THINREMOTE vs EWON TALK2M

Operate the whole device, not just tunnel to the PLC

Ewon puts a rugged VPN router in front of a machine so an engineer can reach the PLC behind it through Talk2M. ThinRemote takes a different route: a software agent on the device itself that adds observability, SSH, web-service access, remote desktop, files and fleet automation, with no appliance to buy.

VS
A VPN router reaches
PLC · Line 1behind Cosy 131 box
HMI · Cell 4behind Flexy 205 box
PLC · Line 7router offline box
one appliance per machine, the PLC behind it
ThinRemote operates
Gateway 14 · Madridonline · CPU 12% Disk 92%
Edge PC 27 · Lyononline · SSH · Web UI
Panel 41 · Turinonline · fw 2.4.1
any device, fully observable and operable

Two different approaches

This is not a like-for-like contest. Ewon is a hardware VPN appliance built to reach the equipment behind it; ThinRemote is a software agent built to operate the device it runs on. The real question is what your team actually needs to do once it connects.

Ewon: the VPN appliance

A Cosy or Flexy industrial router sits on the machine's LAN and brokers a secure VPN through the Talk2M cloud, so an engineer can reach the PLC or HMI behind it. It is a proven, PLC-oriented, ruggedized product, and the Flexy adds fieldbus data acquisition. It is also a box you buy, wire in and maintain for each machine or site.

ThinRemote: the software agent

One small outbound agent runs directly on any Linux device, gateway or edge computer and gives you live telemetry, alarms, SSH, web-service access, remote desktop, files, fleet automation and an MCP server for AI agents, out of the box. No proprietary hardware, and you manage the whole device, not only the tunnel to a controller.

Hardware vs software

No appliance to buy, ship or rack

With Ewon, remote access starts with hardware: a Cosy or Flexy router per machine or site, wired into the LAN, powered, provisioned and kept up to date. That box is exactly what makes it robust, and it is also inventory, lead time and a spare you keep on the shelf for every deployment.

ThinRemote is a single static binary, under 10 MB, that you install on hardware you already have. It runs on almost anything, from a modern edge server to a years-old industrial box (kernel 2.6 and up, 16 architectures), makes one outbound connection and changes nothing about the device's own networking. Add a device by installing the agent, not by ordering a router.

thinr-agent< 10 MB
1 static binarykernel 2.6+16 architecturesno applianceno open ports
Installs on
Pi / SBC IPC / edge PC Linux gateway Panel PC Cloud VM
Nothing to procureAdd a device by installing the agent, not by ordering and wiring a router.
Tiny footprintOne static binary under 10 MB, kernel 2.6+, across 16 architectures.
No network surgeryAn app-layer agent: no new hardware on the LAN, no route or interface changes.
Observability & alarms

See the device's health, not just reach the PLC

Ewon's data features are built around the equipment on the machine LAN: a Flexy can poll PLC and sensor tags over Modbus, EtherNet/IP, OPC UA and more, log them and raise tag-based alarms by email or SMS. That is genuinely useful for process values, and it is aimed at the controller, not at the box doing the connecting.

ThinRemote reports the health of the device itself. Every agent publishes a structured monitoring resource: CPU and load, memory, per-filesystem usage, network throughput, temperature and uptime, shown on per-device and per-fleet dashboards and wired into threshold alarms over email or webhook. Expose any value from a small script and it becomes a first-class metric you can chart, roll up across the fleet and alarm on, no extra gateway required.

Monitorgateway-14 Online
12%
CPU
47%
Memory
92%
Disk
Network 210 B/s 188 B/s
Disk almost fulldisk.usage 92.0
High Temperaturecpu.temperature 71.5
Host-level telemetryCPU, memory, disk, network, temperature and uptime, out of the box.
Define your own metricsTurn any value a script reports into a tracked, chartable metric.
Alarm on anythingBuilt-in or custom metric, with severity and email or webhook notifications.
Access surfaces

Reach the whole device, not just a VPN tunnel

A Talk2M session gives you network reach to the equipment behind the router, and then you bring your own tools over it. That is the right model when the thing you care about is a PLC or HMI on the far side of the box.

ThinRemote treats the device as something you operate directly. Over the same outbound agent you get an in-browser terminal and SSH, a file explorer, remote desktop, and HTTP/TCP/TLS tunnels to any local web UI or service, plus the ability to turn a script into a named, callable device API. And you drive it three ways over one auth model: a web console, a scriptable CLI with JSON output, and a built-in MCP server for AI agents.

