THINREMOTE vs IXON CLOUD

Connect the machine, or operate the whole device

IXON gets a machine builder a secure VPN to a PLC or HMI and turns machine data into cloud dashboards. ThinRemote is a software agent for any Linux device that gives you the shell, the filesystem, monitoring and fleet automation. Two good tools for two different jobs.

VS
IXON reaches
PLC / HMIVPN to the machine
VNC · HTTPthe machine's own screens
Fieldbus dataOPC-UA · Modbus · S7
Cloud dashboardsmachine visualization
the machine, through a gateway
ThinRemote operates
Root shell & filesSSH, terminal, explorer
System + custom metricsCPU · disk · your values
Playbooks & CI/CDfleet-wide rollouts
Any Linux boxno gateway to ship
the device, as software

Two different jobs

This isn't a feature war, and IXON is very good at what it does. The honest question is whether your problem is getting into an OEM machine or operating a fleet of Linux devices.

IXON: OEM machine connectivity

An IIoT platform for machine builders. Delivered largely through the IXrouter edge gateway (with the IXagent software option for supported controllers), it gives you a secure VPN to any-brand PLC, HMI, IPC or camera, reads machine data over industrial protocols, and turns it into cloud dashboards, data logs and alarms. Its home is the machine you build and ship to customers.

ThinRemote: software fleet operations

A hardware-agnostic remote management platform. One outbound agent on any Linux device gives you SSH and a terminal, the filesystem, system and custom telemetry, alarms, device APIs, fleet playbooks and CI/CD, plus an MCP server for AI agents. Its home is operating and automating the devices you already run, whatever the hardware.

Device targets & footprint

Software on any Linux box, no gateway to ship

IXON's fastest path to a connected machine is its hardware: the IXrouter sits on the machine network and bridges the PLC to the cloud. There's an IXagent software option too, aimed at a curated set of industrial controllers (Sigmatek, Phoenix Contact PLCnext, WAGO, Berghof) and PC-class hosts. It's a great fit when you're building a machine and can specify the box.

ThinRemote is only software. A single static binary under 10 MB installs on almost anything that runs Linux, from a modern server to a years-old industrial gateway (kernel 2.6+, 16 CPU architectures), with no router to source and nothing to rack. If it runs Linux, it runs the agent, so you're never tied to a controller list or a specific gateway.

thinr-agent< 10 MB
1 static binarykernel 2.6+16 architecturesno gateway hardwareno open ports
Runs on
Pi / SBC Edge gateway Industrial PC Linux server Cloud VM
Hardware-agnosticAny Linux device, not a fixed router or a supported-controller list.
Nothing to shipNo edge gateway to source, rack or maintain: install the binary and go.
Any linkWorks behind NAT, CGNAT, corporate firewalls and cellular, no fixed IP.
Operate the OS

A root shell and the filesystem, not just a tunnel to the HMI

IXON's remote access is built around the machine's own interfaces: it tunnels a VPN to the PLC and hands you VNC for the HMI screen, HTTP for a built-in web UI, or a fieldbus session. That's exactly what a service engineer needs to look at a running machine.

ThinRemote operates the device itself. You get an interactive shell and SSH, an in-browser file explorer, remote command execution, and HTTP/TCP/TLS tunnels to any local service, all over the same outbound agent. Read a log, edit a config, restart a service, push a file, on the operating system, not just on the machine's front panel.

edge-gw-17SHELL
SSHinteractive shell→ tty
EXECsystemctl restart app
FILES/etc · /var/log · /opt
TUNNELhttp · tcp · tls→ local svc
Web console CLI Remote desktop
Shell & SSHAn interactive terminal and SSH into the OS, from the browser or the CLI.
Files & commandsBrowse and transfer files, run commands, manage services on the device.
Service tunnelsReach any local HTTP, TCP or TLS service without opening a port.
Observability & alarms

Device health telemetry, not only machine data

Both platforms do telemetry, and it's worth being clear about the difference. IXON shines at machine data: it logs values from the PLC over industrial protocols and turns them into live and historical dashboards, reports and alarms for the equipment you build.

