Infowin Hybrid Vault

Your Data, Your Rules

Infowin Hybrid Vault — Double-Tunnel Hybrid Private Cloud

System logic evolves in the cloud; raw data stays permanently in your internal network. We only transmit computation commands.

Double-Tunnel Architecture

Infowin uses the industry-leading Double-Tunnel architecture, physically separating the 'system command flow' from the 'personnel access flow', ensuring data is encrypted on every path.

Cloud Logic Layer

UI / Business Logic / AI Algorithms — maintained and auto-updated by Infowin

System Command Flow

Self-hosted mTLS Tunnel

Cloud UI sends computation commands to on-premises via mutual TLS tunnel. Raw data never leaves your server.

Personnel Access Flow

Cloudflare Zero Trust

Authorized personnel access securely via Cloudflare WARP — no firewall ports needed (Elite plan)

On-Premises Server Room

PostgreSQL + Redis, deployed in 192.168.x.x internal network, IP never exposed to public internet

We only transmit computation commands. Raw data stays permanently in your internal network (192.168.x.x)

Why Choose Hybrid Vault?

Complete three-way deployment comparison

Traditional Cloud SaaS
Traditional On-Premise
Infowin Hybrid VaultRecommended
Data StorageVendor's cloud serversClient's own serversClient's own servers
System UpdatesAutomatic, always latestManual, often outdatedAutomatic, always latest
Maintenance CostZeroRequires dedicated ITMinimal (Infowin monitors)
Data SovereigntyAt vendor's facility100% self-owned100% self-owned
Remote AccessAnywhere, anytimeOffice LAN onlyZero Trust encrypted tunnel
Security IsolationDepends on vendorDepends on in-house ITRLS + mTLS + Audit Log
總結Data is at someone else's placeFeatures never updateLogic evolves in cloud, data guarded on-premise

Plans & Pricing

Choose the right data protection plan for your organization

Standard Cloud

General businesses, small landlords

Setup FeeNT$ 0
Monthly MaintenanceNT$ 0
SaaS Monthly FeeStandard pricing
Anywhere, anytime

Secure, reliable, zero overhead. Ideal for clients who prioritize convenience.

開始使用
Data On-Premise

Private Cloud Basic

Established temples, mid-size firms

Setup FeeFrom NT$ 58,000
Monthly MaintenanceNT$ 2,500 / month
SaaS Monthly FeeStandard pricing
Office LAN only

Data on-premise, century-long legacy. For institutions demanding ultimate privacy and only need to operate within the office.

預約諮詢
Military-Grade

Private Cloud Elite

Century-old temples, international law firms

Setup FeeFrom NT$ 128,000
Monthly MaintenanceNT$ 6,000 / month
SaaS Monthly FeeStandard pricing
Zero Trust encrypted remote tunnel

Borderless office, military-grade protection. Integrated Cloudflare global nodes to securely control on-premise data from anywhere in the world.

預約諮詢

* Setup fee includes: on-site/remote assessment, Docker deployment, mTLS tunnel setup and security testing

* Maintenance fee includes: 24/7 tunnel monitoring, auto Schema sync, Cloudflare Zero Trust management (Elite)

Three Security Mechanisms

Row-Level Security (RLS)

Enforced at the database engine level. Even on shared infrastructure, Tenant A's data is completely invisible to Tenant B. Even Infowin engineers cannot cross-tenant read.

Complete Audit Trail

Every read, modification, and deletion is recorded with tamper-proof logs: who, what time, what command. Compliant and auditable by authorities.

Encrypted Transport (mTLS)

All command communications use AES-256 encryption and TLS 1.3 protocol. Mutual mTLS authentication ensures only authorized endpoints can communicate.

Four Steps to Deploy

01

One-Click Install Script

IT staff completes local database deployment in 10 minutes

02

Encrypted Tunnel Connection

Cloud app reads/writes to local DB via mTLS encrypted tunnel

03

Automatic Version Sync

Schema Migration executes automatically, local DB structure syncs with cloud upgrades

04

Physical Isolation Protection

External internet cannot directly probe or access the local DB

Technical Specifications

Transport EncryptionAES-256 GCM, TLS 1.3
Data IsolationPostgreSQL RLS
DeploymentDocker / One-click install script
System Command FlowgRPC / REST over mTLS
Personnel Access FlowCloudflare Tunnel (Elite)
DB Version SyncSchema Migration auto-executed
Disaster RecoveryLocal Backup + Encrypted Cloud Backup
MonitoringCloud health check (no data content access)
Stealth DefenseCloudflare Tunnel — DB IP never exposed

Data Sovereignty Guarantee

01

Absolute Ownership

Clients have 100% ownership and disposal rights over all raw data stored on their local servers.

02

Physical Isolation

Cloud systems only send query commands when executing business logic. Raw data is not permanently stored on cloud servers.

03

Anti-Probing

Database is on internal network (192.168.x.x) using Cloudflare Tunnel. IP is never exposed to public internet.

Unless authorized in writing by the client or required by law, Infowin engineers shall not proactively read the specific content of client on-premises data.

IBM-Grade Enterprise Architecture in Every Line of Code

Infowin is led by a technical team with NTU master's degree, former IBM software engineer, and university lecturer backgrounds. We combine academic rigor with hands-on operations across large-scale property management, IoT rollouts, and education sites to build the highest-caliber digital fortress for clients.

🎓National Taiwan University, Master's Degree
📚Chung Yuan University, Adjunct Lecturer
💼Former IBM Software Engineer

We run the same stack every day across large-scale property, tenants, students, and clients — refined through long-haul field iteration and daily operations.

Michael Chen (陳胤辰)

Founder & CTO

FAQ

Will the local database fall behind cloud updates?

No. Each time the cloud releases new features, Schema Migration automatically executes field/index updates on the local DB to stay in sync.

Can Infowin engineers see my data?

Cloud plan: RLS intercepts at the database level — engineers cannot cross-tenant read. Hybrid plan: data is in your LAN, we cannot even touch the raw data.

I don't have IT staff. Can I use Hybrid Vault?

Yes. We provide on-site installation + remote monitoring (system metrics only, no data content). You can migrate back to cloud anytime.

What are the costs for the local plan?

SaaS monthly fee unchanged, plus a one-time deployment fee (from NT$58,000) and monthly maintenance fee. Contact sales for details.

Can I switch from cloud to Hybrid later?

Yes. Our architecture supports bidirectional migration — cloud to local, or local back to cloud, both achievable with our tools.

What does the Vault console look like?

The Vault console is a complete management interface where you can view connection status, manage keys, and review audit logs.

Go to Vault Console

Book a Hybrid Vault Architecture Consultation

Let our architects design the optimal deployment plan for your institution

© 2026 Infowin Technology Co., Ltd. · Hybrid Vault