iPaaS & Integration

Deployment Options

Run FloSynq the way your security team wants. Cloud orchestration with an installed Bridge agent inside your network, or the full platform installed on your own infrastructure. Either way, your business data stays in your network.

Option A (Most Popular)

FloSynq Cloud with an Installed Bridge Agent

Orchestration, scheduling, monitoring and alerting run in the FloSynq cloud. A lightweight Bridge agent installed inside your network does all the local work: ERP access, folder drops and pickups, and calls to your internal services.

You get SaaS economics (no platform maintenance, continuous updates, vendor-managed uptime) while every byte of business data movement stays inside your network. It is also the lower-cost option to build and to run.

How the Bridge agent works

  • A single Docker container installed on a server or VM inside your network
  • Sight of your ERP (database or API), transfer folders, and internal service endpoints
  • All invoice data processing happens inside your network
  • Connectivity is outbound HTTPS only. No inbound ports, no VPN required
  • Cloud tier holds orchestration state, logs and monitoring, not your invoice files
  • Payload content can be excluded from cloud logs entirely where policy requires (metadata only)
Option B

Fully Installed on Your Infrastructure

Some organisations need the entire platform inside their own perimeter. For them, FloSynq deploys as Docker containers (or onto Kubernetes) on infrastructure you own and operate, completely ring-fenced from the public internet.

This maximises isolation at the cost of a shared maintenance layer: upgrades become planned joint activities rather than continuous vendor-managed updates. We support both models as first-class citizens, so the choice is your security team's, not ours.

What a full install looks like

  • The complete platform (services, PostgreSQL, Redis queue, scheduler, dashboard) as Docker containers on your infrastructure
  • Kubernetes supported where your DevOps team prefers it for more complex environments
  • Everything ring-fenced inside your network. Nothing leaves except the files you choose to send
  • We supply the containers, installation runbook, upgrade procedure and support
  • You provide and patch the host infrastructure (VM or cluster, storage, backups)
  • Platform upgrades become scheduled joint activities with your infrastructure team
Side by Side

Choosing Between the Two

Both options keep your business data inside your network and need no inbound firewall changes. The difference is who runs the platform layer.

Dimension Cloud + Bridge Fully Installed
Invoice and business data locationStays in your networkStays in your network
Inbound firewall changesNone (outbound HTTPS only)None
Platform maintenanceVendor managed, continuous updatesJoint, scheduled upgrade windows
Infrastructure you provideOne Docker host for the Bridge agentDocker or Kubernetes hosts, database storage, backups
Monitoring dashboardCloud, SSO via ClerkLocal instance inside your network
Hosting complianceRender, SOC 2 Type II attestedInherits your infrastructure controls
Typical fitTeams that want SaaS economics with on-network data handlingStrict isolation policies or regulated environments

No Inbound Ports

The Bridge agent initiates all connections outbound over HTTPS. Your firewall rules stay exactly as they are.

Data Sovereignty

Invoice files, customer records and supplier data never leave your network in either model. The cloud sees orchestration metadata, and even that can be minimised.

Same Platform, Same Flows

Integrations built on one deployment model move to the other without rework. Start hybrid, go fully installed later, or the reverse.

Not Sure Which Model Fits?

Bring your security team's requirements. We will walk through both deployment models against your policies and recommend the one that clears review fastest.