Products
Applies to: SimpleTwo 0.9.x · Checked: 08.10.2026
SimpleTwo ships in parts: the core and five products on top of it. There are no editions across the platform — no "standard" and "enterprise" version of everything at once. Only Audio/Video ships in two tiers. High availability, legal hold on mail and the like are features of their own products, not a separate edition.
What is in each
| Product | Roles | What it gives |
|---|---|---|
| Core — free with SimpleOne | coordinator — the control plane, messaging — chats, directory — the directory with the calendar, postgres — the database | chats, threads and files in conversations; the directory of people, groups and the organisation's contacts; calendars, meetings, personal and team address books; sign-in through your own identity provider (ADFS, Entra ID, Keycloak); the admin console |
| Audio/Video Basic | sfu, turn, a TLS front before sfu, recorder; redis — the bus, from the second sfu node and for recording; s3 — object storage for recordings | calls and conferences, the lobby, guest links, meeting recording |
| Audio/Video Plus | everything in Basic, mcu (with redis), pstn — the PSTN gateway, support — the support bot | meeting rooms with SIP endpoints, the telephone network over a carrier's trunks — see Telephony, call recording, federation between installations, the AI support bot |
| Secure Access | gateway, DMZ gateways, routing rules | the VPN: access to the internal network and egress in a chosen country; for any other product, also the posture "only through Secure Access" |
mail and mx; s3 — object storage | the organisation's mail in place of Exchange — see Mail | |
| Drive | drive; s3 — object storage | files: a personal space for everyone, group spaces, the recycle bin — see Files |
| ID | the directory role in provider mode (the ID option) | its own passwords and passkeys, sign-in approval on the phone, codes by e-mail, OpenID Connect and SAML sign-in for the company's applications, the LDAP server, access reviews, the person's portal — for those leaving AD and ADFS |
An option for any installation: monitoring — metrics, logs and traces of every host, its
interface opened from the console. Not a product and not required: installed if wanted, one per
installation.
postgres and s3 are infrastructure, not products: your own Postgres cluster and S3-compatible
store can stand in for the roles. The support bot and the AI lane spend minutes of an external
model provider; that is a cost line of its own, not a role.
What follows for an installation
- The VPN is optional. Every product works directly over TLS with its own certificate; Secure Access is a product of its own and the "only through the tunnel" posture for the rest.
- Calls without Secure Access need a TLS front before
sfuandturnwith TLS on 443: iOS does not open the media server's signalling without TLS, and strict networks let only 443 through. - The core's directory carries mail and files. Distribution groups, aliases, app passwords and submission on 587/465 for mail, group spaces for files all come from the directory. Without it, mail is a mailbox server with no groups or aliases.
- Chats carry calls. Without
messagingthere are no calls, nomcuand no support bot:messagingadmits people to rooms and carries the signalling. - Storage is the main cost line. The core needs
postgres; mail, files and recording needs3(thes3role or your own S3-compatible store). - The products are the console's switches. Settings → Product options (coordinator
after 0.9.303): each row is a product; the clients hide disabled modules and the console hides
their tabs. Secure Access goes on only with a gateway enrolled; while it is off, an
invitation for a
gatewayhost is refused and every other product's access mode reads "direct" — there is no tunnel. Audio/Video has a tier, Basic / Plus: invitingmcuandpstnhosts, turning federation on and standing up the support bot need Plus; going back to Basic deletes nothing. Mail and Drive are switches with an access mode; their tabs appear in the clients once the host answers on its public name. Every change is an audit row (features.<option>). - ID is a console option too (on by default). Without it
directorystays the core's directory: its own sign-in, the OIDC/SAML provider and the LDAP server are closed, and people sign in through your identity provider; it cannot go off whileplatform_tokenisidentity. See section 7 of Switching sign-in to identity. - There is no licence key. Which products are switched on is the contract's; the product checks nothing against a licence.
- One app — SimpleTwo Connect for every product. Its Mail and Files tabs appear when the installation announces those services.
Next
- How the platform is built — planes and services
- On-premise deployment — installing role by role
- Sizing — resources by organisation size