-
MeshCloud
How MeshCloud
is architected.
Modular, production-validated, Azure-native. Engineered from edge to enterprise.
Reference Architecture
Four capability zones,
edge to enterprise.
MeshCloud is organized into four capability zones: the messaging and ingestion core, IT operations, data and analytics, and visualization. Each zone is modular, with clean boundaries and explicit integration patterns. Each is production-validated. Together they form the architecture your connected products run on.
What Each Layer Does
Modular by design.
Four capability layers, each shipped production-ready and built to be extended, swapped, or replaced on its own.
Messaging & Ingestion Core
Devices connect through Azure IoT Hub, with provisioning at scale handled by Device Provisioning Services and certificate lifecycle management built in. The architecture supports multiple device protocols and can consume from any broker, protocol, or data format with minimal effort, so brownfield fleets connect alongside greenfield deployments, with private networking available out of the box. Telemetry flows through a Container App and Event Hubs pipeline load-tested to one million devices, with commands routing back to devices through a parallel pipeline orchestrated by the same patterns.
Data & Analytics
Time-series data lands in Azure Data Explorer or Microsoft Fabric for analytics, while operational state, asset metadata, and digital twin data live in Cosmos DB, each store tuned for what it does best. Device models follow DTDL v3, with configuration management and full historization baked in, so you can query not just what a device reports now, but what it reported and how it was configured at any point in time. A secure HTTP API exposes all device data over service-principal authentication, simplifying KQL while preserving its querying power, so any app or cloud-to-cloud integration can consume it without learning a custom query language.
Visualization & Device Health
An Engineering Portal built in React ships out of the box, with reusable UI components and dynamic forms for device operations and health monitoring. Grafana, Power BI, and Microsoft Fabric handle dashboards and analytical surfaces. A YARP-based Backend-for-Frontend layer with JWT auth and standardized error normalization gives your team a clean integration point. Extension to source code where scoped lets you build exactly the customer experience your product needs.
IT & Operations
Modern auth patterns run throughout the platform: service principals, managed identities, and Azure Entra integration, with customer IDPs extending the auth layer where scoped. OpenTelemetry-native instrumentation covers structured logging, distributed tracing, and alerting, with the ability to swap monitoring backends without code changes. Audit trail is on by default. Deployment automation and infrastructure-as-code ship with the platform, alongside automated test suites that exercise the core paths.
Azure-Native
Production-grade Azure, end to end.
Engineered to ship, not to demo.
MeshCloud isn’t “cloud-native” as a marketing phrase. It’s Azure-native as an architectural decision. The platform runs on the services Microsoft built for exactly these workloads, with the patterns Microsoft hardened in production.
The architecture you just walked through isn’t a feature list. Each of the major decisions above maps to a specific problem buyers face in the build-vs-buy trap. That mapping is why MeshCloud can be a third path at all.
Modular architecture
Solves overfit. You take only the components your use case requires. The platform doesn’t force you to pay for or live with features you didn’t ask for.
Production-validated infrastructure
Solves the build-from-scratch cost. The months most teams spend building DevOps, security, observability, and ingestion are already done. You start with the differentiation, not the plumbing.
Customer-owned deployment
Solves vendor lock-in. Your tenant, your data, your applications, your integrations. You choose how MeshCloud is hosted, licensed, and operated.
Source-code extensibility
Solves underfit. When your use case grows beyond what ships out of the box, you build above the platform, not workarounds around it. Source code access is included under the right agreement.
Ready to see the architecture in action?
Tell us about the connected product you’re trying to get to market. We’ll show you how the architecture maps to your use case, and how fast you can be in production on a foundation that’s already proven at scale.