Skip to main content

Titan Cloud vs Titan On-Prem

Both editions share the same codebase. The difference is where it runs and who manages it.

Quick Comparison​

Titan CloudTitan On-Prem
Hosthub.titanrfid.com (Wonder-managed SaaS)Your server (3 Docker containers)
ReadersConnect over internet (TLS/MQTT)Connect over LAN (MQTT)
SetupPlug in reader → appears in your accountInstall bundle, configure, register readers
MaintenanceAutomatic updates, backups, monitoringYou manage: backups, upgrades, monitoring
IdentityPasskey sign-in (OIDC) + local accountsLocal email/password (OIDC optional)
LicenseYearly licenceYearly licence (online check-in, or signed offline licence)
Air-GappedNo (requires internet)Yes (offline license, local images)

When to Choose Cloud​

Best for:

  • Standard deployments (1-10 readers)
  • No IT infrastructure available
  • Want plug-and-play experience

Requirements:

  • Readers can reach internet (firewall allows outbound 8883/tcp to mqtt.titanrfid.com)
  • Comfortable with data in cloud (encrypted in transit and at rest)

Reader Provisioning:

  • Wonder-Shipped (current): Reader arrives configured; plug in and it works
  • BYO (designed, not built): Customer installs CAP, claims reader via hub, pulls identity

When to Choose On-Prem​

Best for:

  • Air-gapped sites (no internet access)
  • Regulatory requirements (data must stay on-site)
  • Custom integrations (need direct database or API access)

Requirements:

  • Linux server with Docker Engine 24+
  • 4+ GB RAM, 100+ GB disk
  • Static IP on same network as readers
  • Someone to manage: backups, upgrades, monitoring

Reader Provisioning:

  • Register via hub UI → titand pushes config to reader via REST API
  • No internet exposure during provisioning (all on LAN)

Feature Parity​

Both editions support:

  • Tag data, history, zones, users, API keys
  • Real-time location tracking
  • Multi-reader coordination
  • CSV import/export
  • Alerts and notifications
  • R700 CAP for Start/Stop commands

Cloud-Only Features:

  • Multi-tenancy (multiple organizations on shared infrastructure)
  • The Titan operator console (internal administration UI)

On-Prem-Only Features:

  • Full control over database (direct SQL access)
  • Custom reverse proxy configuration (HTTPS termination, custom headers)
  • Runs without internet (air-gapped deployments)

Network Architecture​

Cloud Model​

┌─────────────┐
│ R700 Reader │
│ (on-site) │
└──────┬──────┘
│ Outbound TLS (8883/tcp)
│ to mqtt.titanrfid.com
│
└──────── Internet ──────────┐
│
┌─────────▼──────────┐
│ Titan Cloud │
│ (Wonder infra) │
└─────────┬──────────┘
│
Browser (HTTPS)

Firewall Rules Needed:

  • Reader → Cloud: Allow outbound 8883/tcp to mqtt.titanrfid.com
  • Browser → Cloud: Allow outbound 443/tcp to hub.titanrfid.com

No Inbound Ports: Cloud cannot reach into customer network. Readers connect out.

On-Prem Model​

┌─────────────┐ ┌─────────────────────┐
│ R700 Reader │──────▶│ Titan Server │
│ (LAN) │ 1883 │ (on-site) │
└─────────────┘ │ - mosquitto :1883 │
│ - titand :8080 │
│ - postgres :5432 │
└──────────┬──────────┘
│
Browser (LAN or VPN)

Firewall Rules Needed:

  • Reader → Server: LAN traffic (1883/tcp for MQTT)
  • Browser → Server: LAN traffic (8080/tcp for web UI, or 443 if reverse proxy)
  • Server → Internet: Optional (for license activation, image pulls, updates)

Reader Configuration: Bidirectional. Titan can reach readers over LAN to push config via REST API.

Licensing​

Titan is paid software in both editions; there is no free tier.

  • Yearly licence. Both editions are licensed per year.
  • Sized by readers and sites. A licence sets how many readers and how many sites you can run. It is not priced by user seats or by tag volume.
  • Paid add-ons. Some features are sold as add-ons on top of the core licence. Settings > Subscription in the hub shows which ones your licence includes.
  • Keeping running if contact is lost. On-Prem installs check in with Titan's licence server. If they lose contact, a grace period starts (a warning, then read-only) rather than stopping your site.
  • Air-gapped sites get a signed offline licence file instead, with no check-in.

Contact Wonder for pricing.

Migration Path​

Cloud → On-Prem:

  1. Export tag data (CSV from hub)
  2. Install On-Prem bundle
  3. Import CSV
  4. Reconfigure readers to point at on-prem broker (REST API call)

On-Prem → Cloud:

  1. Export tag data (SQL dump or CSV)
  2. Provision readers for cloud (install CAP, claim identity)
  3. Import data to cloud tenant
  4. Readers reconnect to mqtt.titanrfid.com

Migration in either direction is data + reader reconfiguration. History is portable (CSV/SQL), but reader identity must be re-issued (different broker, different certificates).

Decision Framework​

Choose Cloud if:

  • You want plug-and-play
  • You lack IT infrastructure

Choose On-Prem if:

  • Air-gapped or data-residency requirements
  • You have IT staff for maintenance
  • You need custom integrations (direct DB access, custom auth)

Still Unsure?​

Start with Titan Cloud. If you outgrow it or hit a regulatory requirement, migrate to On-Prem later. Tag data and configuration are portable.

Next Steps:

  • Cloud: Contact Wonder for reader provisioning and account setup
  • On-Prem: See the on-prem installation guide shipped with your Titan on-prem package.