Architecture

How DigiEdge Workspace is built.

One control plane provisions, secures, and operates every workspace — and connects securely back into your existing network. This page opens up the full architecture: the platform layer by layer, how it connects to your estate, and how a session actually flows.

Schematic overview

The whole platform, on one diagram.

One view of how it fits together — your users on the left, DigiEdge Cloud in the middle with the control plane framing the layer stack, and your corporate network on the right. The two views below break each half down.

Your users

People Any device
Workspace client App or browser

DigiEdge Cloud

or your own environment

Control plane — provisions · secures · operates

Service Access Platform services
Desktop Access Desktops & apps
Site-to-Site Connect Into your network
Access & security SSO / MFA · connection broker · policy
Workspace delivery Containerised Windows & Linux · streamed apps
Compute, GPU & storage Container infrastructure · GPU · fast storage
Monitoring Sessions · usage · health

Your corporate network

Connectivity agents broker access — no exposed ports

PCs & VMs
Servers
Directory (AD/LDAP)
Brokered session — screen streamed, no open inbound ports Control plane boundary
Schematic overview — the control plane provisions, secures, and operates every workspace and connects securely back into your estate.

View A

The platform, layer by layer.

DigiEdge Workspace is one platform with a single control plane at its centre. The control plane provisions, secures, and operates everything inside it — the layers below don't run independently, they run under it.

L0
Control plane
Provisions, secures, and operates everything; the outer frame that runs the whole platform. People, desktops, access, environments, and policy are all managed from here.
L1
Access & security
Gateways, SSO/MFA, the connection broker, and policy enforcement. Every session enters through this layer.
L2
Workspace delivery
Containerised Windows and Linux desktops and individually streamed applications, delivered to any device. Each workspace runs as its own isolated container.
L3
Compute, GPU & storage
The container-based infrastructure each workspace runs on, including GPU for AI and heavy workloads, with fast shared and object storage. Because workspaces are containerised, environments provision quickly, stay consistent, use resources efficiently, and scale cleanly.
L4
Monitoring
Central visibility into sessions, usage, and workspace health across the whole platform.

Full component view

Every component, on one schematic.

For technical evaluators: the complete platform map. Access & security at the top, control planes on the left, the compute plane running containerised Windows and Linux desktops in the centre, and monitoring and storage on the right — all operated from the control plane.

Access & Security

Gateways, SSO, trusted-endpoint checks, and the access-policy engine — every session enters here.

Control Planes

The brains: APIs, dashboard, scheduling, networking, billing, licensing, and policy — provisions and operates everything.

Computes

Where work runs: containerised Windows and Linux desktops and SaaS instances, each isolated with its own guest agent.

Monitoring

Central visibility into sessions, usage, and health, with a historical database and alerting.

Storage

Local, block, and object storage — fast for live sessions, durable for data at rest.

access & security → control planes → computes → monitoring & storage

Show full component map

DigiEdge Access & Security

DigiEdge Gateways

S2S Connect Gateway
Desktop Access Gateway
Service Access Gateway
DigiEdge SSO
Trusted Endpoint Manager
Access Policy Engine

DigiEdge Control Planes

  • Cloud API
  • Workspace API
  • Dashboard
  • Cloud Platform Manager
  • Scheduler
  • Network Manager
  • Billing & Consume Engine
  • License Manager
  • Policy Manager
  • Cloud Platform Operator
  • SaaS Operator

DigiEdge Desktop SaaS

  • Desktop Controller
  • Desktop Image Manager
  • Desktop Network Manager
  • Desktop Scheduler
Cloud Platform Agent
Cloud DB

DigiEdge Computes

Container Windows Desktops

Virtual machine

Windows App
Windows App
Windows App

Guest Agent

Display Protocol
Session Monitoring
Profile Directory
Core
VirtualMachine Handler

Container Linux Desktops

Virtual machine

Linux App
Linux App
Linux App

Guest Agent

Display Protocol
Session Monitoring
Profile Directory
Core
VirtualMachine Handler

