Hybrid Deployment
TargetBoard's hybrid deployment option allows you to keep sensitive data and selected infrastructure in your own environment while TargetBoard runs the rest as a managed SaaS platform. TargetBoard op…
TargetBoard's hybrid deployment option allows you to keep sensitive data and selected infrastructure in your own environment while TargetBoard runs the rest as a managed SaaS platform.
TargetBoard operates the application, integrations, and authentication. You choose whether to host the data layer and AI components yourself or leave them with TargetBoard.
Architecture
Te deployment has three parts: the customer's source systems, components managed by TargetBoard, and components that can run in either environment.
Component | Role | Hosted by |
Customer applications | Source systems TargetBoard reads data from; only customer-authorized data is accessed. | Customer |
ETL and integration services | Collect, process, and normalize data from source systems. | TargetBoard |
Authentication Manager and Key Vault | Store and manage integration credentials used by ETL services. | TargetBoard |
TargetBoard application servers | Stateless servers that power dashboards, metrics, analytics, alerts, and AI features. | TargetBoard |
User authentication | Authenticates users on web and mobile clients. | TargetBoard |
Customer database (PostgreSQL) | Stores the customer's processed data. | Customer or TargetBoard |
Cache (Redis) | Speeds up application reads. | Customer or TargetBoard |
Database backups | Backups of the customer database. | Customer or TargetBoard |
LLM API (ChatGPT) | Powers AI features. No conversation history is recorded; supports a customer-provided API key. | Customer or TargetBoard |
Data Flow
Data moves in one direction, from source systems to authenticates users:
- TargetBoard ETL pulls authorized data from the customer's systems, using credentials held in the key vault.
- ETL normalizes the data and writes it to the configured PostgreSQL database, which is backed up.
- Stateless TargetBoard servers read from the database and Redis cache. calling the LLM API for AI features.
- Users sign in through Auth0 and access the platform from web or mobile clients.
Why Hybrid?
- Data control - operational data can stay in customer-controlled infrastructure.
- SaaS simplicity - TargetBoard continues to operate, update, and maintain the application.
- Enterprise security - authorized-only integrations, centralized credential management, and SSO.
- AI governance - use your own approved LLM account and API key; no conversation history is retained.
- Flexibility - the setup adapts to security, compliance, networking, and data-residency requirements.
How did we do?
Connecting Okta SSO
IP Addresses to Whitelist