Private deployment. Clear control boundaries.
Review how the public site, Endpoint control plane, operational data, remote support and managed endpoints are separated before a pilot begins.
Agents connect outbound to the control plane.
Routine state reporting and authorized work do not require opening a general inbound management port on each endpoint.
Outbound-first agent path
Heartbeat, inventory and routine management originate from the endpoint toward the approved product service.
Identity before action
Enrollment, persistent device identity and administrator authorization are separate controls.
Governed operations
Actions pass through job, role and tenant boundaries and retain result context.
Product information and public documentation. Endpoint operational data is not required for this service.
Assign each service before rollout.
A pilot topology should name who operates each service, where product data is stored and who owns backup, recovery and upgrades.
| Area | Owner | Data / responsibility | Boundary |
|---|---|---|---|
| Public website | ZENQIX | Product information and public documentation | No customer endpoint state required |
| Control plane | Deployment owner | Device identity, state, jobs and product policy | Private product-service boundary |
| Operational data | Deployment owner | PostgreSQL device state, inventory and evidence | Backup and retention owner required |
| Remote support | Deployment owner / approved operator | Session authorization, target identity and lifecycle evidence | Separate support path |
| Endpoint agent | Customer endpoint | Heartbeat, inventory, capability and authorized work | Outbound-first routine communication |
Current and future operating models.
Customer-controlled / private
Private PilotProduct services run in infrastructure the organization controls or explicitly approves.
ZENQIX-managed
PlannedA managed service will only be published when its support, monitoring, backup and operating model is ready.
Hybrid
PlannedFuture models may separate selected services while preserving agreed data and policy boundaries.
Resolve ownership before installing agents.
Approved hostname, DNS, TLS, proxy and firewall requirements.
Database owner, backup location, retention and restore responsibility.
Technician authorization, device scope and session lifecycle.
Who approves upgrades, validates health and triggers rollback.
Desktop endpoint operations first
Capability status remains platform-specific. Android and iOS/iPadOS are not current commercial UEM claims.
Review capability matrixReview deployment against your environment.
Use the architecture guide and evaluation checklist to record network, ownership, backup and platform requirements before a pilot starts.