Fundamentum: the Governance Layer for Connected Infrastructure

Connecting devices is the easy part. Governing them — deciding who may act on them, which updates they accept and how they change over a service life of 10 to 25 years — is where large deployments succeed or stall. Fundamentum is designed as that governance layer: the control plane between your physical infrastructure and the applications that run on it.

Where Fundamentum sits in your stack

LayerWhat it doesExamples
ApplicationsShows information and lets people act on itDashboards, reports, AI assistants
WorkflowsOrganizes the work of operations teamsAsset management, work orders, field service
Connectivity and dataAnswers “can this message be delivered?”Message brokers, data pipelines, cloud IoT services
Governance control plane — FundamentumAnswers “should this action be allowed?”Device identity, roles and permissions, update authorization, device state, audit evidence
Physical infrastructureDoes the work in the fieldDevices, gateways, networks

Applications change every few years; the infrastructure stays. The governance layer is what keeps your rules consistent while everything above it evolves.

The problem: rules that emerge everywhere

Every large deployment ends up making the same decisions: device identities, user permissions, lifecycle states, update policies, compliance requirements, who may read which data. When nothing owns those decisions, each system makes its own — the cloud service, each application, the field-service tool, the mobile app, the integration scripts.

  • Permissions drift apart between systems, and nobody can say which one is right.
  • An update approved in one tool is pushed from another.
  • Answering an auditor means rebuilding a history from several logs.
  • Replacing an application or a cloud provider means re-creating the rules it held.

Governance either emerges everywhere, independently, or it is defined once, as a layer of its own. Fundamentum is built for the second option: one authority that every application, cloud service and team consults.

One question, answered in one place

Who is authorized to act, on which assets, under which policy — and with what evidence?

Fundamentum brings the answers together under a single model:

  • Device identity — each device is provisioned and authenticated before it connects (MQTTS, HTTPS, LoRaWAN).
  • People and organizations — roles and permissions with OAuth 2.0 and OpenID Connect, across sites, teams and clients.
  • Updates and configuration — firmware updates and device configuration go through the platform, not through side channels.
  • Device state — the current state of each device, from commissioning onward, in one place.
  • Evidence — because actions go through one layer, the answers an auditor or a client asks for come from one place instead of being reconstructed.

What it changes for an operator

  • Lower cybersecurity risk — one identity and permission model instead of several that drift apart.
  • Safer updates — firmware and configuration changes follow one policy across the fleet, which reduces the risk of costly field interventions after a failed update.
  • Easier compliance — audit and procurement questions are answered from one place, backed by Groupe Vectanor’s SOC 2 Type II audit, whose scope includes Fundamentum.
  • Freedom to change applications — dashboards, work-order systems or analytics tools can be replaced without re-creating the rules that govern the devices.
  • Faster deployments — identity, permissions, updates and device management already exist: your team builds the product, not the plumbing.

Why governance matters more as AI makes software cheaper

AI-assisted development is making application software much faster and cheaper to build: a dashboard, a workflow or an integration no longer takes a large team. What AI does not provide is operational authority — a trusted identity for every device, update decisions you can defend, evidence that stands up to an audit, and continuity over assets that stay in service for decades. Those still take architecture and production experience, and they become the durable part of a connected-infrastructure project as the software around them gets easier to replace.

Built for long-lived infrastructure

Street lights, parking sensors, chargers and grid equipment often stay in service 10 to 25 years — longer than the applications, the cloud contracts and often the teams that installed them. Governance has to outlive all three.

Fundamentum manages hundreds of thousands of devices in production, in deployments that include smart street lighting control, smart parking management, EV energy management, energy management and control, and industrial asset tracking. The same governance question applies to utilities, water networks, transportation systems and other critical facilities.

Your data can be stored in Canada, or in the region you require, with residency written into your agreement, and Fundamentum can also be installed on your own infrastructure, anywhere. Availability is covered by a 99.9% SLA.

Frequently asked questions

What is an IoT governance control plane?

It is the layer between connected devices and the applications that use them. It decides who may act on which devices, which actions are permitted, which firmware and configurations are trusted, and how changes roll out across a fleet. A connectivity service answers “can this message be delivered?”; a governance control plane answers “should this action be allowed?”

How is Fundamentum different from device management software or a cloud IoT service?

Device management is one of the things Fundamentum governs, not the whole of it. Fundamentum keeps device identity, permissions, update decisions and device state under one model that every application and team shares, instead of each tool keeping its own rules. It can also interface with the cloud services you already use.

Does Fundamentum replace our applications?

No. Your dashboards, work-order systems and analytics tools stay; they rely on Fundamentum for identity, permissions and device state. That is what lets you replace an application later without re-creating the rules that govern your devices.

Why does governance matter more as AI makes software easier to build?

Because AI lowers the cost of building applications, not the cost of governing infrastructure. Trusted device identities, defensible update decisions, audit evidence and continuity over decades still take architecture and production history, and they stay in place when the applications around them are rebuilt.

Which kinds of infrastructure need a governance layer?

Any operator of distributed, long-lived assets: smart cities and street lighting, parking, EV charging, energy and utilities, water networks, transportation, industrial operations and OEM connected products. Fundamentum already manages hundreds of thousands of devices in production, including smart street lighting, parking, EV energy management and industrial asset tracking.

Where is Fundamentum’s data stored, and how is it secured?

Your data can be stored in Canada, or in the region you require, and that residency can be written into your agreement; Fundamentum can also be installed on your own infrastructure, anywhere. Groupe Vectanor, Amotus’ parent company, holds a SOC 2 Type II report issued by RCGT and dated April 15, 2026, and Fundamentum is within the scope of that audit.

Talk to us about your fleet

Tell us how many devices you operate, which systems govern them today and what you need to prove to auditors or clients. More answers in the IoT & Fundamentum FAQ.

Need more expertise?

Create your customized, connected solution

Let's Discuss Your Project