VANDA
The device reaches out. Nothing reaches in.
A network appliance that bridges your cloud infrastructure with field devices — inside networks you don't control, without touching a single firewall rule.
Cloud-to-device connectivity, without the firewall fight.
VANDA is an appliance that lets your cloud services reach devices deployed inside customer networks you neither control nor can reconfigure. It powers on, dials out, and the link is established — no inbound rule, no client IT ticket.
Reaches out only
The VPN tunnel is always initiated by the device. No inbound traffic, ever — the attack surface from outside is simply not there.
Zero client-side config
No firewall exceptions, no infrastructure changes on the client's side. Drop it in a locked-down network and it just works.
Multi-tenant isolation
Rigorous VPN routing keeps every client network structurally separate — no traffic can cross between tenants, by design.
Hardware or software
The same stack ships as a physical appliance or runs as software on your existing on-premise servers and field units.
Designed and manufactured end-to-end by Thelis — proven in production across five industry sectors.
How it connects.
Connectivity
Provisioning & management
Deployment
Platform
Hardware variant specifications confirmed per deployment. Contact us for the full datasheet.
One connectivity fabric, many fields.
Remote device access
Reach and operate equipment deployed across customer sites — time-management terminals, access control, monitoring — as if it were on your own network.
Field & mobile maintenance
Maintain mobile units in the field — including truck-mounted systems — over the same secure tunnel, wherever they connect from.
Centralized cloud services
Deliver cloud-based services that depend on direct, reliable communication with distributed on-site hardware — without hosting compromises.
Regulated & secure environments
Operate where strict network policies forbid inbound access — VANDA's outbound-only model keeps you compliant and the client's IT untouched.
Connectivity without the compromise.
No firewall changes
The device reaches out; nothing reaches in. No inbound rules, no exceptions, no burden on the client's infrastructure team — ever.
Structural isolation
Multi-tenant separation is enforced at the routing level — not a config you can mistakenly disable, but a guarantee built into the architecture.
No infra dependency
Deploy without relying on the client's network team. Automated provisioning means every unit is plug-and-play from first boot.
Power on. Dial out. Manage from the cloud.
Power on
Install the appliance — or the software — inside the target network and power it up. No on-site configuration required.
Dial out
It authenticates against the central CRM and opens an outbound VPN tunnel automatically — no inbound rule, no firewall change.
Manage from the cloud
Your cloud services now reach the field devices behind it — securely, in isolation, regardless of the network they sit in.
Reach every device,
change no firewall.
Tell us about your fleet and your network constraints, and we will show VANDA bridging your cloud to the field — live.
