PRATA
Technical specs

Two documents. Read the half that's yours.

One covers architecture and security posture, the other covers what a site needs before installation. Both are written for two different readers, so the sections below split them that way — the owner or operator on one side, the person doing technical review on the other.

Audience one

The owner or operator

You're deciding whether to buy it and where it goes. What matters is ownership, cost over time, what your staff have to do, and what happens to your data. Neither document asks you to understand the networking.

TF-PRATA-TO / REV 2026.07 Technical Overview & Security Posture What it tells you about ownership and cost
  • You own the hardware outright and the licence is perpetual on it
  • No activation server and no entitlement check that can switch the system off
  • Renewal is $1 a year from year two, covering upgrades and integration maintenance
  • Stop renewing after the first twelve months and it keeps running, debranded, at the last version you paid through
  • Your staff never patch, update or configure anything, and your IT burden is none
  • Your business data stays on your appliance — no vendor copy, no telemetry, nothing sold or used for training
  • If TanFlag ceased operating, installations keep running; what you lose is future support, not the system
Download PDF
TF-PRATA-SR / REV 2026.07 Site Requirements & Installation Readiness What your site has to provide
  • Three things from you: one standard grounded outlet, one open LAN port, and under a square foot of indoor shelf
  • Everything else arrives configured — appliance, UPS, cabling and setup
  • Hardware is billed at cost, roughly $325 all-in, with no markup, and you own it
  • Two battery-backed outlets are needed: one for the appliance, one for your router
  • Nobody on staff touches it — it runs headless, with no monitor or keyboard
  • Installation completes within seven days of deposit, typically in a single visit
  • Afterwards: leave it powered and connected, and tell us before a router, ISP or firewall change
Download PDF
Audience two

Technical review

CTO, IT director, managed IT provider, network administrator, or whoever gets asked to sign off. Every control is stated as an implementation rather than a claim, and the egress specification is complete enough to write firewall rules from.

TF-PRATA-TO / REV 2026.07 Technical Overview & Security Posture Architecture, access control and the operator boundary
  • Single-tenant on-premises deployment; ARM64 Debian, headless, services in discrete containers, PostgreSQL local and not exposed beyond the container network
  • Zero inbound ports. Outbound-only encrypted tunnel, four concurrent connections to distributed edge nodes
  • QUIC over UDP 7844 primary, automatic HTTP/2 over TCP 7844 fallback; functions behind CGNAT
  • Not discoverable by external IP or port scanning; no port forwarding, NAT rule, DMZ placement or public IP
  • TLS appliance to edge and edge to end user; certificates issued and renewed at the edge, none on client equipment
  • Authentication enforced at the edge before requests reach the appliance, scoped per named individual, revocation immediate, with an independent application-layer session and role model behind it
  • Operator boundary: application interface only — no host, container, database or credential access, permanently, not as a setup-phase restriction
  • TanFlag retains persistent administrative access over the tunnel for the life of the support relationship
  • Component inventory is not published; specifics are answered under mutual NDA
Download PDF
TF-PRATA-SR / REV 2026.07 Site Requirements & Installation Readiness Network, egress rules and pre-installation
  • Wired gigabit only, Wi-Fi disabled; untagged access port, no VLAN tagging required by default
  • Static DHCP reservation bound to the appliance MAC address is required
  • No inbound rule on any port; no VPN, dynamic DNS or client-managed certificates
  • Egress: UDP 7844 and TCP 7844 to the edge, TCP 443 to platform APIs, DNS on 53, NTP on 123
  • 25 Mbps down and 5 Mbps up minimum — upstream is the governing constraint, since the appliance transmits more than it receives
  • TLS interception on the management tunnel prevents it establishing; the appliance must be exempted from DPI
  • SNI-enforcing and IP-based rule sets need the current edge destination ranges, requested close to the installation date
  • Section 9 is a pre-installation checklist with the network administrator items marked [IT]
Download PDF
The documents

Both, in full

Open either one here, or take the PDF with you. No form and no email gate.

TF-PRATA-TO / REV 2026.07

Technical Overview & Security Posture

Deployment model, operating environment, network architecture, access control, privilege separation, data custody, maintenance posture and physical resilience. 8 pages.

Download PDF
TF-PRATA-SR / REV 2026.07

Site Requirements & Installation Readiness

Site conditions, scope of supply, placement, electrical and network requirements, internet service minimums, firewall and egress rules, ongoing responsibilities and the pre-installation checklist. 7 pages.

Download PDF
Deeper review

What these don't cover

The component inventory isn't published. Everything else — architecture, security model, network requirements, egress specification, privilege model and data handling — is documented in full above, and specific questions are answered under a mutual non-disclosure agreement. Tell us the reviewing organisation and the scope of the assessment.

Get in touch