Nothing leaves your building.
The intelligence runs on the appliance in your building, in your store or your server room, with zero open inbound ports. Not our cloud. Not anyone's. This is the page your IT team can read without a sales call.
Not a better version of the same architecture. A different one.
Every cloud competitor must expose a public login page in order to exist. RetailPulse doesn't have an open port. Each of these is checkable in thirty seconds by anyone who doubts it.
1. Zero open inbound ports.
"The server is invisible to the internet. There is nothing to scan and nothing to knock on."
Nothing listens for the outside world. There is no login page on the internet, because there is no port for one to sit behind.
2. One database per customer.
"There is no shared data pool. A worst case touches one customer and never cascades."
Structural, not policy. A multi-tenant vendor is asking you to trust their access controls; here there is nothing to control access to. The word your CIO already uses is blast radius. Ours is one customer.
3. Your data in your building.
"Self-hosted or on-premise appliance. No cloud dependency in any critical path. No telemetry containing your data."
Local inference. The forecasting, the ordering, the reasoning: all of it runs where the data already lives. It is also why the price doesn't scale with your SKU count: there is no cloud bill underneath it.
4. Kill switch in seconds.
"Drop the tunnel and the system vanishes from the internet, while carrying on fully operational in-store on the LAN."
This answers the question every CIO is actually asking: what can I do at 2am? A cloud vendor's answer to a security incident is to phone someone. Yours is one action, and the stores keep trading.
5. The easiest IT approval in the industry.
"An on-premise appliance needs exactly one outbound HTTPS connection. No firewall changes, no static IP, no port forwarding at your site."
The real objection to on-premise software was never philosophical. It was "we'd have to open ports, get a static IP, involve the network team, and sit in a change queue for six weeks." One outbound HTTPS connection is the same thing your laptops already do.
"A tunnel is a third-party service. Doesn't that contradict 'no cloud dependency'?"
The tunnel is how you reach it remotely. It isn't how it runs. Cut the tunnel and the system keeps trading on your LAN. That's the kill switch. There is no cloud service in the path between your data and your decisions.
Remote access and operational dependency are two different things. We would rather volunteer the distinction than have a good answer ready when challenged.
Every threshold the engines read, on the screen. Every change, audit-logged.
The guard rails are yours to set. Beside each one: the measured recommendation, what it does, and where it is quoted. 47 settings in seven groups, and the spike floor that kept 828 false stockouts out of the queue.
Hard target. Small blast radius. Fast recovery.
We don't say "unhackable". Nobody honest does. We say the target is hard to reach, the damage a worst case can do is bounded to one customer, and recovery is measured in minutes.
- Zero-trust login. Authentication happens before any request reaches a server.
- Automated security patching.
- Keys-only SSH. No password authentication, anywhere.
- Database reachable from localhost only.
- Snapshot-based recovery. Ransomware rollback in minutes, not days.
- POPIA and GDPR. The simplest story there is: your trading data never leaves your control, so it never enters ours. We publish the architecture rather than defend it on request.
We answer security questionnaires directly, and in detail. Ask for the depth layer at hello@retailpulse.co.za.