DigiEdge SaaS Instances

VirtualMachine Agent
Network Agent
Image Agent
Desktop Session Controller
Event Handler
Monitoring & Alerts Agent
Cloud Platform Agent

Monitorings

Historical DB
  • Monitoring Operator
  • Monitoring & Alert
  • Cloud Platform Agent

Storages

  • Storage Operator
  • Monitoring & Alert
  • Storage Agent
  • Cloud Platform Agent
Platform schematic — simplified by default. Expand the full component map for the complete breakdown: access & security, control planes, computes, monitoring, and storage.

View B

How it connects to your estate.

Users reach their workspace through a brokered gateway — never a directly exposed machine or open port. When a workspace needs to reach systems you already run, the platform connects back into your network through a secure site-to-site link and lightweight agents.

[+]
DigiEdge Workspace client
The user's entry point from any device (client or browser).
[+]
Service Access gateway
Brokered entry to platform services.
[+]
Desktop Access gateway
Brokered entry to desktops and streamed applications.
[+]
Site-to-Site Connect gateway
A secure link between DigiEdge Cloud and your corporate network.
[+]
Connectivity agents
Deployed inside your network to reach existing PCs, servers, VMs, and directory services (AD/LDAP).
[+]
DigiEdge Cloud
Where the control plane and workspaces run (or your own environment, in private/hybrid deployments).
Session flow

How a session flows.

  1. 01

    The user opens the DigiEdge Workspace client from any device.

  2. 02

    They authenticate once with SSO and MFA at the access layer.

  3. 03

    The connection broker matches them to the workspace or system they're authorised to reach.

  4. 04

    The session is established through the relevant gateway — never by exposing the workspace or an open port directly.

  5. 05

    The workspace runs in DigiEdge Cloud (or your own environment); only the screen is streamed to the device.

  6. 06

    For access to existing systems, the Site-to-Site Connect gateway and connectivity agents reach back into your corporate network.

  7. 07

    Every session is monitored and audited centrally by the control plane.

Security by design

Security is a property of the architecture, not a bolt-on.

Because of how the platform is built, security is enforced by the design itself. These are the mechanisms your own team can verify:

[+]
Identity-based access
SSO and MFA at the access layer, with RBAC controlling who can reach what.
[+]
Brokered connections
No exposed endpoints and no open inbound ports to the workspace.
[+]
Full session audit
Recording and logs of who accessed what, and when.
[+]
Data stays server-side
The workload runs centrally; nothing is stored on the device.
[+]
Per-workspace isolation
Each workspace is isolated from the others.
[+]
Deploy in your perimeter
Run it in your own private or hybrid environment.
Technical FAQ

Questions evaluators ask.

Where does the workload actually run? +

In the workspace — in DigiEdge Cloud or your own environment. Nothing runs or persists on the user’s device; only the display is streamed.

What operating systems are supported? +

Containerised Windows and Linux desktops, plus individual streamed applications.

Is the platform container-based? +

Yes — workspaces run on container-based infrastructure, each in its own isolated container. This is what lets environments provision quickly, stay consistent, use resources efficiently, and scale cleanly.

How do users connect? +

Through the DigiEdge Workspace client to a brokered gateway — no exposed endpoints and no open inbound ports to the workspace.

How does it reach our existing systems? +

Through the Site-to-Site Connect gateway and connectivity agents deployed in your network, which broker access to existing PCs, servers, VMs, and directory services.

How does it integrate with our identity? +

SSO and MFA at the access layer, integrating with your identity provider and directory (AD/LDAP). RBAC controls who can reach what.

Where can it be deployed? +

Managed cloud, private cloud, or hybrid — all available today.

Does it support GPU and AI workloads? +

Yes — GPU and AI desktops and environments are live today.

[ initiate_evaluation ]

Want to go deeper on the architecture?

Talk to our team about how DigiEdge Workspace would connect to your environment — your identity, your systems, and your deployment model.