Browse guides

Operate

Deployment and responsibilities

Shared hosted, dedicated and on-premises FDIE, with an explicit division of operating responsibilities.

Guide type: Deployment guide

In this guide
Deployment and responsibilities
ModelOperatorCommercial / data scope
Self-service hostedMagdox operates the shared platformShared cloud in India; subscribed seats, storage and monthly analyses
Enterprise hostedMagdox operates the agreed shared or dedicated deploymentLocation, capacity, support, retention and recovery in the Order Form
On-premises / air-gappedCustomer operates the stack unless managed services are agreedEnterprise licence, approved release bundle, local identity/storage/network and offline update process
FDIE deployment: logical data flow
  1. 01 · Browser → frontend / API

    Authorised uploads, sign-in, review and exports over TLS.

  2. 02 · API → records and storage

    Organisation records in PostgreSQL; firmware and artifacts in approved storage.

  3. 03 · Queue → analysis workers

    Background extraction, identification, checks and report generation.

  4. 04 · Workers → runtime sandbox

    Supported emulation and fuzzing under resource and network restrictions.

  5. 05 · Results → reviewer

    Findings, coverage and evidence returned for human decisions.

  6. 06 · Optional connections

    Identity, feed updates, monitoring and notifications: permit explicitly or provide local alternatives.

Hosted: Magdox operates the agreed platform. On-premises: these components run in the customer environment. Identity and outbound paths require deployment-specific configuration.

Use a server or container platform

FDIE's API, database, durable queue, long-running workers and execution sandboxes require persistent infrastructure. A static website or request-only serverless function is not the complete FDIE deployment. Container orchestration can separate workers and scale the queue; size it using representative extraction and runtime workloads.

Capacity and production prerequisites

  • Use a supported Linux container host, Docker Engine and Compose v2 for the delivered Compose profile. Match the supplied image architecture; do not assume every release supports ARM.
  • Agree CPU, RAM, fast temporary disk and retained storage for your image size and concurrency. Worker, database and sandbox limits must fit the host together. A small evaluation configuration is not a production capacity guarantee.
  • Provide HTTPS, internal DNS, trusted certificates, clock synchronisation, a customer identity provider where required, restricted administrative access and monitored storage.
  • Keep databases, caches and sandbox control interfaces private. Expose only approved application ingress; do not publish the container runtime socket.
  • Name the owner for host patching, image upgrades, identity recovery, backups, restore tests, monitoring and incident response.
  • Security updates for an on-premises installation are provided while your FDIE subscription or support agreement is active, for the release Magdox currently supports under it, through the agreed delivery channel.

Agree recovery by scenario

Define database and object-storage recovery together. Replication alone is not a point-in-time backup and can propagate deletions. A standby server cannot recover records if its backup source is unavailable. Record backup retention, restore access, deletion replay, tested RPO/RTO and regional-outage scope for the actual deployment; another product's recovery targets do not apply automatically.

Prepare an offline installation

Read the combined Information Security Addendum

Production acceptance for the agreed profile

Production acceptance for the agreed profile
AreaAcceptance evidenceResponsible owner
Identity and accessSign-in, role assignment, MFA/SSO where enabled and account recovery testedApplication and identity operators
Analysis capacityRepresentative images complete within the agreed limits; failures remain visibleAnalysis operator and customer engineering
Storage and recoveryDatabase and object restoration tested together with retention and deletion handlingDeployment operator
External connectionsFeed updates, notifications and integrations match the approved network policyNetwork and application operators
OperationsNamed patching, monitoring, incident and upgrade proceduresThe parties named in the deployment agreement

Record the results for the actual deployment. A configuration file or another customer's capacity test does not establish your recovery time, performance or isolation boundary.