For a meaningful minority of contact centres, sending call recordings to a third-party cloud is not an option. Sometimes that is regulation, sometimes contractual, sometimes an internal policy nobody will reopen.
It is worth separating those, because they permit different solutions.
Work out what the actual constraint is
"Data cannot leave our infrastructure" usually turns out to be one of four narrower requirements:
| Stated as | Often actually means | Permits |
|---|---|---|
| Nothing leaves our network | No audio leaves our network | Cloud analysis of derived data only |
| Data must stay in-country | Processing must be in a named jurisdiction | Regional cloud deployment |
| No third-party processors | No processor outside an approved list | Cloud with the right contract |
| Air-gapped | Genuinely no external connectivity | On-premise only |
Only the last requires full on-premise. The others are often satisfied by a deployment model that is considerably easier to run — worth establishing before you shorten your vendor list to the few who offer air-gapped installs.
The three shapes
- On-premise. Everything runs in your data centre. Maximum control, and you own the operational burden: capacity, upgrades, model updates, monitoring.
- Hybrid. Audio stays with you; a component reaches out for analysis, or analysis runs locally and only derived data is centralised. Covers most real requirements.
- Cloud with dedicated resources. Standard cloud, but isolated infrastructure and a specified region. Satisfies jurisdiction and isolation requirements without the operational load.
Xperia supports all three on Enterprise plans — see deployment options — but the honest recommendation is the least isolated model that satisfies your actual requirement.
What on-premise costs you beyond licensing
Rarely discussed in procurement and always felt afterwards:
- Model updates lag. Cloud analysis improves continuously; an on-premise install improves when you schedule an upgrade.
- You own the capacity problem. Speech analysis is compute-heavy and bursty. Sizing for peak means paying for idle hardware.
- Support gets harder. Diagnosing a problem your vendor cannot see takes longer, every time.
- Your team carries it. Someone internal becomes responsible for uptime of a system they did not build.
None of these are reasons not to do it. They are reasons to be sure you need to.
Questions to ask before shortlisting
- Which components must run on-premise, and which may reach out? A hybrid split is often available and not offered unless asked.
- How are model updates delivered, and how often in practice?
- What are the actual hardware requirements at our call volume, including peak?
- What can your support see when something breaks, and what will you need from us?
- If we start in the cloud, is there a migration path — or is this a decision we cannot revisit?
Retention matters more here, not less
Teams that keep recordings in their own infrastructure often keep them indefinitely, because storage is theirs and nobody is forcing the question. That inverts the intent: the data is now under your control and accumulating indefinitely, which is a larger exposure than a shorter-lived copy elsewhere. Retention windows and automatic deletion apply regardless of where the system runs.
On-premise is the right answer for genuinely air-gapped environments and an expensive one everywhere else. Establish which of the four constraints you actually have before letting it narrow your options.
And whichever model you choose, set a retention window. Controlling the infrastructure is not the same as controlling the data.
