PRATA
Technical specs

A single-tenant appliance with zero inbound ports.

The full specification is in the table below. Both source documents are on this page, readable in the browser or as PDFs.

0Inbound ports
1Tenant per installation
TLSEnd to end
On-premData residency
7 daysDeposit to running
01Specification

The whole thing on one screen.

Deployment

ModelSingle-tenant, on-premises, client-owned hardware
SharingNo data, compute or credential store shared between installations
LicensePerpetual on the hardware. No activation server, no entitlement check
Vendor dependencyNone for operation. The appliance never contacts the vendor for authorization
Cloud componentsNone for application logic or data. A managed edge provides encrypted transport and authentication only

Hardware and OS

ProcessorQuad-core 64-bit Arm Cortex-A76 at 2.4 GHz, ARM64
Memory8 GB LPDDR4X
Storage512 GB NVMe SSD over PCIe 2.0, chosen over removable flash for write endurance
Operating systemDebian-based Linux, 64-bit, headless, no desktop environment
Service isolationDiscrete containers under a supervised runtime, no shared filesystem namespace
DatabasePostgreSQL, local to the appliance, not exposed beyond the container network
Restart policyEvery service recovers unattended after power loss or reboot
AdministrationCommand line over SSH. No graphical console on any network

Site

PowerOne 120V grounded outlet, 27W maximum, on a line-interactive UPS
UPS outletsTwo battery-backed: one for the appliance, one for the router
FootprintUnder 1 sq ft including the UPS, 2 in. clearance for airflow
Staff accessNone required. Headless, with no monitor, keyboard or peripheral
InstallationComplete within seven days of deposit, typically one visit

Network

Inbound portsNone. No port forwarding, no NAT rule, no DMZ, no inbound exception
Public IPNot required. Functions behind CGNAT
ConnectionWired gigabit, untagged access port, static DHCP reservation on the appliance MAC
TransportQUIC over UDP 7844 primary, HTTP/2 over TCP 7844 fallback, four concurrent edge connections
Egress requiredUDP and TCP 7844, TCP 443, DNS 53, NTP 123. A firewall blocking all ingress and permitting only these is complete
DiscoverabilityNot resolvable by external IP or port scanning
DPITLS interception on the tunnel prevents it establishing. The appliance requires an exemption
Uplink minimum25 Mbps down, 5 Mbps up. Upstream governs, since the appliance transmits more than it receives
Client-side infrastructureNo reverse proxy, VPN, dynamic DNS or certificate automation

Access and privilege

Enforcement pointNetwork edge, upstream of the appliance. Unauthenticated requests are never forwarded
Policy scopePer named individual, not a shared credential or a network range
Application layerIndependent session, role and permission model behind the edge policy. Two layers must be satisfied
RevocationImmediate at the edge, regardless of application session state
Operator privilegeApplication interface only. No host, container, database or credential access, at any point in the lifecycle
Credential storeEncrypted, inside the automation layer, behind separate authentication restricted to vendor identities
EncryptionTLS appliance to edge, TLS edge to end user. Certificates issued and renewed at the edge

Data

ResidencyClient premises, on the client-owned appliance
ScopeCustomer records, review history, message content, campaign, scheduling and analytics data
Egress of dataOnly when a workflow you configured transmits it to a service you connected
Vendor-side copyNone. No central store, no replica
TelemetryNone. No usage reporting, no analytics beacon, no diagnostic upload
MonetizationNone. Not aggregated, resold, licensed or used for model training
PortabilityA standard relational database on hardware you own, readable with standard tooling
02Documents

Both documents, in full.

Technical Overview & Security Posture

Deployment model, operating environment, network architecture, access control, privilege separation, data custody, maintenance posture, physical resilience.

8 pages10 sections
Download PDF

Site Requirements & Installation Readiness

Site conditions, scope of supply, placement, electrical and network requirements, internet minimums, firewall and egress rules, ongoing responsibilities, pre-installation checklist.

7 pages9 sections
Download PDF
03Where to look

Two readers, different sections.

Buying it
  • Overview §1 Deployment model, licensing, what happens on lapse
  • Overview §6 Data custody, telemetry, portability
  • Overview §7 Who maintains it and what your staff do
  • Overview §7.1 Version entitlement if you stop renewing
  • Site Reqs §1–4 Power, placement, what your site provides

Ownership, cost over time, what your staff have to do, where your data sits.

Signing off on it
  • Overview §3 Network architecture and required egress
  • Overview §4 Access control, enforcement point, revocation
  • Overview §5 Privilege separation and the operator boundary
  • Overview §9 Security posture summary table
  • Site Reqs §5–7 Network, internet service, firewall and egress rules
  • Site Reqs §9 Pre-installation checklist, items marked [IT]

Every control is stated as an implementation. The egress specification is complete enough to write firewall rules from.

04Component inventory

Not published.

The architecture, security model, network requirements, egress specification, privilege model and data handling are documented in full above, and we will answer questions on any of them. The component inventory itself stays in-house. It is not released under NDA or any other arrangement.

Get in touch