Take this to any vendor conversation, including ours. If a vendor cannot answer one of these to your satisfaction, that answer tells you where their architecture concedes.
This single question exposes the entire architectural truth. Any honest answer that reveals diverging code paths confirms the platform is device-first, legacy redistributed, not unified commerce.
Regulators don't care about your uptime SLA. If the log is scattered across devices that may have been off, backgrounded, or replaced, you don't have an audit trail. You have a liability.
The two common answers are cached credentials on the device, or a blocked sign-in. Both are unacceptable. One is a security hole, the other closes your store. There is no good middle ground unless identity is handled at platform level.
Manual card capture is fraud exposure. Transactions recorded as cash distort your reporting. If payments stop when connectivity drops, the store effectively closes. This is the most direct revenue impact of any architectural weakness.
Vendors rarely volunteer where their responsibility ends. Behind this question sits your real total cost of ownership: the IT headcount, the field service visits, the fleet management overhead that never appears in a licensing proposal.
Every retail architecture has an edge. Legacy has one, but cloud-native has one as well. And cloud-native solutions that offer a device-first approach have both. What has been missing is a bridge. This insight is about how EVA became that bridge, and what it means for running thousands of stores at a global scale tomorrow.
For decades a store was its own world. A till on the counter, a printer on a cable, a server in the back. Everything present, everything connected, everything working. State was local. Failures were local. Recovery was local too. What made it legacy was not its architecture. It was its isolation from the rest of the brand.
Cloud made unified commerce possible for the first time. Global reach, one catalogue, one price, one customer across every touchpoint. What the old world could not do, cloud did overnight. But it also brought its own edge. And that edge presented itself where it is most critical not to have one: the shop floor. Where the connection wavers, and connections waver, the platform wavers too. Even at 99.9% platform uptime, the average retailer sees over eighty hours of unplanned downtime a year per store, once you count the network and the site. Cloud alone is not a store platform. It is a promise, at a distance.
To overcome the new edge cloud introduced, the industry offered a device-first approach. That sounds logical. Move the business logic into the hand of the employee. It feels like the right thing to do, because we recognise the tech. But it is legacy in modern clothes.
The industry moved the logic back to the tablet. State on the iPad. Business logic on the iPhone. Reconciliation after the fact, not in real time. Call the cloud only when you need something, and push completed transactions after the fact if the network cooperates. That is not modernization. It is the old world redistributed across thousands of devices. Every device becomes its own small island of logic, app version, version of data, and part of the larger context. Every fleet becomes an operational tax that grows with your store count. But if a cloud-native platform still holds a device-first architecture, what has actually changed?
Every architecture has edges. Legacy had one: it was isolated. Cloud has one: it stops where connectivity stops. Device-first has one: it distributes complexity across thousands of endpoints. Our answer is Watchtower, and not another edge. Watchtower is a bridge. The same EVA, present where the customer stands. Same apps, same processes, same endpoints, same data, same audit trail, whether it is cloud or on-prem. There is nothing to synchronize between systems that are already the same. Watchtower is the third generation of our highly available, cloud-native design conviction.
Safe, compliant, bridging the edge of your store and extending the cloud beyond your connection.
A modern retail platform does not remove the store from its architecture. It brings the platform to where the customer stands, and where the associate is empowered to transact.
These are the places where every architecture is tested at scale. Most platforms have made concessions here. Where they concede is where their architecture shows its limits. What follows is the requirement first, and immediately after, what EVA does.
Every enterprise retailer operates under strict fiscal legislation in multiple countries. Italy, Poland, France NF525, Germany TSE, Portugal SAF-T, Spain, Hungary, to name a few. Each requires a certified approach to transacting and validation that keeps advancing when the connection does not. The old world kept this simple because compute was local. Cloud-only architectures gave that up, and device-first architectures pushed the burden onto endpoints that may be off, backgrounded, or out of sync.
In EVA:
Watchtower carries all of EVA's fiscal certifications into the store. Sequences advance during a connection interruption, in the correct order, at the right cadence. Cloud absorbs the segment on reconnect, seamlessly. No gaps. No duplicates. No unfiscalised transactions. In your store in Milan on a Thursday afternoon, the customer sees a receipt. The Agenzia delle Entrate sees a signature. Both are correct.
In the United States, sales tax is calculated per jurisdiction, per product, per exemption, per zip code, sometimes per side of the street. Vertex or Avalara must remain answerable to every transaction. When the connection is interrupted, a device-first platform defaults to a rate or asks the cashier to override. Both are audit exposure.
In EVA:
Choose Vertex or Avalara once, centrally per country or region, in EVA Cloud. From that moment, every Watchtower in that scope carries the full logic of the chosen provider, online and in real time. Never a default. Never a manual override. In your Manhattan flagship during the lunch rush, the calculation is the same as it would be in the cloud, at the same precision.
