Deployment

Managed cloud or a broker in your environment.

Choose who operates the broker, portal, database, certificates, updates, and backups without changing the mobile experience.

Side-by-side

Cloud and self-hosted deployment comparison.

In both models, the connector initiates the broker connection. The monitoring interface does not need public exposure.

Deployment detailLCW Labs CloudSelf-hosted broker and portal
Who operates itLCW Labs operates the broker, database, portal, updates, backups, certificates, and push delivery.Your organisation operates the broker, PostgreSQL, portal, reverse proxy, certificates, updates, and backups.
Monitoring server exposureNo inbound connection. The connector initiates outbound HTTPS.No inbound connection. The connector initiates outbound HTTPS to your broker.
Broker and portal accessManaged service over public HTTPS.Reachable by authorised apps and connectors over TCP 443 through your selected access path.
Inbound portsNo inbound Server Alerts ports in the monitoring network.TCP 443 at the broker. TCP 80 is optional for ACME. PostgreSQL 5432 and broker 8080 stay private.
Monitoring dataStored in the managed Server Alerts database.Snapshots, queues, users, dashboards, alerts, and audit records stay in your PostgreSQL database.
IdentityManaged accounts and configured organisation SSO.Local portal roles, seat controls, administration, and per-organisation OIDC.
HTTPS certificatesProvisioned and monitored by LCW Labs.Automatic public HTTPS or your own public/internal CA certificate. Internal CA trust must also be deployed to every client device.

Self-hosted requirements

A production-shaped deployment you operate.

The supported Compose stack includes the broker, PostgreSQL 16, Caddy HTTPS, private networking, readiness checks, volumes, and backups.

Host

Start with Linux, 2 vCPU, 4 GB RAM, 20 GB persistent storage, Docker Engine and Compose, DNS, and time synchronisation.

Network

Inbound TCP 443, optional TCP 80 for ACME, and outbound TCP 443 for identity, licensing, updates, and push relay.

Operations

Your organisation manages availability, certificates, backups, disaster recovery, access, and supported updates.

HTTPS certificates

Automatic public HTTPS or your own certificate.

An internally issued certificate works when its CA trust is installed on every mobile device and browser accessing the broker.

Public certificateSimplest for app access across managed and unmanaged networks.
Internal CASuitable for private access with centrally managed client trust.
Private servicesPostgreSQL and the internal broker port stay off the public network.