Titan Cloud vs Titan On-Prem
Both editions share the same codebase. The difference is where it runs and who manages it.
Quick Comparison
| Titan Cloud | Titan On-Prem | |
|---|---|---|
| Host | hub.titanrfid.com (Wonder-managed SaaS) | Your server (3 Docker containers) |
| Readers | Connect over internet (TLS/MQTT) | Connect over LAN (MQTT) |
| Setup | Plug in reader → appears in your account | Install bundle, configure, register readers |
| Maintenance | Automatic updates, backups, monitoring | You manage: backups, upgrades, monitoring |
| Identity | Passkey sign-in (OIDC) + local accounts | Local email/password (OIDC optional) |
| License | Yearly licence | Yearly licence (online check-in, or signed offline licence) |
| Air-Gapped | No (requires internet) | Yes (offline license, local images) |
When to Choose Cloud
Best for:
- Standard deployments (1-10 readers)
- No IT infrastructure available
- Want plug-and-play experience
Requirements:
- Readers can reach internet (firewall allows outbound 8883/tcp to
mqtt.titanrfid.com) - Comfortable with data in cloud (encrypted in transit and at rest)
Reader Provisioning:
- Wonder-Shipped (current): Reader arrives configured; plug in and it works
- BYO (designed, not built): Customer installs CAP, claims reader via hub, pulls identity
When to Choose On-Prem
Best for:
- Air-gapped sites (no internet access)
- Regulatory requirements (data must stay on-site)
- Custom integrations (need direct database or API access)
Requirements:
- Linux server with Docker Engine 24+
- 4+ GB RAM, 100+ GB disk
- Static IP on same network as readers
- Someone to manage: backups, upgrades, monitoring
Reader Provisioning:
- Register via hub UI → titand pushes config to reader via REST API
- No internet exposure during provisioning (all on LAN)
Feature Parity
Both editions support:
- Tag data, history, zones, users, API keys
- Real-time location tracking
- Multi-reader coordination
- CSV import/export
- Alerts and notifications
- R700 CAP for Start/Stop commands
Cloud-Only Features:
- Multi-tenancy (multiple organizations on shared infrastructure)
- The Titan operator console (internal administration UI)
On-Prem-Only Features:
- Full control over database (direct SQL access)
- Custom reverse proxy configuration (HTTPS termination, custom headers)
- Runs without internet (air-gapped deployments)
Network Architecture
Cloud Model
┌─────────────┐
│ R700 Reader │
│ (on-site) │
└──────┬──────┘
│ Outbound TLS (8883/tcp)
│ to mqtt.titanrfid.com
│
└──────── Internet ──────────┐
│
┌─────────▼──────────┐
│ Titan Cloud │
│ (Wonder infra) │
└─────────┬──────────┘
│
Browser (HTTPS)
Firewall Rules Needed:
- Reader → Cloud: Allow outbound 8883/tcp to
mqtt.titanrfid.com - Browser → Cloud: Allow outbound 443/tcp to
hub.titanrfid.com
No Inbound Ports: Cloud cannot reach into customer network. Readers connect out.
On-Prem Model
┌─────────────┐ ┌─────────────────────┐
│ R700 Reader │──────▶│ Titan Server │
│ (LAN) │ 1883 │ (on-site) │
└─────────────┘ │ - mosquitto :1883 │
│ - titand :8080 │
│ - postgres :5432 │
└──────────┬──────────┘
│
Browser (LAN or VPN)
Firewall Rules Needed:
- Reader → Server: LAN traffic (1883/tcp for MQTT)
- Browser → Server: LAN traffic (8080/tcp for web UI, or 443 if reverse proxy)
- Server → Internet: Optional (for license activation, image pulls, updates)
Reader Configuration: Bidirectional. Titan can reach readers over LAN to push config via REST API.
Licensing
Titan is paid software in both editions; there is no free tier.
- Yearly licence. Both editions are licensed per year.
- Sized by readers and sites. A licence sets how many readers and how many sites you can run. It is not priced by user seats or by tag volume.
- Paid add-ons. Some features are sold as add-ons on top of the core licence. Settings > Subscription in the hub shows which ones your licence includes.
- Keeping running if contact is lost. On-Prem installs check in with Titan's licence server. If they lose contact, a grace period starts (a warning, then read-only) rather than stopping your site.
- Air-gapped sites get a signed offline licence file instead, with no check-in.
Contact Wonder for pricing.
Migration Path
Cloud → On-Prem:
- Export tag data (CSV from hub)
- Install On-Prem bundle
- Import CSV
- Reconfigure readers to point at on-prem broker (REST API call)
On-Prem → Cloud:
- Export tag data (SQL dump or CSV)
- Provision readers for cloud (install CAP, claim identity)
- Import data to cloud tenant
- Readers reconnect to
mqtt.titanrfid.com
Migration in either direction is data + reader reconfiguration. History is portable (CSV/SQL), but reader identity must be re-issued (different broker, different certificates).
Decision Framework
Choose Cloud if:
- You want plug-and-play
- You lack IT infrastructure
Choose On-Prem if:
- Air-gapped or data-residency requirements
- You have IT staff for maintenance
- You need custom integrations (direct DB access, custom auth)
Still Unsure?
Start with Titan Cloud. If you outgrow it or hit a regulatory requirement, migrate to On-Prem later. Tag data and configuration are portable.
Next Steps:
- Cloud: Contact Wonder for reader provisioning and account setup
- On-Prem: See the on-prem installation guide shipped with your Titan on-prem package.