Deployment

Your network decides.
Not our architecture.

Four topologies, all read-only. The ring buffer always sits next to the poll loop; only frozen snapshots ever tier outward. Whether your plant is air-gapped, on-prem, hybrid, or cloud-native — PulseMQ meets you where you are.

Book a Pilot Get the Sales Guide
Same Guarantees, Every Topology

Three properties that don't change with your network.

Every deployment topology below has the same three security and data-safety properties. Only the tiering behavior changes.

1. Read-only by default

Controllers feed PulseMQ read-only. Writes require an operator action, gated by role and domain, and every write is logged with its evidence chain. Nothing on your PLC gets touched by default.

2. Ring buffer next to the poll loop

Live data lives on the Edge appliance in a ring buffer — not in a cloud database, not in a shared filesystem. The buffer is where the poll loop writes and where AlarmIQ reads. Every topology preserves this locality.

3. Only frozen snapshots tier outward

When data leaves the Edge for another destination, it's a frozen snapshot — timestamped, versioned, no longer subject to change. The live buffer stays on the Edge. Nothing your controller produces sits in transit in an ambiguous state.

Topology 01
T1 · AIR-GAPPED

Air-gapped

Nothing leaves the plant. Ever.

The Edge box holds everything — live poll cache, ring buffer, alarm history, replay snapshots, machine models. No outbound network path is used or required. Operators access the platform over the plant LAN. Updates arrive via signed USB packages if and when you want them.

Best fit: Defense-adjacent manufacturing, regulated chemical processes, plants where the OT network is deliberately isolated from IT and internet.

  • OT contact Read-only via industrial protocols
  • IT contact None — no outbound path
  • Data locality 100% on the Edge box
  • History window 72 hours of snapshots on-box (extensible)
  • Updates Signed offline packages, operator-approved
  • Multi-site Each site is its own island
Topology 02
T2 · ON-PREMISE

On-Premise

Your VLAN. Your DNS. Your identity.

The Edge appliance sits beside the line and feeds a plant server in your OT DMZ. All storage, all user accounts, all API endpoints live inside your network perimeter. The platform authenticates against your identity provider (Active Directory, Okta, or LDAP). Nothing crosses the firewall unless you configure it to.

Best fit: Plants with existing OT DMZ architecture and mature IT/OT segregation. Companies with strong data-locality requirements or where compliance rules dictate on-prem storage.

  • OT contact Edge to PLCs, read-only
  • IT contact Plant server in your DMZ
  • Data locality 100% on-site
  • History window Bounded by plant server storage
  • Identity Your AD / Okta / LDAP
  • Multi-site Each site independent, optional cross-site portal
Topology 03
T3 · HYBRID

Hybrid

OT stays put. Reporting goes to the cloud.

The live layer stays on-prem — Edge appliance beside the line, plant server for AlarmIQ and Manufacturing. What tiers outward to your cloud is frozen event snapshots: alarm records, cycle histograms, OEE roll-ups. The cloud is where multi-site reporting happens and where cross-plant dashboards live. But your live PLC data never sits in transit.

Best fit: Multi-site manufacturers who want single-pane-of-glass visibility across plants but still keep production-critical data on-prem. Common in food & beverage, packaging, and multi-plant CPG.

  • OT contact Same as On-Prem
  • Cloud contact Frozen snapshots only, one-way outbound
  • Data locality Live data on-prem; reporting data replicated
  • History window Long-term retention in cloud
  • Identity Federated SSO (SAML / OIDC)
  • Multi-site Native — cross-plant rollups in the cloud tier
Topology 04
T4 · CLOUD

Cloud

Edge to AWS. Fastest setup.

The Edge appliance publishes directly to your PulseMQ cloud instance on AWS. Storage, identity, dashboards, and multi-user access all run in AWS behind a private tenant. No plant server required. This is the fastest topology to stand up — measured in hours, not weeks.

Best fit: Greenfield deployments, plants without existing OT DMZ infrastructure, single-site rollouts where cloud is already the default posture. Also the right choice for pilots — get to first value without waiting on IT to provision a plant server.

  • OT contact Edge to PLCs, read-only
  • Cloud contact Edge to AWS, one-way outbound
  • Data locality Live cache on Edge; primary storage in AWS
  • History window Long-term retention in your AWS tenant
  • Identity AWS-hosted SSO (SAML / OIDC / Cognito)
  • Multi-site Native — multiple Edges into the same AWS tenant
Side by Side

Which topology fits your plant?

Every topology preserves the same read-only, ring-buffer, frozen-snapshot guarantees. The differences are where data lives and how far it tiers outward.

T1 · Air-Gapped T2 · On-Prem T3 · Hybrid T4 · Cloud
Cloud contactNoneNoneSnapshots onlyYes
Plant server neededNoYesYesNo
Multi-site rollupPer-site islandOptional portalNativeNative
Time to first value1–2 weeks1–2 weeks1–2 weeksDays
IT involvementMinimalSignificantModerateMinimal
OT firewall changesNoneRead-only outbound to DMZSame as T2Read-only outbound to internet
Best for pilotsRegulated plantsExisting DMZ plantsMulti-plant CPGGreenfield / speed

You don't need to decide topology on day one. Every pilot starts at T1 or T4 (whichever your IT will approve fastest), and topology migrations between them are supported natively — because the platform code is identical across all four.

Pick the topology that matches your network.

Not sure which fits? Bring us your plant's network diagram and we'll tell you what fits. Sales engineering is included in every pilot — no long RFP process.

Book a Pilot Get the Sales Guide