ThinRemote's angle is the device and the OS. Every agent reports a structured monitoring resource, CPU and load, memory and swap, per-filesystem usage, network throughput, temperature and uptime, on per-device and per-fleet dashboards and wired into threshold alarms over email or webhook. And you can expose any value from a small script on the device, a fault code, a queue depth, units in stock, and alarm on it like a built-in metric. Different telemetry for a different job.

Monitoredge-gw-17 Online
14%
CPU
41%
Memory
81%
Disk
Network 164 B/s 265 B/s
High Diskdisk.usage 94.0
Custom · queue depthjobs.pending 512
OS health built inCPU, memory, disk, network, temperature and uptime, out of the box.
Define your own metricsTurn any value a script prints into a tracked, chartable metric.
Alarm on anythingBuilt-in or custom metric, with severity and email or webhook alerts.
Automation & CI/CD

Roll a change across the fleet, not one machine at a time

IXON is API-first: its Open API and Cloud SDK let developers build custom apps and automate the platform, and its Fleet Manager organises devices with metadata and pushes settings and updates. That's a solid foundation you can build on.

ThinRemote ships fleet automation as a product. Playbooks describe a change once, dry-run it on a single device, then roll it out across a whole product in controlled batches that stop on their own if too many devices fail. The same flow runs from your terminal, a CI/CD pipeline, cron, or an AI agent, so operating 400 devices is one command instead of 400 sessions.

Rollout · agent-update400 devices
Batch 1100 ✓
Batch 2100 ✓
Batch 358 / 100
Batch 4queued
Failure rate 1.2% kill-switch at 25%
Fleet playbooksDescribe a change once and run it across the whole product in YAML.
Safe by defaultDry-run on one device, then batch the rollout with a failure kill-switch.
Pipeline-nativeJSON output and exit codes, driven from CI/CD, cron or an AI agent.
Security & connection model

Outbound-only, nothing listening on the device

Here the two are closer than the rest of this page, and that's a good thing. IXON is also outbound-only: the IXrouter needs just outgoing port 443 and dials the cloud over HTTPS, MQTT and an encrypted VPN, and IXON operates an ISO 27001 certified information-security management system.

ThinRemote uses the same posture in software. The agent makes a single outbound connection over TLS 1.3 and never listens, so there's no inbound port and no service to attack. Operators, pipelines and AI agents connect through the cloud relay under token-based auth, role-based access and an audit trail, and because devices can't reach each other, a compromised box has no neighbours to move to.

ThinRemote is ISO 27001 certified, and IXON also holds an ISO 27001 certified ISMS, so both meet that bar.

ThinRemote outbound-only connection modelLinux devices each open a single outbound TLS 1.3 connection to the ThinRemote cloud relay; operators, CI/CD pipelines and AI agents reach the fleet through the relay under role-based access. No inbound ports and no path between devices.OperatorsCI/CDAI · MCPThinRemotecloud relay · RBACdeviceagentdeviceagentdeviceagentoutbound TLS 1.3 · no inbound port
Every agent dials out; there is no route from one device to the next.
Nothing listensThe agent only dials out over TLS 1.3: no inbound port, no listening service.
Brokered accessToken-based auth, role-based access and an audit trail across every surface.
No lateral movementDevices can't reach each other, so a breach stays on one box.
Surfaces & AI

Web console, CLI and a built-in MCP server

IXON gives you a polished cloud portal for machines and an Open API/SDK to build on. If your team lives in a browser dashboard and builds custom apps against the API, that's a strong, coherent surface.

ThinRemote gives you three working surfaces over the same agent. A web console with dashboards, terminal, file explorer, remote desktop and alarms. A scriptable CLI with JSON output for pipelines. And a built-in MCP server so Claude, Cursor or any MCP client can drive the fleet in plain language, all under the same roles and tokens. Ask "which gateways are low on disk?" and it acts on the real fleet.