A promotion is a legal statement about what a shopper pays. Cross-basket, tiered thresholds, loyalty stacking, currency-scoped campaigns. Enterprise retailers change these multiple times a day, approved by finance, published across every touchpoint. When the connection falters, a device-first architecture typically falls back to letting a cashier apply a manual discount or overwrite the price. That is not a strategy. That is fraud exposure with an audit tail.
In EVA:
Watchtower runs the full promotion engine locally, evaluating the same rule set approved centrally. Every price at every register, provably correct, whether or not the connection holds. No cashier discretion. No end-of-day surprises. What finance approved this morning is what the customer sees, everywhere.
A store operating during a connection outage must be able to sign in and sell. Not with credentials stored on devices. Not with store managers creating temporary accounts or transacting on fallback logins. The old world had this working because identity was local. The new world must not lose that, without gaining local security exposure.
In EVA:
Watchtower is your beacon of trust. Federation with your identity provider through SAML or OIDC. Session policy defined centrally, enforced everywhere. Sessions authorised by EVA Cloud, held by Watchtower, honoured by every device in the store. Not with cached credentials. Not with temporary sessions. Truly authenticated users, at the same security posture, before, during, and after any outage.
An iPhone powered off mid-transaction cannot orphan the basket. Closing an app cannot break the audit trail. Logging cannot resign to the individual iPhone that started the transaction. That is what enterprise-grade means.
In EVA:
Because Watchtower is EVA, every transaction begun in the store persists in the store's EVA instance. Recovery is a routine EVA behaviour, not a special path. Audits stay whole. State lives at platform level, not at device level, even when multiple devices are working on the same order object.
A regulator issues an update. You change the template once. Every store worldwide prints the new receipt on the next transaction. Not tomorrow. Not after a synchronization job. Not after five thousand devices are updated, some of which may be off or backgrounded.
In EVA:
Change the template once in EVA Cloud, scoped to a country, a region, or even a specific store. Every next print worldwide is the new template. Instantly. Watchtower absorbs the change and prints from it. No template drift. No stale versions. One version of the truth, governed by EVA, audited by EVA.
A fleet carries thousands of peripherals across hundreds of stores. Printers, payment terminals, RFID pads, cash drawers. No IT team should touch a device to make it discoverable. There should be no pairing of individual iPhones or iPads to individual peripherals. No VPN tunnels, no mTLS setups, no central print servers, no port forwarding to reach a station on the shop floor.
In EVA:
Peripherals are grouped into stations at the platform level. Watchtower orchestrates traffic on the local network, routing every request to the right place, whether the logic sits on Watchtower or belongs on an iOS device. The app declares intent. Watchtower carries it out. No app needs to know a peripheral. Onboarding is central. EVA does the rest.
Seventy-five hundred devices in a fleet. Each opens its box, joins Wi-Fi, and must be operational without store-specific configuration on the device. That is room for error, overhead in scaling, and unnecessary field service when a device needs replacing.
In EVA:
No store awareness lives in the app. Apps are deployed fully agnostic. The app opens, users sign in through MDM, the app finds Watchtower, secures itself, inherits the store settings, is operational. Everything else follows.
A regulator or an accountant asks for the complete history of a sale that occurred during a fifteen-minute cloud outage. Every event, every signature, in order, provably unmodified. In a device-first architecture, that history is scattered across devices that may or may not have retained it.
In EVA:
Every event is EVA. Statutory audit files (JPK, SAF-T, SDI, NF525 archive) generate from the same records the platform ran on. No missing audits. No different logging path. Just the same EVA.
No VPN mesh to fifteen hundred stores. No MPLS to every location. No peripheral on the public internet. No inbound port mapping to individual printers or payment devices. Device-first architectures typically require some combination of these to reach devices remotely, or leave you blind on your infrastructure.
In EVA:
Watchtower speaks to peripherals on the local LAN over standard protocols. Outbound to EVA Cloud over TLS, fully managed by EVA. The store's infrastructure stays transparent as EVA reports back on in-store telemetry, peripheral status, and connected clients. One platform, in full detail.
A connection interruption during a busy hour cannot mean shoppers are turned away. It cannot mean the associate records a card number by hand, leaving the retailer with the fraud risk and a paper trail that shows up in reports as cash. That is not payment processing. That is legal exposure.
In EVA:
Watchtower coordinates payment terminals on the local network. Payments continue through any short-lived connection interruption, on the same providers, with the same authorisations. With EVA Pay, referenced payments can be processed even without an internet connection at all. Multiple payment providers, one behaviour. The bridge holds, even for payments. The same payment, on the same platform, whether the cloud is reachable or not.
