voiceOne in your data centre. All data stays with you.
The complete voiceOne platform — AI phone assistant, agent softphone, CRM and workflow automation — installed in your own infrastructure. Your own PostgreSQL database, your own SIP telephony, your own LLMs. Optionally fully air-gapped. For everyone who cannot hand over their data.
Why On-Premises?
Because some data must not leave your building. Because audit requirements rule out cloud setups. Because you want to decide for yourself who accesses what and when.
Full data sovereignty
Patient data, client data, banking data, citizen data — everything stays on your hardware. No SaaS contracts, no data-processor discussions, no cloud hops.
Compliance without workarounds
§ 203 StGB for professionals bound by confidentiality, KRITIS for utilities, BaFin for financial service providers, gematik TI for healthcare. On-prem is often the only route that works without special permits.
Your own integrations
Direct access to KIS, KIM, AnNoText, DATEV, RA-Micro, application X. No VPN tunnelling, no reverse-proxy tangle. Performance at local-network level.
Your own language models & voice
You choose the language model yourself: a cloud model in your own tenant, a model in your VPC, or locally hosted open-source models on your own GPU. Speech synthesis and speech recognition either locally or as a cloud endpoint.
Air-gapped possible
When needed: completely offline. Updates via signed trusted transfer (USB, data diode). Suitable for public authorities, defence and critical infrastructure without an internet connection.
Plannable & auditable
A one-off setup investment instead of monthly per-seat scaling. Fully auditable: every data flow, every LLM call, every session in your logs — no black box.
Cloud vs. Private Cloud vs. On-Premises
Which model fits your compliance, performance and sovereignty requirements?
| voiceOne Cloud | Private Cloud (in your tenant) | voiceOne On-Premises | |
|---|---|---|---|
| Hosting location | Hetzner DE (Falkenstein) | Your cloud tenant, EU region | Your data centre / your servers |
| Data sovereignty | Data processing (DPA) | Shared responsibility | 100% with you |
| § 203 StGB suitable | With confidentiality binding | Yes | Yes, without reservations |
| Air-gapped possible | No | No | Yes (optional) |
| SIP connection | voiceOne SIP provider | Own SIP trunk possible | Your PBX / your trunk |
| Language model | Managed by voiceOne | Cloud LLM in your tenant | Freely selectable incl. local models |
| Updates & patches | Automatic | Semi-automatic | You decide on the timing |
| Commercial model | Self-service, cancellable monthly | Custom Quote | Setup + annual licence |
| Time-to-Production | Immediate | 2–4 weeks | 4–8 weeks |
| Typical target group | SMEs, self-employed, quick trial | Mid-market with a cloud strategy | Healthcare, Legal, public authorities, KRITIS |
Who is On-Premises made for?
Industries with special protection, confidentiality or audit requirements.
Hospital chains & MVZ
Patient data must not leave your TI security zone. voiceOne On-Prem connects to your KIS (via HL7/FHIR), your KIM mailboxes and your TI connectors.
- KIS connection via HL7/FHIR
- gematik TI compatible
- Integrable with the mediOne stack
Law firms
Professional confidentiality under § 203 StGB effectively rules out classic SaaS. On-prem with a connection to AnNoText, RA-Micro or DATEV — all client communication stays in-house.
- § 203 StGB compliant without a special agreement
- AnNoText / RA-Micro / Advoware
- beA integration optional
Tax advisors & auditors
DATEV connection local, client files under your control. Ideal for firms with 50–500 employees that have their own cloud strategy.
- DATEV DMS integration
- GoBD-compliant call & client logs
- Client-to-client separation
Public authorities & municipalities
Citizen data belongs in a BSI-compliant environment. voiceOne On-Prem runs in your municipal cloud or local server rooms, optionally air-gapped.
- BSI C5 / IT-Grundschutz
- Connection to OZG specialist procedures
- Multi-tenant capable for administrative associations
Technical architecture
Container-based. Open. Auditable. Runs on your existing infrastructure.
