The defense subcontractor's quality lead opens the twinzo demo on a laptop in the integration office. Forklift spaghetti on a 3D hall, live pins on tool cages, a no-go flash when a tug crosses a paint line. Production wants that picture on the machining floor next quarter. Then cybersecurity asks for the data-flow diagram and where packets leave the site.
There is no outbound path. The plant VLAN that carries RTLS and MES traffic is isolated by policy, not by accident. Radios and shop-floor tablets are not allowed to resolve public SaaS endpoints. The project does not die because the use case is weak. It stalls because the default assumption (subscribe, authenticate, stream positions to someone else's region) does not fit a site that treats the network as part of the security boundary.
That friction is normal in aviation MRO, defense manufacturing, nuclear and radiological facilities, and other critical sectors where IEC and national guidance treat industrial control and operational data as assets that should stay inside the fence. twinzo can run entirely on your LAN. Positions, history, models, and alert rules stay on VMs you operate. Operators still open the same browser and phone apps. The change is who runs the servers and who issues the certificates, not whether the floor gets a live twin.


