0951 16092950 · info@voice-one.ai · 24/7 — our AI always answers ·
On-Premises · Enterprise

voiceOne in your data centre. All data stays with you.

The complete voiceOne platform — AI phone assistant, agent softphone, CRM and workflow automation — installed in your own infrastructure. Your own PostgreSQL database, your own SIP telephony, your own LLMs. Optionally fully air-gapped. For everyone who cannot hand over their data.

GDPR & BSI C5 § 203 StGB compliant ISO 27001-ready HIPAA-ready Air-gapped possible

Why On-Premises?

Because some data must not leave your building. Because audit requirements rule out cloud setups. Because you want to decide for yourself who accesses what and when.

🏛️

Full data sovereignty

Patient data, client data, banking data, citizen data — everything stays on your hardware. No SaaS contracts, no data-processor discussions, no cloud hops.

🔐

Compliance without workarounds

§ 203 StGB for professionals bound by confidentiality, KRITIS for utilities, BaFin for financial service providers, gematik TI for healthcare. On-prem is often the only route that works without special permits.

⚙️

Your own integrations

Direct access to KIS, KIM, AnNoText, DATEV, RA-Micro, application X. No VPN tunnelling, no reverse-proxy tangle. Performance at local-network level.

📜

Your own language models & voice

You choose the language model yourself: a cloud model in your own tenant, a model in your VPC, or locally hosted open-source models on your own GPU. Speech synthesis and speech recognition either locally or as a cloud endpoint.

🛑

Air-gapped possible

When needed: completely offline. Updates via signed trusted transfer (USB, data diode). Suitable for public authorities, defence and critical infrastructure without an internet connection.

📊

Plannable & auditable

A one-off setup investment instead of monthly per-seat scaling. Fully auditable: every data flow, every LLM call, every session in your logs — no black box.

Cloud vs. Private Cloud vs. On-Premises

Which model fits your compliance, performance and sovereignty requirements?

  voiceOne Cloud Private Cloud (in your tenant) voiceOne On-Premises
Hosting location Hetzner DE (Falkenstein) Your cloud tenant, EU region Your data centre / your servers
Data sovereignty Data processing (DPA) Shared responsibility 100% with you
§ 203 StGB suitable With confidentiality binding Yes Yes, without reservations
Air-gapped possible No No Yes (optional)
SIP connection voiceOne SIP provider Own SIP trunk possible Your PBX / your trunk
Language model Managed by voiceOne Cloud LLM in your tenant Freely selectable incl. local models
Updates & patches Automatic Semi-automatic You decide on the timing
Commercial model Self-service, cancellable monthly Custom Quote Setup + annual licence
Time-to-Production Immediate 2–4 weeks 4–8 weeks
Typical target group SMEs, self-employed, quick trial Mid-market with a cloud strategy Healthcare, Legal, public authorities, KRITIS

Who is On-Premises made for?

Industries with special protection, confidentiality or audit requirements.

Healthcare

Hospital chains & MVZ

Patient data must not leave your TI security zone. voiceOne On-Prem connects to your KIS (via HL7/FHIR), your KIM mailboxes and your TI connectors.

  • KIS connection via HL7/FHIR
  • gematik TI compatible
  • Integrable with the mediOne stack
Legal

Law firms

Professional confidentiality under § 203 StGB effectively rules out classic SaaS. On-prem with a connection to AnNoText, RA-Micro or DATEV — all client communication stays in-house.

  • § 203 StGB compliant without a special agreement
  • AnNoText / RA-Micro / Advoware
  • beA integration optional
Tax & Audit

Tax advisors & auditors

DATEV connection local, client files under your control. Ideal for firms with 50–500 employees that have their own cloud strategy.

  • DATEV DMS integration
  • GoBD-compliant call & client logs
  • Client-to-client separation
Public Sector

Public authorities & municipalities

Citizen data belongs in a BSI-compliant environment. voiceOne On-Prem runs in your municipal cloud or local server rooms, optionally air-gapped.

  • BSI C5 / IT-Grundschutz
  • Connection to OZG specialist procedures
  • Multi-tenant capable for administrative associations

Technical architecture

Container-based. Open. Auditable. Runs on your existing infrastructure.

Platform & Runtime

  • Container: Docker Compose or Kubernetes (Helm charts included)
  • OS: RHEL 8/9, Ubuntu 22.04 LTS, SUSE Linux Enterprise
  • Minimum hardware: 8 vCPU, 32 GB RAM, 500 GB SSD (standard setup)
  • GPU optional: 1× NVIDIA L4 or better for local LLM inference

Database & Storage

  • DB: PostgreSQL 15+ (your own instance or managed in your cloud)
  • Cache: Redis 7
  • Storage: S3-compatible (MinIO included, or your Ceph / NetApp)
  • Backup: 4-layer concept: pg_dump every 6h, verify, off-site, SMS alarm

Telephony & Voice

  • SIP trunk: Your provider (Telekom, sipgate, Vodafone, NFON) or your own
  • PBX connection: 3CX, innovaphone, Avaya, Cisco, Mitel, Asterisk, FreeSWITCH
  • WebRTC: Browser and mobile softphone directly against your instance
  • Recordings: AES-256, storage location and retention defined by you

AI components (your choice)

  • Cloud language model: In your own tenant or in your VPC — no external servers, no training opt-in
  • Local: Open-source language models on your own GPU hardware
  • Speech synthesis: Cloud endpoint with enterprise contract or local TTS
  • Speech recognition: Cloud service or local model

Identity & Access

  • SSO: SAML 2.0, OIDC, OAuth2 (Keycloak, Azure AD, Okta, ADFS)
  • Directory: LDAP, Active Directory
  • RBAC: Fine-grained role model, tenant separation
  • Audit: Complete audit log, export to Splunk, ELK, Graylog

Operations & Monitoring

  • Metrics: Prometheus exporter, Grafana dashboards
  • Logs: structured JSON, compatible with all SIEM solutions
  • Health checks: Liveness/readiness probes for K8s
  • Updates: Quarterly majors, monthly patches, signed

Compliance & Certifications

voiceOne On-Prem ships with audit packages that support your compliance department throughout the certification process.

