves with a migration, but cannot be cloned.
Technical

Security in detail

Accountsscrypt, HttpOnly session, lockout after 5 failures, TOTP RFC 6238
LicenceEd25519, 2 of 3 machine identifiers. An expired licence blocks commands, never monitoring.
PackagesEd25519, SBOM CycloneDX, npm audit stops the build, 4 runtime dependencies
VersionsSide by side. Three crashes within 3 min start the previous version.
CSPscript-src 'self', object-src 'none'
MCPJSON-RPC 2.0, seven read-only tools, every call is journalled
Roadmap

What exists and what is coming

Spine is developed at a fast pace with frequent releases. The current version is 0.139.0.

Available

  • Auto-created points and auto-placement
  • Calendar, conditions and scheduled disablement
  • Test mode and Q1–Q4 test plan
  • People across several access control systems
  • Notifications with images: push, Teams, SMS, email
  • 3D view of the building
  • Detector health with trend

In progress

  • Hanwha Wisenet WAVE
  • Securiton SecuriFire and Consilium
  • IO units via Modbus
  • RCS messages with buttons
  • Buy time during alarm delay

Planned

  • Reconciliation report between export, symbols and drawing
  • Notification-only accounts
  • AD and Entra ID
  • BACnet, Milestone, ONVIF
  • Voice evacuation
  • Axema, Partnersec, Traka Web
Technical · drivers in the test installation 30 Sep 2026
anlaggningen

Sites, buildings, floors and panels

drivrutinernas_lage

Connections, versions and load per path

punkternas_lage

Points and states with filters

las_journal

The journal as structured rows

provningstackning

Tested and untested points

avvikelser

Decided versus actual permissions

underlag

GDPR, CRA and operations documentation