DEPLOYMENT

Cloud when you want it. On-premise when the account requires it.

AquaAdvisor was built to run in both places from the start. The on-premise deployment is not a stripped-down edition — it is the same engine, the same asset models, and the same twins, running inside the customer's network when the account requires it.

WHAT IT ACTUALLY DOES

What it actually does

  • Two first-class footprints

    Cloud SaaS for fast multi-account starts, or full on-premise — private cloud, VM estate, or bare metal — behind the customer's firewall.

  • Identical chemistry

    Same engine, same asset models, same twins, identical results against a pinned database version.

  • Air-gapped capable

    No outbound connectivity required for on-premise operation when the customer's OT policy forbids egress.

  • Versioned chemistry bundles

    Chemistry database bundles delivered as versioned artifacts so results stay reproducible and auditable years later.

  • Your change control

    On-premise upgrades follow the customer's change-control schedule — not a forced cloud push.

  • Data ownership

    Your account data is yours; the customer's process data stays where they require it. Export is a standard feature.

TOPOLOGY

Where the engine sits

Cloud tenancy versus on-premise inside the customer's perimeter — firewall shown explicitly, no outbound path.

Cloud SaaS

Plant / sites

Telemetry egress →

AquaAdvisor cloud

Engine · Twins · Programs

Operators & API clients

Results · dashboards · exports

On-premise

Firewall / perimeter — no outbound

Historian · LIMS · PLC

Inside perimeter

AquaAdvisor on-prem

Same engine · same twins

Operators inside network

No egress required

Illustrative topology. Not a network diagram of a customer site.

COMPARISON

Cloud and on-premise, side by side

The only honest differences are who operates it and update cadence — not chemistry depth.

DimensionCloudOn-premise
HostingAquaAdvisor-hosted SaaSThe customer's private cloud, VMs, or bare metal
Setup timeFast start; multi-account onboardingDeployed into the customer's estate under their change control
Outbound connectivity requiredYes — to the hosted serviceNo — air-gapped operation supported
Chemistry engineFull engineSame full engine
Asset models and twinsFull setSame full set
API accessAvailableAvailable inside the customer's network
AI layerInsights, supervision, and optimization availableSame AI layer available inside the customer's perimeter
Telemetry ingestionTo the hosted platformInside the perimeter; no egress required
UpdatesManaged release cadenceArtifacts on the customer's change-control schedule
Backup and DROperated as part of the hosted serviceUnder the customer's existing backup and DR practices
IdentityPlatform identity (integrations confirmed per deal)Integrate with the customer's identity provider inside the perimeter
Support modelHosted operations plus engineer-led supportThe customer's operations plus engineer-led support

ON-PREMISE

On-premise specifics

  • Containerized deployment
  • Runs in the customer's private cloud, VM estate, or bare metal
  • No outbound connectivity required; air-gapped operation supported
  • License-key activation
  • Versioned chemistry database bundles delivered as artifacts
  • Upgrades on the customer's change-control schedule
  • Integration with historian, LIMS, and identity inside the perimeter

HOW IT WORKS

How an on-premise deployment runs

  1. Containerized install

    Deploy the platform as containers inside the customer's private cloud, VM estate, or bare-metal footprint.

  2. Activate

    Activate with a license key; pin chemistry database versions for reproducible results.

  3. Integrate inside the perimeter

    Connect historian, LIMS, and identity providers inside the account's network — no outbound path required.

  4. Operate and upgrade

    Run air-gapped or DMZ-isolated; take upgrades as artifacts on the customer's change-control cadence.

DATA OWNERSHIP

Your account data is yours in both models

Your service-company account data is yours; the customer's process data stays where they require it. Export is a standard feature. Nothing about the commercial relationship depends on holding history hostage. That is the same independence argument as the rest of the platform.

Why independence matters →

SECURITY POSTURE

What we can state today

Encryption in transit and at rest, role-based access, and audit logging are part of the platform design. Cloud tenancy is isolated per customer. Specific certifications, regions, and identity federation options are confirmed per engagement — we do not list certifications we do not hold.

WHAT YOU GET

What you get out

  • Full platform capability in cloud or on-premise — not a reduced feature set
  • Pinned chemistry database versions for auditability
  • Telemetry and twin operation inside the customer's perimeter when the account requires it
  • Standard data export in both models
  • A deployment choice that matches the customer's OT policy instead of fighting it

WHO CHOOSES WHICH

Who chooses which

  • Cloud: your multi-account fleet, fast onboarding, and accounts that can live in hosted SaaS
  • On-premise: air-gapped accounts you still want to serve — refineries, power, defense-adjacent sites, some data centers, and any customer whose OT policy forbids external egress

Talk to us about an on-premise deployment.

Bring the customer's OT constraints. We will map cloud vs on-premise against the same chemistry and the same results.