The eleven items above are what EVA does when the network is not on your side. Resilience is the floor, not the ceiling. What follows is what becomes possible when the platform actually stands where the customer stands.
The dividend of being present.
Presence in the store has consequences beyond compliance. It changes what a store platform can carry, and what it can become.
Four things follow from the same architecture that keeps you compliant during an outage.
The current generation of Watchtower runs on Apple silicon. That matters. iOS 27 ships a generation of on-device AI capabilities designed to work best against an always-on local anchor on the store network. Visual product recognition on the sales floor. Associate assistants that draw on customer context in real time. Inventory reasoning across the store. Handled locally, from a Mac mini in your infrastructure, under our operation. No per-inference cloud tokens. No round trip. No running cost that AI at fleet scale becomes.
Product images, videos, catalogue assets, and operating system updates that every device currently fetches independently are cached once in the store and served locally. Apple Content Caching is native to macOS, so this is not a New Black invention. It is a native capability we bring inside your store platform. Endless-aisle, clienteling, and product lookups stop being uplink-bound. On release days, fifteen devices download the OS update once, not fifteen times. The difference between an operational store and one waiting on progress bars.
Watchtower runs on hardware providing hardware-attested boot, Secure Enclave, and device-integrity signals. Apple's Trusted Infrastructure Mode gives the platform a signed, verified foundation from silicon up. The store platform sits inside your existing Apple ecosystem: same MDM, same update flow, same security posture, same vendor lifecycle as your iPads and iPhones. Your IT organisation does not manage a separate appliance next to its Apple fleet. For teams operating under PCI-DSS scope or CISO oversight, this is not a checkbox. It is what makes the conversation possible in the first place.
The Watchtower Mac mini sits in your store. The operational responsibility sits with us. macOS lifecycle, security patching, EVA updates, remote fault handling, telemetry, first and second line support. Fleet observability spans device health, network conditions, LAN and WLAN quality, and peripheral reachability, all in one view we share with you. When we build new capabilities that extend what the store can do, they land in your fleet without a rollout project on your side. What we ship, you get. Frictionlessly.
For the CISO, the VP Infrastructure, and the enterprise architect who will assess this platform before it enters the fleet. Eight cards. Everything else, on request.
One EVA, two locations.
EVA Cloud is authoritative in normal operation. Watchtower runs a full EVA instance, kept in mirror through a change feed. During a cloud interruption, Watchtower is authoritative for its store. Writes are recorded in the local EVA instance with monotonic sequencing and reconciled cloud-side on reconnect. Conflict resolution is deterministic and cloud-arbitrated.
Nothing lives only on the device.
Because Watchtower is EVA, every transaction begun in the store persists in the store's EVA instance. Client device failure does not orphan the transaction. Recovery is routine EVA behaviour, not a special path. No scenario exists where transaction state lives only on the device.
Certified counters, uninterrupted.
Italy Server RT, Poland fiscal print sequence, France NF525, Germany TSE, Portugal SAF-T. During a cloud interruption, Watchtower advances the sequence within the local EVA instance. On reconnect, cloud absorbs the segment. Certified sequence is preserved without gaps and without duplicates.
Standard protocols. No tunnels.
Watchtower talks to peripherals over the store LAN using standard protocols. Outbound to EVA Cloud over TLS 1.3 on HTTPS. No VPN. No MPLS to each store. No site-to-site tunnels. No inbound ports on the store network. Peripherals never exposed to the public internet.
Federation, centrally enforced.
EVA Cloud is the token authority. Federation with the customer identity provider is SAML or OIDC. Session policy (lifetime, offline extension window, role-based mandate) is defined centrally and enforced by both cloud and Watchtower. No credentials stored on client devices. The full authentication chain is reproducible from the identity provider log and EVA event log.
Your hardware, our operation.
Watchtower is customer-owned hardware, enrolled to New Black through Apple Business Manager and managed in our MDM. macOS lifecycle, security patching, EVA runtime updates, telemetry, and remote fault handling are operated by New Black. Fleet observability is shared with the customer through a common view.
Every event, every export.
Every transaction, promotion evaluation, price decision, session event, fiscal signature, reprint, and reconciliation is recorded in EVA. Statutory audit files (JPK, SAF-T, Italy SDI export, France NF525 archive) are generated from the same records the platform operated on. No separate reporting system to reconcile.
Independent, at fleet.
One Watchtower per store. Client devices scale independently. Peripheral onboarding is remote. EVA rollouts are cloud-driven; Watchtower absorbs new versions on a schedule the customer controls per country or region. Rollback is native at the EVA release level.
There is No Edge to Unified Commerce
A modern retail platform does not remove the store from its architecture. It brings the platform to where the customer stands. EVA is that platform. Cloud native by design, resilient by nature. Not another edge, a bridge, running as one truth in every store and every cloud.