TEST MODE — keys, files and assessments of this session are test data and not intended for operation.
Browser storage is not available for this file — client, keys and open request apply only until closing. Before closing, use "Save project state" under Settings, or open the file in Chrome or Edge.
Your plant · Customer Board Cloud 1.0.0 · Overview local, encrypted storage, analysis via the expert team
Cloud storage active — storage: ablage.wodaiq.vencly.com · keys: only with you · overview computed locally · this file contains no assessment logic
Overview
Data import
Analysis
Recommendations
Settings
Info
Your plant at a glance
Traffic-light status per well and pump, computed entirely on this computer. Causes, trends and confidence come back from the expert team as a file via the Analysis tab — which is why this file deliberately contains no assessment logic and no thresholds.
Normal
Watch
Critical
N/A — no data available
Average efficiency
–
Plant score
– / 100
No data loaded yet.0 wells recorded. Add further wells via the "Data import" tab.
📄
No data loaded yet
This board deliberately contains no pre-entered values. Upload a file here — Excel, CSV, ZRXP, WaterML, PI export or the template; several files at once are fine. Known formats then only need "Calculate"; for everything else a mapping assistant checks the file together with you. Add further wells later via the "Data import" tab.
Data import
Download the standard template
WodaIQ_Import_Template.xlsx , fill it in and upload it here. Wells with a master-data entry but no time-series sheet of their own appear as N/A in the overview.
Well
Well status
Pump status (submersible)
Ø efficiency
Scoring
Data basis and processing
Measured quantities used per well: flow rate Q, wellhead pressure, depth to water (together they give the head H), power input P, current I, frequency f, operating water level. Pump status: hydraulic efficiency η = 9.81·Q·H⁄(3600·P); without depth to water, a percentile rank of the specific consumption within the fleet is used instead. Well status: margin to the limit water level (optional master datum); without it, a percentile rank of the drawdown within the fleet — additionally raised by one level when the operating water level keeps falling over time (indication of iron incrustation/clogging; for the pump status a falling efficiency only enters the analysis, not the status colour itself, see knowledge base). Formula factors and status thresholds can be changed under Settings.
Not available and therefore not part of the assessment: well construction/borehole log and the following master data —
Installation depth (submersible pump)
Installation depth of the pressure sensor
Pump type / submersible pump type
Rated flow rate
Rated head
Rated power
Rated current / rated voltage
Frequency f (setpoint)
NPSH value of the submersible pump
Installation depth of the screen sections
Both statuses can be overridden manually at any time (dropdown) and commented on (💬 symbol, layer 2) — stored client-side only, never transmitted. Wells without any time series in a file appear as N/A rather than with invented values — see the "Data import" tab to add further wells of the plant.
The application processes all data locally; only ciphertext goes to the storage, and only when you click. Contains real operating data — treat as confidential.
Data import
Add further well data or read in a new export. Wells already loaded are updated, new ones are added.
No data loaded yet — the first import takes place directly in the overview.
Manual readings
For wells without a control system: the meter readings that are taken anyway are enough — energy meter in kWh, water meter in m³, monthly. Optionally the depth to water (dip meter), the wellhead pressure (gauge), the hour meter, diesel litres for plants without an energy meter and the pump's install date. If you prefer to keep it in Excel: WodaIQ_Reading_Sheet.xlsx
, fill it in and upload it above.
Causes, trends and patterns per well
The assessment does not take place in this file. You prepare your data, send the file to the expert team and load the response here — only then do figures, trends, causes and confidence appear. Your well names, water levels and absolute values stay on this computer throughout.
🔒
Analysis — no assessment loaded yet
You can now prepare your data for the expert team or load a response you have already received. You see everything that leaves the file beforehand and can deselect any figure.
🔒
Layer 3 · Optimize & Consult
Automatically derived recommendations and measure management are part of an additional consulting package. Talk to us — or upgrade in Settings for demonstration purposes.
Recommendations per well
Your assessments entered manually in layer 2, collected in one place.
Export findings & recommendations
Exports the current status per well, the layer-2 findings and your manually entered recommendations as a CSV file. The PDF export can be chosen per level — independent of the demo level currently active in Settings, so that e.g. a pure level-1 report can be produced for the customer while level 3 is used internally.
Storage (cloud edition)
Your project file can additionally be kept encrypted in the storage. Encryption happens on this computer with the data key from your key file (.wodaid); the storage receives only ciphertext and holds no key. The local project file remains the primary copy — without a network the board keeps working in full. No reset: Whoever loses both the key file and the emergency sheet has lost the data in the storage for good.
