Documentation contents
Get started
Using the platform
Help
Deployment
Three deployment models, the same platform in each. This page covers what your infrastructure team needs to provide, what we operate, and how a rollout is sequenced across sites.
Updated July 2026 · 10 min read
Choosing a model
| Model | Operated by | Data location | Typical fit |
|---|---|---|---|
| Managed cloud | Trust Quality Assurance | Regional tenant (EU / US / APAC) | Most multi-plant rollouts |
| Private cloud | Shared: you own infrastructure, we own the application | Your cloud subscription | IP-sensitive or regulated programmes |
| On-premise / air-gapped | You, with our support model | Inside the plant network | Defence, semiconductor, restricted sites |
Network and infrastructure requirements
Per site
- Gateway host: 4 vCPU, 8 GB RAM, 100 GB disk (Linux container host or Windows Server with container support).
- Outbound HTTPS (443) to your tenant hostname. No inbound ports and no VPN are required for managed cloud.
- Read access to in-scope sources: OPC UA endpoints, historian, inspection databases, gauge shares.
- NTP synchronisation — timestamp integrity matters more here than in most systems, because subgroup formation depends on it.
- Optional GPU where on-edge vision inference is in scope.
Identity
- SAML 2.0 or OIDC single sign-on with your identity provider (Entra ID, Okta, Ping and others).
- SCIM 2.0 provisioning so joiners, movers and leavers follow your existing IT process.
- Group-to-role mapping, with scope assigned by site, line, product family or supplier.
- Break-glass local administrator accounts, disabled by default and audited when used.
# Verify the signed bundle before installing (public key supplied out of band)
tqa-bundle verify --file tqa-2026.3.2-offline.tar.zst --key tqa-release.pub
# Stage and apply
tqa-bundle stage --file tqa-2026.3.2-offline.tar.zst
tqa-bundle apply --window "2026-08-15T22:00:00+02:00" --rollback-on-failure
# Confirm component versions after the window
tqa-admin versions --expect 2026.3.2Rollout sequencing
Sites are sequenced so each one is faster than the last. The gating item is almost never technical — it is agreement on shared characteristic definitions.
- 1Pilot line at the lead site: prove the value case and establish the characteristic library.
- 2Remainder of the lead site: reuse definitions, connectors and alert routing patterns.
- 3Template site: a second plant with different equipment, to validate that the template travels.
- 4Wave rollout: remaining sites in waves of two to four, each with a local process owner.
- 5Network reporting: cross-plant benchmarking enabled once definitions are demonstrably comparable.
| Phase | Elapsed | Effort from your team |
|---|---|---|
| Pilot line | 2–4 weeks | ~0.3 FTE quality, ~0.1 FTE IT |
| Lead site completion | 4–8 weeks | ~0.5 FTE quality, ~0.1 FTE IT |
| Template site | 3–5 weeks | ~0.3 FTE per site |
| Wave rollout | 6–10 weeks per wave | ~0.2 FTE per site |
| Network reporting | 2 weeks | Governance workshop plus sign-off |
Validated environments
For ISO 13485 and 21 CFR Part 11 programmes, an enterprise agreement includes a validation package: IQ and OQ documentation, a requirements traceability matrix, change-control artefacts and release notes structured for regulatory review. PQ remains your responsibility because it is specific to your process.
Support model
| Tier | Response target | Included with |
|---|---|---|
| Business hours | Next business day | Pilot engagements |
| 24 × 5 | 4 hours for production impact | Plant subscriptions |
| 24 × 7 with escalation | 1 hour for production impact, named escalation path | Enterprise agreements |
Need something this page does not cover?
Solution architects answer technical questions directly — no ticket triage for pre-sales evaluation.