Platform & Runtime
- Container: Docker Compose or Kubernetes (Helm charts included)
- OS: RHEL 8/9, Ubuntu 22.04 LTS, SUSE Linux Enterprise
- Minimum hardware: 8 vCPU, 32 GB RAM, 500 GB SSD (standard setup)
- GPU optional: 1× NVIDIA L4 or better for local LLM inference
Database & Storage
- DB:
PostgreSQL 15+(your own instance or managed in your cloud) - Cache: Redis 7
- Storage: S3-compatible (MinIO included, or your Ceph / NetApp)
- Backup: 4-layer concept: pg_dump every 6h, verify, off-site, SMS alarm
Telephony & Voice
- SIP trunk: Your provider (Telekom, sipgate, Vodafone, NFON) or your own
- PBX connection: 3CX, innovaphone, Avaya, Cisco, Mitel, Asterisk, FreeSWITCH
- WebRTC: Browser and mobile softphone directly against your instance
- Recordings: AES-256, storage location and retention defined by you
AI components (your choice)
- Cloud language model: In your own tenant or in your VPC — no external servers, no training opt-in
- Local: Open-source language models on your own GPU hardware
- Speech synthesis: Cloud endpoint with enterprise contract or local TTS
- Speech recognition: Cloud service or local model
Identity & Access
- SSO: SAML 2.0, OIDC, OAuth2 (Keycloak, Azure AD, Okta, ADFS)
- Directory: LDAP, Active Directory
- RBAC: Fine-grained role model, tenant separation
- Audit: Complete audit log, export to Splunk, ELK, Graylog
Operations & Monitoring
- Metrics: Prometheus exporter, Grafana dashboards
- Logs: structured JSON, compatible with all SIEM solutions
- Health checks: Liveness/readiness probes for K8s
- Updates: Quarterly majors, monthly patches, signed
Compliance & Certifications
voiceOne On-Prem ships with audit packages that support your compliance department throughout the certification process.
From enquiry to go-live
Standard playbook for most stacks. Longer accordingly for more complex integrations.
Architecture consultation & requirements gathering
We get to grips with your stack: phone system, identity provider, HIS/CRM, compliance requirements. You receive a solution proposal with an architecture diagram and a fixed quote.
Test installation & PoC
voiceOne runs in your test environment. SIP connection, SSO, a first AI agent with your data. You test with your real use cases.
Production installation & integrations
Rollout into the production environment. Connection to HIS / CRM / DMS. Workflow configuration. Monitoring & backup set up. Audit packages handed over.
Training & Go-Live
Administrator training (2 days), end-user training (half a day). Supported commissioning with a hypercare phase (4 weeks of daily contact).
Request a personal consultation
No sales pitch, no newsletter. A 45-minute conversation with our solutions architect about your requirements and our answer to them.
Frequently Asked Questions
Yes. Voice data, transcripts, CRM records, recordings and logs reside solely on your hardware — in your data centre or your private cloud (Azure, AWS, OTC, Hetzner Dedicated). voiceOne needs no outbound data stream to operate. Optionally available fully air-gapped (updates via USB/trusted transfer).
You choose: (a) a cloud language model in your own tenant (EU region, no training opt-in), (b) a language model in your own VPC, (c) locally hosted open-source models on your own GPU hardware — completely offline in that case. Speech synthesis and speech recognition optionally local or via a cloud endpoint with an enterprise contract.
voiceOne On-Prem connects to your existing phone system via SIP trunk (3CX, innovaphone, Avaya, Cisco, Mitel, Asterisk, FreeSWITCH). Alternatively, voiceOne can be operated as a complete telephony solution with a SIP provider of your choice. Mobile softphone (iOS/Android) and browser softphone run over WebRTC directly against your instance.
GDPR, BSI C5, ISO 27001-ready (controls mapping available), the gematik TI security guideline (for healthcare), § 203 StGB-compliant (for professionals bound by confidentiality: lawyers, doctors, tax advisors), KRITIS-capable, BaFin-MaRisk-compliant, HIPAA-ready (for US deployments). We supply audit packages, technical documentation and support your compliance department throughout the certification process.
Three models: (1) You operate it yourself — we supply container images, Helm charts, documentation and updates. (2) Managed On-Prem — we operate the system remotely in your data centre via a bastion host (two-factor + audit log of every session). (3) Hybrid — application at your site, 24/7 monitoring & patch management on our side over a secure read-only channel.
Architecture workshop + PoC: 2–3 weeks. Full commissioning including SIP connection, LDAP/SAML integration, data migration and staff training: 4–8 weeks. We have standard playbooks for the most common stacks (Active Directory, 3CX, FreeSWITCH, Azure AD, Keycloak).
A one-off setup fee (installation, configuration, training, go-live support) plus an annual licence for a standard instance with all modules. Scaling in tiers by seats and locations. Support SLA selectable: business hours, 24/7 or a dedicated Customer Success Manager. You will receive a concrete quote after a no-obligation architecture consultation — dependent on seats, locations, desired modules and SLA.
Yes. Quarterly major releases, monthly security patches, immediate hotfixes for critical CVEs. Updates are verified in advance in your test environment. For air-gapped installations we deliver signed update packages via trusted transfer (USB, data diode). You retain full control over the roll-out timing.
Let's talk about your architecture.
45 minutes with our solutions architect. Concrete. Technical. No sales loops.