AI agentvia thinr MCP
Which edge gateways are low on disk?
thinr product edge monitoring --json
3 over 90%: gw-04, gw-17, gw-31.
Run the cleanup playbook on those three.
thinr product edge playbook rollout disk-cleanup
Done on 3 / 3.
One agent, three surfacesClick it in the browser, script it in CI, or let an AI agent do it.
AI-nativeA built-in MCP server drives the whole fleet in natural language.
Same access controlRBAC, tokens and audit apply identically across console, CLI and MCP.

Device targets & requirements

What each one runs on, and what you need in place before it can connect.

Dimension
ThinRemote
IXON Cloud
Delivery
Software agent only, installed on the device
IXrouter edge-gateway hardware, or the IXagent software option on supported controllers
Device targets
Any Linux device: servers, SBCs, industrial PCs, edge gateways, cloud VMs
Any-brand PLC/HMI/IPC/camera behind an IXrouter; IXagent targets a curated controller list (Sigmatek, PLCnext, WAGO, Berghof) and PC hosts
CPU architectures
16 architectures, kernel 2.6+
Router hardware, plus supported controllers/hosts for IXagent (e.g. ARM controllers, Debian/Ubuntu/Windows/Raspberry Pi)
Agent footprint
Single static binary, <10 MB, no runtime dependencies
Not published as a single lightweight binary; sizing depends on router or host
Extra hardware needed
None
Typically an IXrouter, unless a supported controller runs IXagent
Connectivity
Outbound only; works behind NAT, CGNAT, firewalls and cellular
Outbound only; IXrouter needs outgoing port 443 (Ethernet, Wi-Fi or 4G)

Features & operations

The operational surface, side by side. Green is a strong out-of-the-box fit, amber means possible or partial, grey means it's not the tool's focus.

Capability
ThinRemote
IXON Cloud
Primary purpose
Software fleet access & ops
OEM machine connectivity & IIoT
Remote SSH / terminal
Interactive shell and SSH to the OS, in-browser and via CLI
VPN to the machine; SSH only if you run it yourself over the tunnel
Remote desktop / HMI
Remote desktop to the device (when it has a GUI)
VNC to the machine's HMI, plus HTTP to its web UI
Filesystem access
In-browser file explorer and transfer
Not a first-class OS file browser (access the host over the VPN)
Web / HTTP service proxy
HTTP/TCP/TLS tunnels to any local service
HTTP and VNC access to machine interfaces over the VPN
Monitoring & metrics
OS metrics (CPU, memory, disk, network, temp, uptime) plus custom metrics
Machine data logging over industrial protocols, live & historical dashboards
Alarms & notifications
Threshold alarms on any metric, email or webhook
Machine alarms with email and mobile notifications
Fleet automation
Playbooks (YAML, check mode, batched rollout, failure kill-switch), parallel exec
Fleet Manager for settings/updates; build custom automation on the Open API/SDK
CI/CD & scripting
JSON output, exit codes, ad-hoc & stored playbooks for pipelines
Open API and Cloud SDK to script the platform yourself
Device APIs
Scripts become typed, callable resources on every device
Platform Open API; fieldbus protocols (OPC-UA, Modbus, S7, EtherNet/IP, BACnet)
AI agents (MCP)
Built-in MCP server to drive the fleet in natural language
None built in (build on the Open API)
Connection model
Outbound-only, TLS 1.3, no inbound port, no lateral reachability
Outbound-only over port 443: HTTPS, MQTT/TLS and an encrypted VPN
RBAC & audit
Role-based access, tokens and audit trail across all surfaces
User roles, permissions and a Request Access approval flow
Security certification
ISO 27001 certified
ISO 27001 certified ISMS
Industrial fieldbus protocols
Tunnel to a local protocol service, or read values via a device script
Native OPC-UA, Modbus TCP, Siemens S7, EtherNet/IP, BACnet

A fair reading: IXON is purpose-built to connect and visualize OEM machines, and it's excellent at that. ThinRemote is purpose-built to operate and automate Linux device fleets. Several cells reflect focus, not a missing capability.

