← Back to docs

Update policy

Which updates you run yourself, which get scheduled together, and why the two are separated.

Two kinds of update

Updates within the running version. Security and bug fixes. Low risk, and yours to run from the interface whenever you like. We suggest off-peak hours, but you do not need anyone’s permission.

Moving to the next major version. This replaces core parts of the system. That button is deliberately held back for customers and handled with the support team in an agreed window.

Why they are separated

Major version moves are where unexpected trouble concentrates: changed defaults, configuration adjustments, reboots. Holding it back is not about trust. It is about making sure someone is standing by when a step misses.

Audit trail

Every update run from the interface is recorded in full: who, when, and the result. That record lives on your device, not on our servers, and can be collected for audits.

Networks with no outbound internet

The device can pull updates from a local mirror inside your own network. This exists for sites with strict egress policy or expensive links. Raise it during the assessment so the mirror is part of the design.