# On-Premise IoT

## The whole platform. On your network.

For environments where data can't leave the building — secure facilities, regulated industries, ships at sea, the quiet rooms nobody talks about. Echolo ships as a fully air-gapped appliance, or as a hybrid edge that syncs to the cloud on your terms.

## Two modes

### Air-gapped or hybrid. Pick the one that matches your rules.

### Mode 01

#### Private — fully air-gapped.

The full platform — broker, storage, dashboards, rule engine — runs on the appliance. Nothing outbound, nothing inbound. Updates delivered on signed removable media when you want them, and not a moment earlier.

SENSORS

ECHOLO ON-PREMISE · PRIVATE

YOUR APP

Sensors feed the Echolo On-Premise Private appliance, which serves your app directly. No cloud connection.

- Zero external network dependency — runs without WAN.
- All telemetry stays inside your perimeter. Your data, your rack.
- Fits classified, regulated, or genuinely disconnected environments.

### Mode 02

#### Edge — local first, cloud when you want.

Rules, alerts, and real-time calculations execute on-site in under a second — even if the uplink is down. A background syncer batches messages to Echolo Cloud on a schedule you control, so per-message pricing doesn't eat your margin.

SENSORS

ECHOLO ON-PREMISE · EDGE

YOUR APP

ECHOLO

IoT PLATFORM

Sensors feed the Echolo Edge appliance, which serves your app locally and batches data to the cloud platform on your schedule.

- Sub-second local decisions — alerts fire without a round trip.
- Batched cloud sync on your schedule — minute, hour, or never.
- Automatic security patching once the link is open.

## Security stack

### Hardened because you have to be.

Built to survive an audit. These are the defaults, not an upsell.

### Closed by default

Every port we don't need stays closed. Only the ones your integration uses get opened, and only on the interfaces you specify.

### Encrypted at rest

Filesystem encryption on every appliance, with salted SHA-512 for credentials. No plaintext anything, no exceptions.

### UFW out of the box

Uncomplicated Firewall shipped pre-configured. Your netsec team gets a readable rule set they can audit on day one.

### Peripherals locked

USB and SD boot disabled. External media is locked down at the firmware level — nobody walks out with your data on a thumb drive.

### Automatic patching

Edge mode receives security patches on a cadence you set. Private mode can pull signed update bundles over removable media.

### Stream or persist

MQTT, WebSocket, or SSE for real-time consumers. MySQL or MongoDB for durable storage. Your choice, not ours.

## Who this is for

### If “must not leave the network” is on your requirements doc.

An appliance-shaped deployment scales to [**1,000+ hubs**](/content/hardware/index.html) and **tens of thousands** of end devices without calling the cloud once. Works for a dozen sensors in a lab too.

- **Regulated industries**  
  Healthcare, defense, finance — anywhere compliance prohibits public cloud.

- **Air-gapped facilities**  
  Sites where 'must not leave the network' is a hard requirement.

- **Remote + offline**  
  Mines, ships, oil + gas, remote construction. No WAN, no problem.

- **Cost-sensitive at scale**  
  When per-message cloud pricing doesn't pencil out, edge batching does.

## Ready to see your fleet?

A 20-minute walk-through of the platform, your equipment types, and what a deployment actually looks like. No sales team. No pitch deck.
