The full specification is in the table below. Both source documents are on this page, readable in the browser or as PDFs.
| Model | Single-tenant, on-premises, client-owned hardware |
|---|---|
| Sharing | No data, compute or credential store shared between installations |
| License | Perpetual on the hardware. No activation server, no entitlement check |
| Vendor dependency | None for operation. The appliance never contacts the vendor for authorization |
| Cloud components | None for application logic or data. A managed edge provides encrypted transport and authentication only |
| Processor | Quad-core 64-bit Arm Cortex-A76 at 2.4 GHz, ARM64 |
|---|---|
| Memory | 8 GB LPDDR4X |
| Storage | 512 GB NVMe SSD over PCIe 2.0, chosen over removable flash for write endurance |
| Operating system | Debian-based Linux, 64-bit, headless, no desktop environment |
| Service isolation | Discrete containers under a supervised runtime, no shared filesystem namespace |
| Database | PostgreSQL, local to the appliance, not exposed beyond the container network |
| Restart policy | Every service recovers unattended after power loss or reboot |
| Administration | Command line over SSH. No graphical console on any network |
| Power | One 120V grounded outlet, 27W maximum, on a line-interactive UPS |
|---|---|
| UPS outlets | Two battery-backed: one for the appliance, one for the router |
| Footprint | Under 1 sq ft including the UPS, 2 in. clearance for airflow |
| Staff access | None required. Headless, with no monitor, keyboard or peripheral |
| Installation | Complete within seven days of deposit, typically one visit |
| Inbound ports | None. No port forwarding, no NAT rule, no DMZ, no inbound exception |
|---|---|
| Public IP | Not required. Functions behind CGNAT |
| Connection | Wired gigabit, untagged access port, static DHCP reservation on the appliance MAC |
| Transport | QUIC over UDP 7844 primary, HTTP/2 over TCP 7844 fallback, four concurrent edge connections |
| Egress required | UDP and TCP 7844, TCP 443, DNS 53, NTP 123. A firewall blocking all ingress and permitting only these is complete |
| Discoverability | Not resolvable by external IP or port scanning |
| DPI | TLS interception on the tunnel prevents it establishing. The appliance requires an exemption |
| Uplink minimum | 25 Mbps down, 5 Mbps up. Upstream governs, since the appliance transmits more than it receives |
| Client-side infrastructure | No reverse proxy, VPN, dynamic DNS or certificate automation |
| Enforcement point | Network edge, upstream of the appliance. Unauthenticated requests are never forwarded |
|---|---|
| Policy scope | Per named individual, not a shared credential or a network range |
| Application layer | Independent session, role and permission model behind the edge policy. Two layers must be satisfied |
| Revocation | Immediate at the edge, regardless of application session state |
| Operator privilege | Application interface only. No host, container, database or credential access, at any point in the lifecycle |
| Credential store | Encrypted, inside the automation layer, behind separate authentication restricted to vendor identities |
| Encryption | TLS appliance to edge, TLS edge to end user. Certificates issued and renewed at the edge |
| Residency | Client premises, on the client-owned appliance |
|---|---|
| Scope | Customer records, review history, message content, campaign, scheduling and analytics data |
| Egress of data | Only when a workflow you configured transmits it to a service you connected |
| Vendor-side copy | None. No central store, no replica |
| Telemetry | None. No usage reporting, no analytics beacon, no diagnostic upload |
| Monetization | None. Not aggregated, resold, licensed or used for model training |
| Portability | A standard relational database on hardware you own, readable with standard tooling |
Deployment model, operating environment, network architecture, access control, privilege separation, data custody, maintenance posture, physical resilience.
Site conditions, scope of supply, placement, electrical and network requirements, internet minimums, firewall and egress rules, ongoing responsibilities, pre-installation checklist.
Ownership, cost over time, what your staff have to do, where your data sits.
Every control is stated as an implementation. The egress specification is complete enough to write firewall rules from.
The architecture, security model, network requirements, egress specification, privilege model and data handling are documented in full above, and we will answer questions on any of them. The component inventory itself stays in-house. It is not released under NDA or any other arrangement.