Storage ablage.wodaiq.vencly.com · no key file loaded yet
1 · Key file
Create generates your customer key pair and a random data key and saves both as .wodaid, protected by the passphrase (at least 12 characters, preferably several words). The emergency sheet with the recovery code then appears — print it and keep it in the safe.
2 · Signing in to the storage
On first contact the invitation code binds your client to the key in the key file. After that the key file is enough: signing in is a signature, not a password. A different key is accepted only after release by the operator.
3 · Project in the storage
Save encrypts the whole state (like the project file, without the private key) with its own object key per version and stores it under your client; every version is bound to client, path and version. Load fetches the current version and replaces the state in this browser.
4 · Expert cycle via the storage
Instead of e-mail: the request created in the Analysis tab (.wodaiqex) is placed in the storage, the response (.wodaiqim) is fetched from there. Both files are already end-to-end encrypted and signed — the storage is only the transport.
5 · Recovery (recovery code)
Store backup saves a copy of the key file in the storage, encrypted with a key derived from the recovery code on the emergency sheet. Whoever loses the key file types in the 24 words, fetches the copy and receives a new .wodaid with a new passphrase. The operator cannot help here — it has neither code nor key.
Project file (.wodaiq)
The whole state in one file that belongs to you: wells with time series, settings, notes, comments, status assessments, mapping profiles, manual readings — and the file exchange details. Without a project file everything is gone when the browser is closed — the storage (card above) is an encrypted second copy, not a substitute. With a password the file is encrypted (AES-256-GCM) and then also contains your private customer key; without a password the key stays out.
Your licence level
Determines which content is visible in Overview, Analysis and Recommendations. The level below can be chosen freely for demonstration purposes — in a real delivery it would be fixed by the contract booked.
Current: Level 1 · Inform
(demo upgrade — not a real order)
Formulas
Affects the layer-1 assessment (overview). The detail values in layer 2 keep using the standard formula until the next board build.
Head H = depth to water ×
+ pressure ×
Efficiency η — green from
%
yellow from
%
Specific-capacity trend (analysis) — conspicuous from
%
Decline of the operating water level over the period; indication of iron incrustation/clogging
Well status (water-level margin)
Margin = limit water level − operating water level (limit water level as an optional master datum in the import template). ≤ 0 is always red. Without a limit water level on record the status falls back to a percentile rank within the fleet — a relative, not a robust statement.
Margin — yellow up to
m
Percentile fallback
worst/best %
Pump-status fallback (without efficiency)
Applies only when no depth to water is available and therefore no physical efficiency can be computed.
Method
Percentile fallback
worst/best %
Relative to the best well — yellow from
+ %
red from
+ %
Score prioritisation
Weight of well status
%
Weight of pump status
%
Ranking priority
Exchange with the expert team
The client number is assigned by the expert team when the contract is signed. It is in every file you create; your plant or well name is in none.
Client number
Format: M- and four digits
Test mode
Uses the expert team's test key and marks all displays as TEST
Your key pair
The key pair is created in this browser and leaves it only as the public part in the .wodaiqex. The expert team encrypts the response for you with it. Save it via "Save project state" — without the private part no response can be read any more.
Identifier (kid): no key yet
Test mode only: load the customer test key pair from werkzeuge/format-vertrag/testschluessel/ to open the supplied test files. Select the four files kunde_test_enc.pem, kunde_test_enc.pub.b64, kunde_test_sig.pem and kunde_test_sig.pub.b64 together. They apply to this session only and are not saved.
Deliveries and open request
Mapping of wells to pseudonyms
This table stays on this computer. The expert team sees only the right-hand column.
Project state
Keys, mapping table, delivery counter, open request and response have been saved since Customer Board 1.6.0 with the Project file (.wodaiq) at the top of this tab. Old project-state files (.json) can still be loaded there.
How WodaIQ works with your data
The process in seven steps. Everything left of the dashed line happens on your computer; only two files cross the line, both encrypted — sent by you by e-mail or, in the cloud edition, placed in and fetched from the storage.
What leaves your computer — and what does not
In the file to the expert team
Stays on your computer
One pseudonym per well (e.g. P-3fa91c), day 1 to n instead of calendar dates, specific energy demand in kWh/m³, all other quantities only as a ratio to their own reference value (flow rate, pressure, power, current, frequency, drawdown), runtime share, switching operations per day, age class of the pump, events as a type without date. Your client number.
