Dimension
ThinRemote
Ewon (Cosy / Flexy + Talk2M)
Form factor
Software agent
Hardware VPN router + cloud
What you install
A single static binary on hardware you already own
A Cosy or Flexy appliance per machine or site, wired into the LAN
Where it runs
Any Linux device, gateway, IPC, SBC, panel PC or cloud VM
Runs on the Ewon device; reaches PLCs/HMIs on its machine LAN
Architectures / OS
16 CPU architectures, Linux kernel 2.6+, containers
Fixed to Ewon's own firmware and hardware models
Footprint
< 10 MB static binary, no interface or route changes
A dedicated physical device (power, DIN-rail space, spares)
Connectivity / WAN
Any existing link: Ethernet, Wi-Fi, cellular, behind NAT/CGNAT/firewalls
Ethernet, Wi-Fi and cellular WAN options on the hardware
Open inbound ports
None; outbound-only over TLS 1.3
None; outbound-only over HTTPS 443 / OpenVPN UDP 1194
Capability
ThinRemote
Ewon (Cosy / Flexy + Talk2M)
Primary purpose
Whole-device management & access
Secure VPN access to PLCs/HMIs
Remote SSH / terminal
In-browser terminal and SSH to the device, no inbound port
Reach the device over the VPN, then use your own SSH client
Device observability
Host metrics (CPU, memory, disk, network, temperature, uptime) plus custom metrics, on dashboards
Flexy logs PLC/sensor tags (Modbus, OPC UA, etc.); host-level metrics are not the focus
Web-service / HTTP proxy
HTTP/TCP/TLS tunnels to any local UI or service
M2Web browser access to HTTP/VNC/RDP endpoints on the LAN
Remote desktop
Remote desktop to the device when it has a GUI
RDP/VNC to machines on the LAN over the VPN or M2Web
Filesystem access
Built-in file explorer and transfer to the device
Not a feature of the router; use your own tools over the VPN
Alarms & thresholds
Native over metrics & events (email / webhook)
Flexy tag alarms with email / SMS / SNMP notification
Fleet automation
Playbooks (check mode, batched rollout, failure kill-switch), parallel product exec
Per-unit configuration; fleet-wide change is bring-your-own
CI/CD & scripting
CLI with JSON output and exit codes; ad-hoc & stored playbooks
On-device BASIC / Java scripting on the Flexy; APIs for Talk2M
RBAC & audit
Token-scoped RBAC and audit trail across web, CLI and MCP
User groups, device pools and access rights (Talk2M Pro)
Certifications
ISO 27001 certified
Talk2M is ISO 27001 certified today; Cosy+ has a hardware secure element
Industrial fieldbus
Not a PLC-protocol gateway; tunnels to services and runs scripts
Deep native support (Modbus, EtherNet/IP, PROFINET, OPC UA, serial) on the Flexy
AI agents (MCP)
Built-in MCP server to drive the fleet in natural language
None built in