Web console
Dashboards Terminal / SSH Files Remote desktop Web services
CLI
SSH Tunnels Exec Playbooks JSON
MCP server
AI agents Natural language Same RBAC
Shell, files & desktopIn-browser terminal and SSH, a file explorer and remote desktop on the device.
Web-service accessHTTP/TCP/TLS tunnels to any local UI or API, no inbound port opened.
Three surfaces, one authWeb console, CLI and MCP server under the same roles and tokens.
Automation & pipelines

Fix it once, roll it out to the whole fleet

Ewon is configured per unit: each Cosy or Flexy is provisioned and updated as its own device, which is a natural fit when a machine builder ships one box with one machine. Applying the same change across hundreds of them is a job you take on yourself.

ThinRemote makes the whole fleet programmable. It brings playbooks: describe a change once, try it on a single device in check mode, then roll it out across the product in controlled batches that stop on their own if too many devices fail. The same flow runs from your terminal, a CI/CD pipeline over the CLI's JSON output and exit codes, or an AI agent over MCP, all under the same roles and tokens.

Rollout · agent-update400 devices
Batch 1100 ✓
Batch 2100 ✓
Batch 358 / 100
Batch 4queued
Failure rate 1.2% kill-switch at 25%
Fleet playbooksDescribe a change once and run it across the whole product.
Safe by defaultCheck mode on one device, then batch the rollout with a kill-switch if too many fail.
Pipeline-nativeDriven from CI/CD, cron or an AI agent over the built-in MCP server.
Security & connection model

Outbound-only, on both sides

Both products share a sound core idea: the device dials out, so there is no inbound port to open on the plant firewall. Ewon does this well, and does it in hardware. The Cosy+ adds a secure element for a hardware root of trust, secure boot and x509 TLS, and the Talk2M cloud it connects to is ISO 27001 certified. That is a real strength worth acknowledging.

ThinRemote reaches the same outbound-only posture in software. The agent opens a single outbound connection over TLS 1.3, exposes no listening port, and access is brokered through the cloud with token-scoped RBAC and an audit trail shared across the web console, CLI and MCP. Thinger.io, the platform behind ThinRemote, is ISO 27001 certified.

Ewonhardware router in front of the PLC
PLC / HMIfield deviceLANEwon routerCosy / Flexy · hardwareoutboundTalk2MVPN brokerVPN clientEngineereCatcher
ThinRemotesoftware agent on the device itself
Any Linux device+ thinr agent (outbound)TLS 1.3ThinRemotecloud relayRBACWeb · CLI · MCPSSH · files · desktop

Both dial out, so no inbound port is exposed. Ewon brokers a VPN to the PLC behind a hardware router; ThinRemote brokers operator access to the whole device in software.

Nothing listensThe agent only dials out: no inbound port, no listening service to attack.
RBAC, tokens & auditScoped roles and tokens with an audit trail, identical across web, CLI and MCP.
TLS 1.3, ISO 27001 certifiedEncrypted outbound transport; ISO 27001 certified.
AI-native

Drive the whole fleet in plain language

Ewon's world is a VPN and a set of industrial protocols. There is no AI-agent surface to point a model at, so anything an assistant might do you would have to build and maintain yourself on top of the connectivity.

ThinRemote ships an MCP server built into the CLI. Point Claude, Cursor or any MCP client at it and it can list devices, read live metrics, run commands, tail logs, open tunnels and roll out playbooks, all in plain language and all under the same roles and tokens as your team. Ask "which gateways are low on disk?" or "roll the update to Madrid first", and it acts on the real fleet.

AI agentvia thinr MCP
Which edge gateways are low on disk?
thinr product edge-fleet monitoring --json
3 over 85%: Gateway 14, Edge PC 27, Panel 41.
Roll the cleanup playbook to those three.
thinr product edge-fleet playbook rollout disk-cleanup
Done on 3 / 3.
Natural-language opsAsk in plain words; it lists, inspects and acts on real devices.
Same guardrailsAn agent gets the same roles, tokens and scoping as a human user.
Any MCP clientClaude, Cursor or your own tools, registered in one command.

The full breakdown

The details a technical evaluator actually compares, side by side. Ewon here means the Cosy / Flexy routers together with the Talk2M cloud.