Well names and their mapping to the pseudonyms, absolute values (m³/h, kW, A, bar), water levels in metres, coordinates, borehole logs, rated values and pump types, calendar dates, comments, the raw data itself. The preview shows every row before each dispatch; any figure can be deselected.
The expert team knows you as a contracting party and hence your client number. What the expert team does not know: which pseudonym is which well, where it is and how much it pumps. The response comes back with the same pseudonyms; the translation into your well names happens only here.
The encryption procedure
Component
Procedure
Purpose
File content
AES-256-GCM
Encryption with integrity protection; a new random key and a new random IV per file
Key transport
RSA-OAEP, 3072 Bit, SHA-256
The file key is encrypted for the recipient's public key — only the expert team can open your request, only you the response
Signature
ECDSA P-256, SHA-256
Every file is signed by the sender. A modified or foreign file is rejected before any processing
Binding of header data
AAD in AES-GCM
Client, delivery and request ID are bound to the encrypted content; an envelope cannot be rewritten for another client
Key generation
WebCrypto in the browser
Your key pair is created in this browser and leaves it only as the public part. No server, no third-party library
When loading a response, the board checks in a fixed order: file form, format, signature, binding of the header data, client, freshness (delivery and request ID, no response already loaded), decryption, content against the whitelist of the format contract, pseudonyms. It stops at the first error, states the reason and saves nothing. The source code of this file is fully readable and contains no assessment logic.
Cloud edition: what this file says over the network
This edition of the customer board talks to exactly one endpoint,
ablage.wodaiq.vencly.com (data centre in Germany), and only when you trigger it. The Content Security Policy in the document allows no other host. The offline edition without any network contact remains the standard edition.
Leaves the computer
Stays with you
Ciphertext of the project file (AES-256-GCM, one object key per version derived via HKDF from your data key), requests and responses of the expert cycle (encrypted anyway), a copy of the key file encrypted with the recovery code
Key file, data key, passphrase, recovery code, all plaintext: well names, measured values, notes, mappings
Metadata: client number, identifier of your signature key, time, size and number of objects, your IP address during the connection (not stored in the service access log)
Everything else — there is no telemetry, no usage statistics, no reloading
The operator of the plant is the sole key holder: the service holds no key, cannot read content — not even on request — and cannot reset anything (no reset). Every object is bound to client, path and version; a swapped or altered object is rejected on loading. Deleting in the storage removes all versions; whoever also destroys the key file renders the service backups worthless too (crypto-shredding). The procedures follow the recommendations of BSI TR-02102-1 with documented deviations (PBKDF2 instead of Argon2id, P-256 instead of Brainpool); the service holds no certification.
Why this holds up for a critical-infrastructure operator
Exactly one network contact, ciphertext only. This edition talks exclusively to ablage.wodaiq.vencly.com and only when you click; your control system is untouched. What leaves is encrypted on your computer; only you hold the key. This can be checked in the source code and is enforced by the Content Security Policy in the document (this host only, nothing else).
Data minimisation instead of trust. What is transmitted is worthless to third parties without your mapping table: no locations, no capacities, no names. This lowers the protection requirement of the data path in your risk analysis.
Procedures following BSI recommendations. Algorithms and key lengths follow the recommendations of the German BSI technical guideline TR-02102-1 (cryptographic mechanisms, 2026 edition): AES-256, RSA from 3000 bits, EC P-256, SHA-256.
Supply chain under NIS2. The expert team acts towards you as a supplier with data access. Purpose limitation, deletion periods, incident notification to you within 12 hours, audit rights and the place of processing are agreed by contract. The analysis board runs within the expert team's security management.
Cyber Resilience Act. This file is a product with digital elements; it carries a version number (see header) and there is a reporting process for vulnerabilities. Please address security notices to the office named in the contract.
For context, so that nothing is overstated: There is no certification of this product by the BSI and no ISO 27001 certification of the analysis board. "Compliant for critical infrastructure" is not a seal of approval but the result of your own protection-requirement assessment for this data path — the information on this page is the basis for it and can be verified against the source code and the format contract.
🔒 Layer 2 · Analyze
The cause interpretation behind this status — trends, patterns and the data basis of the assessment in detail — is part of Layer 2 · Analyze and of the paid analysis package. See the "Analysis" tab.