GDPR
BSI C5
ISO 27001-ready
§ 203 StGB
gematik TI
KRITIS
BaFin MaRisk
HIPAA-ready
GoBD

Commercial model

One-off setup fee plus an annual licence. No per-seat gouging, no hidden costs for API calls or telephony minutes. You pay for a predictable instance, not for every additional member of staff.

One-off setup
Installation & Go-Live
Architecture workshop, installation, configuration, training, data migration, go-live support
Annual licence
Platform & Updates
Standard instance for up to 20 seats, unlimited calls, all modules, updates and security patches included. Scales in tiers.
Support SLA
Optional
Business hours, 24/7 or a dedicated Customer Success Manager — depending on how critical the service is.

Final quote after a no-obligation architecture consultation — dependent on seats, locations, desired modules and SLA.

From enquiry to go-live

Standard playbook for most stacks. Longer accordingly for more complex integrations.

Week 1

Architecture consultation & requirements gathering

We get to grips with your stack: phone system, identity provider, HIS/CRM, compliance requirements. You receive a solution proposal with an architecture diagram and a fixed quote.

Weeks 2-3

Test installation & PoC

voiceOne runs in your test environment. SIP connection, SSO, a first AI agent with your data. You test with your real use cases.

Weeks 4-6

Production installation & integrations

Rollout into the production environment. Connection to HIS / CRM / DMS. Workflow configuration. Monitoring & backup set up. Audit packages handed over.

Weeks 7-8

Training & Go-Live

Administrator training (2 days), end-user training (half a day). Supported commissioning with a hypercare phase (4 weeks of daily contact).

Request a personal consultation

No sales pitch, no newsletter. A 45-minute conversation with our solutions architect about your requirements and our answer to them.

Your data is processed solely to get in touch with you. Privacy.

Frequently Asked Questions

Does all the data really stay in-house with us?

Yes. Voice data, transcripts, CRM records, recordings and logs reside solely on your hardware — in your data centre or your private cloud (Azure, AWS, OTC, Hetzner Dedicated). voiceOne needs no outbound data stream to operate. Optionally available fully air-gapped (updates via USB/trusted transfer).

Which language models are used — and do they need internet access?

You choose: (a) a cloud language model in your own tenant (EU region, no training opt-in), (b) a language model in your own VPC, (c) locally hosted open-source models on your own GPU hardware — completely offline in that case. Speech synthesis and speech recognition optionally local or via a cloud endpoint with an enterprise contract.

How does the telephony work? We already have a phone system.

voiceOne On-Prem connects to your existing phone system via SIP trunk (3CX, innovaphone, Avaya, Cisco, Mitel, Asterisk, FreeSWITCH). Alternatively, voiceOne can be operated as a complete telephony solution with a SIP provider of your choice. Mobile softphone (iOS/Android) and browser softphone run over WebRTC directly against your instance.

Which compliance requirements does the offering meet?

GDPR, BSI C5, ISO 27001-ready (controls mapping available), the gematik TI security guideline (for healthcare), § 203 StGB-compliant (for professionals bound by confidentiality: lawyers, doctors, tax advisors), KRITIS-capable, BaFin-MaRisk-compliant, HIPAA-ready (for US deployments). We supply audit packages, technical documentation and support your compliance department throughout the certification process.

Who operates the system? Do we have to host it ourselves?

Three models: (1) You operate it yourself — we supply container images, Helm charts, documentation and updates. (2) Managed On-Prem — we operate the system remotely in your data centre via a bastion host (two-factor + audit log of every session). (3) Hybrid — application at your site, 24/7 monitoring & patch management on our side over a secure read-only channel.

How long does the roll-out take?

Architecture workshop + PoC: 2–3 weeks. Full commissioning including SIP connection, LDAP/SAML integration, data migration and staff training: 4–8 weeks. We have standard playbooks for the most common stacks (Active Directory, 3CX, FreeSWITCH, Azure AD, Keycloak).

How is the commercial model structured?

A one-off setup fee (installation, configuration, training, go-live support) plus an annual licence for a standard instance with all modules. Scaling in tiers by seats and locations. Support SLA selectable: business hours, 24/7 or a dedicated Customer Success Manager. You will receive a concrete quote after a no-obligation architecture consultation — dependent on seats, locations, desired modules and SLA.

Do we get updates and new features?

Yes. Quarterly major releases, monthly security patches, immediate hotfixes for critical CVEs. Updates are verified in advance in your test environment. For air-gapped installations we deliver signed update packages via trusted transfer (USB, data diode). You retain full control over the roll-out timing.

Let's talk about your architecture.

45 minutes with our solutions architect. Concrete. Technical. No sales loops.

Request an appointment Call directly