Secure cloud-to-device connectivity appliance

VANDA

The device reaches out. Nothing reaches in.

A network appliance that bridges your cloud infrastructure with field devices — inside networks you don't control, without touching a single firewall rule.

OutboundVPN only 0Firewall changes Multi-tenantIsolation
What it is

Cloud-to-device connectivity, without the firewall fight.

VANDA is an appliance that lets your cloud services reach devices deployed inside customer networks you neither control nor can reconfigure. It powers on, dials out, and the link is established — no inbound rule, no client IT ticket.

Reaches out only

The VPN tunnel is always initiated by the device. No inbound traffic, ever — the attack surface from outside is simply not there.

Zero client-side config

No firewall exceptions, no infrastructure changes on the client's side. Drop it in a locked-down network and it just works.

Multi-tenant isolation

Rigorous VPN routing keeps every client network structurally separate — no traffic can cross between tenants, by design.

Hardware or software

The same stack ships as a physical appliance or runs as software on your existing on-premise servers and field units.

Designed and manufactured end-to-end by Thelis — proven in production across five industry sectors.

Specifications

How it connects.

Connectivity

TunnelOutbound-only VPN
VPN technologyOpenVPN
Inbound trafficNone — zero firewall exceptions
Tenant isolationPer-client VPN routing

Provisioning & management

ProvisioningAutomated, CRM-authenticated
First bootPlug-and-play, secure auto-discovery
ManagementCentralized, cloud-based

Deployment

FormHardware appliance or software
Runs onOn-premise servers · field units
FootprintMinimal — no inbound dependency

Platform

OSEmbedded Linux
Hardware specsOn request
PowerOn request

Hardware variant specifications confirmed per deployment. Contact us for the full datasheet.

Where it fits

One connectivity fabric, many fields.

Remote device access

Reach and operate equipment deployed across customer sites — time-management terminals, access control, monitoring — as if it were on your own network.

Field & mobile maintenance

Maintain mobile units in the field — including truck-mounted systems — over the same secure tunnel, wherever they connect from.

Centralized cloud services

Deliver cloud-based services that depend on direct, reliable communication with distributed on-site hardware — without hosting compromises.

Regulated & secure environments

Operate where strict network policies forbid inbound access — VANDA's outbound-only model keeps you compliant and the client's IT untouched.

Why VANDA

Connectivity without the compromise.

No firewall changes

The device reaches out; nothing reaches in. No inbound rules, no exceptions, no burden on the client's infrastructure team — ever.

Structural isolation

Multi-tenant separation is enforced at the routing level — not a config you can mistakenly disable, but a guarantee built into the architecture.

No infra dependency

Deploy without relying on the client's network team. Automated provisioning means every unit is plug-and-play from first boot.

Deploy & operate

Power on. Dial out. Manage from the cloud.

01

Power on

Install the appliance — or the software — inside the target network and power it up. No on-site configuration required.

02

Dial out

It authenticates against the central CRM and opens an outbound VPN tunnel automatically — no inbound rule, no firewall change.

03

Manage from the cloud

Your cloud services now reach the field devices behind it — securely, in isolation, regardless of the network they sit in.

800+ Devices under management
~400 Active VPN tunnels
5 Industry sectors
0 Client-side network changes
Book a demo

Reach every device,
change no firewall.

Tell us about your fleet and your network constraints, and we will show VANDA bridging your cloud to the field — live.