Skip to content
Trust Quality AssuranceManufacturing Intelligence

Documentation · platform release 2026.3

Documentation contents

Deployment

Three deployment models, the same platform in each. This page covers what your infrastructure team needs to provide, what we operate, and how a rollout is sequenced across sites.

Updated July 2026 · 10 min read

Choosing a model

Deployment models
ModelOperated byData locationTypical fit
Managed cloudTrust Quality AssuranceRegional tenant (EU / US / APAC)Most multi-plant rollouts
Private cloudShared: you own infrastructure, we own the applicationYour cloud subscriptionIP-sensitive or regulated programmes
On-premise / air-gappedYou, with our support modelInside the plant networkDefence, semiconductor, restricted sites

Network and infrastructure requirements

Per site

  • Gateway host: 4 vCPU, 8 GB RAM, 100 GB disk (Linux container host or Windows Server with container support).
  • Outbound HTTPS (443) to your tenant hostname. No inbound ports and no VPN are required for managed cloud.
  • Read access to in-scope sources: OPC UA endpoints, historian, inspection databases, gauge shares.
  • NTP synchronisation — timestamp integrity matters more here than in most systems, because subgroup formation depends on it.
  • Optional GPU where on-edge vision inference is in scope.

Identity

  • SAML 2.0 or OIDC single sign-on with your identity provider (Entra ID, Okta, Ping and others).
  • SCIM 2.0 provisioning so joiners, movers and leavers follow your existing IT process.
  • Group-to-role mapping, with scope assigned by site, line, product family or supplier.
  • Break-glass local administrator accounts, disabled by default and audited when used.
Shell · air-gapped offline bundle install
# Verify the signed bundle before installing (public key supplied out of band)
tqa-bundle verify --file tqa-2026.3.2-offline.tar.zst --key tqa-release.pub

# Stage and apply
tqa-bundle stage --file tqa-2026.3.2-offline.tar.zst
tqa-bundle apply --window "2026-08-15T22:00:00+02:00" --rollback-on-failure

# Confirm component versions after the window
tqa-admin versions --expect 2026.3.2

Rollout sequencing

Sites are sequenced so each one is faster than the last. The gating item is almost never technical — it is agreement on shared characteristic definitions.

  1. 1Pilot line at the lead site: prove the value case and establish the characteristic library.
  2. 2Remainder of the lead site: reuse definitions, connectors and alert routing patterns.
  3. 3Template site: a second plant with different equipment, to validate that the template travels.
  4. 4Wave rollout: remaining sites in waves of two to four, each with a local process owner.
  5. 5Network reporting: cross-plant benchmarking enabled once definitions are demonstrably comparable.
Typical elapsed time
PhaseElapsedEffort from your team
Pilot line2–4 weeks~0.3 FTE quality, ~0.1 FTE IT
Lead site completion4–8 weeks~0.5 FTE quality, ~0.1 FTE IT
Template site3–5 weeks~0.3 FTE per site
Wave rollout6–10 weeks per wave~0.2 FTE per site
Network reporting2 weeksGovernance workshop plus sign-off

Validated environments

For ISO 13485 and 21 CFR Part 11 programmes, an enterprise agreement includes a validation package: IQ and OQ documentation, a requirements traceability matrix, change-control artefacts and release notes structured for regulatory review. PQ remains your responsibility because it is specific to your process.

Support model

Support tiers
TierResponse targetIncluded with
Business hoursNext business dayPilot engagements
24 × 54 hours for production impactPlant subscriptions
24 × 7 with escalation1 hour for production impact, named escalation pathEnterprise agreements

Need something this page does not cover?

Solution architects answer technical questions directly — no ticket triage for pre-sales evaluation.

Ask an engineer