Trust Boundaries tab
- Last UpdatedJul 23, 2026
- 3 minute read
The Trust Boundaries tab enables you to configure trust boundaries for AVEVA products, ensuring secure communication between nodes.

The Trust Boundaries tab provides configuration options for Trust Boundary Mode , where you can defines the trust boundary settings for communication in System Platform 2026 and future versions. By default, it supports backward compatibility with earlier versions of the System Platform.
Note: The Trust Boundaries tab is available only when the local node is configured as a System Management Server (SMS). It is not available when the node is not an SMS or is configured to use a remote SMS.
Upgrade scenario
After upgrading from a legacy System Platform version (for example, System Platform 2023 R2 SP1) to SP 2026, the SMS plugin status will change to Warning and must be reconfigured. Similarly, the FIDP plugin status will also change to Warning and must be reconfigured.

Trust Boundaries
To enable secure communication between services within AVEVA products, those services must be able to authenticate one another. This is achieved by configuring a trust boundary, which allows supported AVEVA services within the same boundary to communicate securely.
The configuration of a trust boundary allows you to easily enable communications between a broader range of AVEVA products to participate in secure communication within the same boundary.
Trust Boundary Mode
-
Universal Mode: When Universal Mode is selected, the trust boundary is maintained by the System Management Server. All AVEVA applications connected to the same System Management Server are considered part of the same trust boundary.
This eliminates the need to explicitly pair System Platform galaxies, enabling all galaxies in the system to be automatically paired. Universal Mode allows communication between AVEVA products through Platform Common Services (PCS) internal communication protocols, including scenarios that extend beyond System Platform, for example, communication between System Platform and Plant SCADA.
Universal Mode also enables communication between products within the System Platform bundle without requiring a platform to be deployed on the machine. For instance, Historian or InTouch can retrieve data directly from a Communication Driver Pack when both products are connected to the same System Management Server.
-
Classic Mode: When Classic Mode is selected, the trust boundary is maintained by the System Platform Galaxy Repository, consistent with System Platform 2023 R2 SP1 P04 and earlier versions. This mode allows customers using multi‑galaxy communication to explicitly control how galaxies are paired, enabling tighter access control for galaxies that require stricter security, similar to previous System Platform releases.
Note: When switching between Universal Mode and Classic Mode, a warning dialog is displayed to inform you of communication disruptions that may occur between AVEVA applications during the transition. Review the message and select OK to continue.