Platform, footprint & deployment

Dimension
ThinRemote
Ewon (Cosy / Flexy + Talk2M)
Form factor
Software agent
Hardware VPN router + cloud
What you install
A single static binary on hardware you already own
A Cosy or Flexy appliance per machine or site, wired into the LAN
Where it runs
Any Linux device, gateway, IPC, SBC, panel PC or cloud VM
Runs on the Ewon device; reaches PLCs/HMIs on its machine LAN
Architectures / OS
16 CPU architectures, Linux kernel 2.6+, containers
Fixed to Ewon's own firmware and hardware models
Footprint
< 10 MB static binary, no interface or route changes
A dedicated physical device (power, DIN-rail space, spares)
Connectivity / WAN
Any existing link: Ethernet, Wi-Fi, cellular, behind NAT/CGNAT/firewalls
Ethernet, Wi-Fi and cellular WAN options on the hardware
Open inbound ports
None; outbound-only over TLS 1.3
None; outbound-only over HTTPS 443 / OpenVPN UDP 1194

Features & operations

Capability
ThinRemote
Ewon (Cosy / Flexy + Talk2M)
Primary purpose
Whole-device management & access
Secure VPN access to PLCs/HMIs
Remote SSH / terminal
In-browser terminal and SSH to the device, no inbound port
Reach the device over the VPN, then use your own SSH client
Device observability
Host metrics (CPU, memory, disk, network, temperature, uptime) plus custom metrics, on dashboards
Flexy logs PLC/sensor tags (Modbus, OPC UA, etc.); host-level metrics are not the focus
Web-service / HTTP proxy
HTTP/TCP/TLS tunnels to any local UI or service
M2Web browser access to HTTP/VNC/RDP endpoints on the LAN
Remote desktop
Remote desktop to the device when it has a GUI
RDP/VNC to machines on the LAN over the VPN or M2Web
Filesystem access
Built-in file explorer and transfer to the device
Not a feature of the router; use your own tools over the VPN
Alarms & thresholds
Native over metrics & events (email / webhook)
Flexy tag alarms with email / SMS / SNMP notification
Fleet automation
Playbooks (check mode, batched rollout, failure kill-switch), parallel product exec
Per-unit configuration; fleet-wide change is bring-your-own
CI/CD & scripting
CLI with JSON output and exit codes; ad-hoc & stored playbooks
On-device BASIC / Java scripting on the Flexy; APIs for Talk2M
RBAC & audit
Token-scoped RBAC and audit trail across web, CLI and MCP
User groups, device pools and access rights (Talk2M Pro)
Certifications
ISO 27001 certified
Talk2M is ISO 27001 certified today; Cosy+ has a hardware secure element
Industrial fieldbus
Not a PLC-protocol gateway; tunnels to services and runs scripts
Deep native support (Modbus, EtherNet/IP, PROFINET, OPC UA, serial) on the Flexy
AI agents (MCP)
Built-in MCP server to drive the fleet in natural language
None built in

A fair reading: Ewon is purpose-built to reach a PLC behind a rugged router, and it is very good at that. Several ThinRemote advantages here come from being a software agent that operates the whole device, which is a different job. Talk2M plan limits (for example, concurrent VPN connections) vary by tier; check the current Ewon plans for specifics.

Where Ewon is the better fit

Different jobs. If the problem is reaching a controller behind a rugged box, reach for Ewon.

A PLC you can't put software on

When the target is a PLC or HMI you can't or won't install an agent on, a hardware router in front of it, isolating the machine LAN, is exactly the right tool.

Deep fieldbus data acquisition

Native Modbus, EtherNet/IP, PROFINET, OPC UA and serial polling of PLC tags, with on-device logging, is the Flexy's home turf.

Rugged hardware & a certified cloud

DIN-rail hardware for harsh environments, a hardware root of trust on the Cosy+, and an ISO 27001 certified Talk2M cloud available today.

Plenty of sites run both: an Ewon router where a PLC needs one, ThinRemote to operate the Linux gateways, IPCs and edge computers around it.

So, which one?

Pick by the question you're actually trying to answer.

DEVICE OPS

Choose ThinRemote

"I need to operate, observe and fix a fleet of Linux devices, no new hardware."

  • Observability & access in softwareMetrics, alarms, SSH, files, desktop and web-service tunnels from one agent.
  • Fleet automation & AIPlaybooks, batched rollouts, CI/CD and a built-in MCP server.
  • No appliance, opens nothingTiny static agent on hardware you own, outbound-only over TLS 1.3.
Get Started
PLC VPN

Choose Ewon

"I need a rugged VPN box to reach a PLC or HMI behind it."

  • Hardware in front of the machineA rugged router that isolates the machine LAN and reaches the controller.
  • Fieldbus data acquisitionNative Modbus, EtherNet/IP, PROFINET, OPC UA and serial on the Flexy.
  • Certified cloud & secure elementISO 27001 Talk2M and a hardware root of trust on the Cosy+.
See how ThinRemote pairs

Operate the whole device, no appliance required

Install the agent in seconds and get observability, SSH, web-service access, remote desktop, files and fleet automation from one outbound connection.