DEPLOYMENT
Cloud when you want it. On-premise when the account requires it.
AquaAdvisor was built to run in both places from the start. The on-premise deployment is not a stripped-down edition — it is the same engine, the same asset models, and the same twins, running inside the customer's network when the account requires it.
WHAT IT ACTUALLY DOES
What it actually does
Two first-class footprints
Cloud SaaS for fast multi-account starts, or full on-premise — private cloud, VM estate, or bare metal — behind the customer's firewall.
Identical chemistry
Same engine, same asset models, same twins, identical results against a pinned database version.
Air-gapped capable
No outbound connectivity required for on-premise operation when the customer's OT policy forbids egress.
Versioned chemistry bundles
Chemistry database bundles delivered as versioned artifacts so results stay reproducible and auditable years later.
Your change control
On-premise upgrades follow the customer's change-control schedule — not a forced cloud push.
Data ownership
Your account data is yours; the customer's process data stays where they require it. Export is a standard feature.
TOPOLOGY
Where the engine sits
Cloud tenancy versus on-premise inside the customer's perimeter — firewall shown explicitly, no outbound path.
Cloud SaaS
Plant / sites
Telemetry egress →
AquaAdvisor cloud
Engine · Twins · Programs
Operators & API clients
Results · dashboards · exports
On-premise
Firewall / perimeter — no outbound
Historian · LIMS · PLC
Inside perimeter
AquaAdvisor on-prem
Same engine · same twins
Operators inside network
No egress required
Illustrative topology. Not a network diagram of a customer site.
COMPARISON
Cloud and on-premise, side by side
The only honest differences are who operates it and update cadence — not chemistry depth.
| Dimension | Cloud | On-premise |
|---|---|---|
| Hosting | AquaAdvisor-hosted SaaS | The customer's private cloud, VMs, or bare metal |
| Setup time | Fast start; multi-account onboarding | Deployed into the customer's estate under their change control |
| Outbound connectivity required | Yes — to the hosted service | No — air-gapped operation supported |
| Chemistry engine | Full engine | Same full engine |
| Asset models and twins | Full set | Same full set |
| API access | Available | Available inside the customer's network |
| AI layer | Insights, supervision, and optimization available | Same AI layer available inside the customer's perimeter |
| Telemetry ingestion | To the hosted platform | Inside the perimeter; no egress required |
| Updates | Managed release cadence | Artifacts on the customer's change-control schedule |
| Backup and DR | Operated as part of the hosted service | Under the customer's existing backup and DR practices |
| Identity | Platform identity (integrations confirmed per deal) | Integrate with the customer's identity provider inside the perimeter |
| Support model | Hosted operations plus engineer-led support | The customer's operations plus engineer-led support |
ON-PREMISE
On-premise specifics
- Containerized deployment
- Runs in the customer's private cloud, VM estate, or bare metal
- No outbound connectivity required; air-gapped operation supported
- License-key activation
- Versioned chemistry database bundles delivered as artifacts
- Upgrades on the customer's change-control schedule
- Integration with historian, LIMS, and identity inside the perimeter
HOW IT WORKS
How an on-premise deployment runs
Containerized install
Deploy the platform as containers inside the customer's private cloud, VM estate, or bare-metal footprint.
Activate
Activate with a license key; pin chemistry database versions for reproducible results.
Integrate inside the perimeter
Connect historian, LIMS, and identity providers inside the account's network — no outbound path required.
Operate and upgrade
Run air-gapped or DMZ-isolated; take upgrades as artifacts on the customer's change-control cadence.
DATA OWNERSHIP
Your account data is yours in both models
Your service-company account data is yours; the customer's process data stays where they require it. Export is a standard feature. Nothing about the commercial relationship depends on holding history hostage. That is the same independence argument as the rest of the platform.
SECURITY POSTURE
What we can state today
Encryption in transit and at rest, role-based access, and audit logging are part of the platform design. Cloud tenancy is isolated per customer. Specific certifications, regions, and identity federation options are confirmed per engagement — we do not list certifications we do not hold.
WHAT YOU GET
What you get out
- Full platform capability in cloud or on-premise — not a reduced feature set
- Pinned chemistry database versions for auditability
- Telemetry and twin operation inside the customer's perimeter when the account requires it
- Standard data export in both models
- A deployment choice that matches the customer's OT policy instead of fighting it
WHO CHOOSES WHICH
Who chooses which
- Cloud: your multi-account fleet, fast onboarding, and accounts that can live in hosted SaaS
- On-premise: air-gapped accounts you still want to serve — refineries, power, defense-adjacent sites, some data centers, and any customer whose OT policy forbids external egress
Talk to us about an on-premise deployment.
Bring the customer's OT constraints. We will map cloud vs on-premise against the same chemistry and the same results.