# Private deployment | Call1 Technical Features

> How the Call1 appliance is built, keyed, licensed, and supported: what crosses your boundary, what stays on the box, and how support reaches it when you ask.

Source: https://call1.cc/features/private-deployment

---

[CALL 1](https://call1.cc/)

[All features](https://call1.cc/features) [RFP reference](https://call1.cc/features#technical-reference) [Pricing](https://call1.cc/contact)

[Talk to us](https://call1.cc/contact)

[Features](https://call1.cc/features) / Private deployment

05 / Deployment, security, and data lifecycle

# Run every part of Call1 inside your boundary, on a machine with no inbound ports and no vendor account.

How the machine is built, keyed, licensed, and supported: what crosses your boundary, what stays on the box, and how we reach it when you ask us to.

In this article

Why it matters

How it works

Technical shape

Data boundary

Performance

What it doesn't do

What to validate

## Why it matters

A day of your recordings holds names, account numbers, health details, card numbers, and whatever else a caller volunteers while trying to get something fixed. Streaming that to a cloud AI vendor adds a subprocessor to disclose, a breach surface that belongs to someone else, and a security review you repeat at every renewal.

So the whole stack ships to you as one versioned deployment: workbench, API, workers, model serving, database, and the working object store, on a machine we spec and image. The models sit on that machine. Scoring a call is local compute, and there is no inference endpoint anywhere in the path.

We still have to patch software, ship adapter updates, and help when a box stops keeping up. Updates travel one direction, onto the machine. What comes back is queue depth, disk health, uptime, and version numbers. Anything past that needs a grant you issue, for one instance, for a window, and it is logged.

## How it works

1. **Rack a machine that arrives empty**
  Call1 specs, images, and ships one validated configuration. It arrives with no data of yours on it and no Call1 credential in it.
2. **Generate the keys on first boot**
  Disk and application keys are created inside your building, and you set the disk-encryption passphrase. Call1 never holds a copy of it.
3. **Point the workbench at your IdP**
  Your SSO gates every session, under your MFA policy and your role mappings. Reviewers, leads, and administrators use the identity you already onboard and offboard. There is no second credential system to run.
4. **Decide the remote path, or skip it**
  LAN-only works with nothing configured, and that is the air-gapped configuration rather than a degraded one. If reviewers work off-site, the tunnel runs in your own Cloudflare account, under your contract, with your IdP in front of it. We create none of it and hold no token for it. Your own VPN is the third option.
5. **Grant support access when you want it**
  There is no Call1 account in the deployment and no network membership we hold. Break-glass is approved by you per instance, scoped to a window, audited, and pointed at fixing the system.

## Technical shape

### Application stack

Workbench, API, workers, the local model-serving seam, database, and S3-compatible working storage, versioned and shipped as one deployment. One configuration for now, so the supported environment count stays at one.

### Network

The machine dials out; nothing listens on a public IP. Your recorder writes to the drop endpoint over whatever path you configured, so remote and cloud recording sources need no inbound port either.

### Identity and access

Your SSO and MFA, roles you define, and an access log that records every workbench session and every break-glass grant. Your reviewers never hold a vendor identity.

### Keys and encryption

Full-disk encryption with your passphrase. Audio routed to your archive is encrypted with keys held on the deployment or in your KMS, so Call1 infrastructure cannot decrypt it. Playback works where your reviewers are.

### Licensing and updates

The licence is sealed to the machine's secure element and checked locally, so an air-gapped install stays licensed with no call home. Software, model, and adapter updates arrive over your tunnel or as a signed offline bundle you carry in. A lapse gates new scoring; the audio, transcripts, scores, and audit log already on the machine stay readable.

## Data boundary and privacy

> Vendor access is the control that matters. Call1 runs where you govern the network, the identities, the keys, and the data.

There is no Call1 account in your deployment to log into, no credential of ours for your network, and no tunnel we operate. Support reaches the machine through a grant you approve, and only for as long as the grant lasts.

Keys are generated on first boot inside your building, and you set the passphrase. Routed audio uses keys held on the deployment or in your KMS. The sentence a reviewer needs is that the box can decrypt for your team and Call1 cannot decrypt at all.

Telemetry off the machine is queue depth, disk state, uptime, and version numbers. A Slack or email alert carries a call ID, a flag reason, and a link back into the workbench. The surfaces with egress read a store that holds no transcript text.

An air-gapped install needs none of this: offline image bundle, local licence check, updates handed over on media. Nothing in the product stops working because the deployment has no outbound path.

## Performance

### Capacity is measured on the machine you get

One validated configuration, benchmarked against your call mix, your rubric, and the analysis modules you turn on. What we commit to is call-hours a day and a maximum processing lag on that hardware.

### Small models, many adapters

Deterministic checks answer most rubric questions outright. One base model stays in memory with a per-question adapter attached at inference, so a modest machine covers the full call stream and retraining one question leaves the other forty alone.

### A bad network does not become a backlog

Transcription, scoring, review, and most storage reads happen on the box, so an internet outage costs you remote access rather than throughput. Buy less capacity than your volume needs and the queue clears slower: expedited calls still score in minutes, everything else by morning.

## What it doesn't do

- Every deployment today runs on a machine Call1 specs and ships. Running the same image on hardware you already own is where this goes, not something you can buy yet.
- Running inside your boundary does not remove your obligations. PHI in the audio still means HIPAA; a card number still means PCI. What it avoids is a new third-party disclosure.
- Post-call redaction protects the copy on the machine. It cannot reach back into what your recorder already captured, and it does not shrink that recorder's PCI scope.
- The architecture is BAA-ready. Executed BAAs, third-party attestations, recovery objectives, and support SLAs are named in the proposal or they do not exist.
- A Cloudflare tunnel terminates TLS at Cloudflare, so a reviewer's session, including evidence quotes and playback, is readable at that edge. It is your account and your contract to weigh, and your VPN or LAN-only avoids the question.
- Break-glass is for repairing a system that has stopped working, not for reading calls.

## What to validate before deployment

1. Where does your trust boundary sit, and who administers the network, identities, hosts, and keys inside it?
2. Which outbound destinations must be allowed, and which fields does the telemetry carry?
3. Which remote path fits your policy: your Cloudflare account, your own VPN, or LAN-only?
4. What approval, duration, scope, and revocation apply to a break-glass grant, and what do you see of the session afterward?
5. What call-hours a day must the deployment sustain, and which benchmark proves it on the shipped configuration?
6. How are patching, vulnerability response, backup, and offboarding divided, and what happens to the drives when the contract ends?

[Previous feature **Smart review queue**](https://call1.cc/features/smart-review-queue) [Next feature **Versioned intelligence**](https://call1.cc/features/versioned-intelligence)

## Evaluate it in your environment.

We'll map this feature to your data boundary, call volume, acceptance criteria, and operating responsibilities.

[Talk to us](https://call1.cc/contact)

[CALL 1](https://call1.cc/)

Every call. Inside your boundary.

[Pricing](https://call1.cc/contact)

[hello@call1.cc](mailto:hello@call1.cc)