Where IXON Cloud is the better fit

If your problem is the machine you build and ship, IXON is likely the stronger choice.

Any-brand PLC/HMI access

You need turnkey, secure VPN access into Siemens, Allen-Bradley, Beckhoff, Omron and other controllers without writing the connectivity yourself. That's IXON's core.

Machine data & customer dashboards

Logging fieldbus values (OPC-UA, Modbus, S7) into historical dashboards, reports and customer-facing machine visualization is exactly what the platform is built for.

Ruggedized edge hardware

You want a DIN-rail industrial router with 4G, digital I/O and a supported hardware catalogue, not just a piece of software on a box you supply.

Plenty of shops run both: IXON for connecting the OEM machines they ship, ThinRemote for operating and automating the Linux fleet around them.

So, which one?

Pick by the question you're actually trying to answer.

FLEET OPS

Choose ThinRemote

"I need to operate, automate and observe a fleet of Linux devices."

  • OS-level access anywhereSSH, shell, files and tunnels on any Linux box, no gateway to ship.
  • Automation & CI/CDPlaybooks, batched rollouts, device APIs and a built-in MCP server.
  • Outbound-only, opens nothingTiny agent, TLS 1.3, RBAC and audit, no lateral movement.
Get Started
MACHINE IIoT

Choose IXON Cloud

"I build machines and need to reach the PLC and visualize its data."

  • Any-brand PLC/HMI VPNTurnkey secure access to industrial controllers behind an edge gateway.
  • Machine data & dashboardsFieldbus logging into live and historical IIoT visualization.
  • Industrial edge hardwareRuggedized IXrouter with 4G, I/O and a supported hardware catalogue.
See how ThinRemote pairs

Frequently asked questions

Straight answers to what OT and IoT evaluators ask when comparing the two.

Is IXON better than ThinRemote for remote access to a PLC?

For getting a secure VPN into an OEM machine's PLC or HMI, yes, that's IXON's core strength and it supports many controller brands out of the box. ThinRemote isn't a fieldbus VPN product; it operates the Linux device itself (shell, files, services, telemetry). Many teams use IXON for the machine and ThinRemote for the Linux gateways and servers around it.

Do I need special hardware to run ThinRemote?

No. ThinRemote is a single software agent (a static binary under 10 MB) that runs on any Linux device across 16 CPU architectures, kernel 2.6 and up. There's no router or edge gateway to buy. IXON often relies on the IXrouter, though its IXagent software can run on a curated set of supported controllers and PC-class hosts.

Is ThinRemote ISO 27001 certified?

Yes. ThinRemote is ISO 27001 certified. IXON also operates an ISO 27001 certified information-security management system. Both connect outbound only, over TLS/port 443, with role-based access, so both meet that bar.

Can ThinRemote do fleet automation and CI/CD?

Yes, natively. Playbooks describe a change once, dry-run on one device, then roll out in controlled batches with a failure kill-switch, driven from the CLI, a CI/CD pipeline, cron or an AI agent via the built-in MCP server. IXON is API-first, so you can build custom automation on its Open API and Cloud SDK.

Does ThinRemote read industrial protocols like OPC-UA or Modbus?

Not as a native fieldbus stack. ThinRemote can tunnel to a local protocol service or read values through a small script on the device and turn them into tracked metrics and alarms. If deep, native OPC-UA / Modbus / S7 logging and machine dashboards are the priority, IXON is purpose-built for that.

Can I use both together?

Often the best answer. Use IXON to connect and visualize the OEM machines you build and ship, and ThinRemote to operate, monitor and automate the Linux devices, gateways and servers in the same estate. They sit at different layers and don't conflict.

Operate your device fleet, whatever the hardware

Install one outbound agent and get SSH, files, telemetry, alarms and fleet automation on any Linux device, no gateway required.