# Self-Hosted On-Premise AI Voice Agent Licensing

> Get Self-Hosted On-Premise AI Voice Agent Licensing with Centricall AI, deploying on your cloud, VPC, or data center while keeping call data and records in-house.

Source: https://www.centricallai.com/partners/on-premise-licensing  
Markdown: https://www.centricallai.com/partners/on-premise-licensing.md

## What an on-premise license is

An on-premise AI voice agent license is a one-time license to deploy and operate a voice AI platform inside your own server or cloud account, so every call recording, transcript and customer record stays within your infrastructure instead of a vendor's multi-tenant SaaS.

- Runs in your cloud account, VPC or data centre
- Recordings, transcripts and PII never leave your environment
- One-time license, quoted once — no per-minute platform fee
- No per-seat, per-location or per-department charges
- Your SSO, VPN, key management and retention rules apply
- Stop the support term and your instance keeps running

## What multi-tenant SaaS costs you

- **Your call data lives somewhere you cannot audit (Risk one)** — Recordings, transcripts, caller names, card references and health details sit in a shared platform alongside every other tenant. Security reviews rarely fail on encryption — they fail on where the data physically lives and who else can reach it.
- **The meter never stops running (Risk two)** — Per-minute and per-seat pricing charges you more precisely as the phone system works better. At real call volume the platform fee stops being a tool cost and starts behaving like a tax on growth.
- **Someone else owns the terms (Risk three)** — Rate changes at renewal, a shifting roadmap, a new sub-processor added by email, a policy update that reclassifies your use case. When the phone line is the business, that exposure is not a procurement detail.

## What the deployment includes

- **The full production platform** — The same build answering live calls today — voice agents, admin console, dashboards and integrations. Deployed into your environment, not a trimmed-down on-prem edition with features held back.
- **Deployment into your infrastructure** — Your AWS, Azure, GCP or private VPC — or your own hardware. Our engineers deploy it with your team, or hand over a packaged deployment your infrastructure people run themselves.
- **Your own database and object storage** — Call records, recordings, transcripts, summaries and configuration are written to storage you own, under keys you hold, in the region you are required to keep them in.
- **Telephony connected through your accounts** — Number provisioning, porting, inbound answering and outbound dialling run through carrier accounts in your name. You keep the numbers and the carrier relationship.
- **Real-time voice orchestration** — The speech-to-text, reasoning and text-to-speech pipeline tuned for interruption handling and natural turn-taking — not the walkie-talkie pauses that make callers hang up.
- **Booking, CRM and API integrations** — Google Calendar, Outlook and Calendly booking; HubSpot and Salesforce sync; webhooks and a documented REST API so the agent reaches the systems you already run, from inside your own network.
- **Multi-department and multi-location support** — Separate numbers, greetings, routing rules, hours and agent behaviour per site or team, all inside the single deployment — with no per-seat or per-tenant charge for adding another.
- **Identity and access on your terms** — Wire the console into your SSO and directory, restrict it behind your VPN or IP allow-lists, and scope roles so each team reaches only the call data it should.
- **Deployment and operations handover** — An architecture and runbook walkthrough with the engineers who built the platform, so your team can operate, monitor and upgrade it rather than file a ticket and wait.

## Where each component runs

| Component | Location |
| --- | --- |
| Voice agent runtime and admin console | Your environment |
| Call recordings, transcripts, summaries and caller PII | Your environment |
| Database and object storage, with your encryption keys | Your environment |
| Logs, audit trail and retention jobs | Your environment |
| SSO, network controls and user directory | Your existing identity stack |
| Telephony numbers, trunks and minutes | Your carrier account |
| Speech and language model inference | Your model provider account |
| Centricall production access | None after handover |

## Compliance and data residency

- **Data residency you can evidence — Deploy in the region you are required to keep data in** — Because you choose the account and the region, residency stops being a vendor promise in a trust centre and becomes a line in your own infrastructure inventory that an auditor can verify directly.
- **HIPAA and PHI handling — Protected health information stays inside your controls** — Call audio and transcripts containing PHI are stored in the environment your existing safeguards, BAAs and access reviews already cover, instead of being handed to another downstream processor to account for.
- **GDPR access and erasure requests — Subject requests become queries you run yourself** — Export and deletion run against your own database on your own timeline. No vendor ticket, no waiting on a third party to confirm a record is gone, no unclear split of controller and processor duties.
- **Consent, recording and retention rules — Configured per jurisdiction, enforced in your stack** — Two-party consent notices, recording toggles, redaction and retention windows are set to what your regulator and your legal team require, and applied by jobs running inside your environment.
- **Your security controls, unchanged — SSO, VPN, allow-lists, KMS, monitoring** — The platform sits behind the controls you have already had audited rather than adding a new externally-hosted surface that has to be reviewed, penetration-tested and re-approved on its own.
- **No surprise sub-processors — You choose every vendor in the path** — Telephony and model providers are your accounts, contracted by you. Nothing new appears in your data-flow diagram because a platform changed suppliers between renewals.

## The economics

- **The platform cost stops scaling** — Per-minute SaaS pricing rises every time the agent answers another call. An on-premise license fixes the platform line permanently, so only genuine usage — carrier minutes and model inference, billed to you at provider rates — moves with volume.
- **Nothing is charged per seat or per site** — Adding a department, a clinic, a branch or a second language is a configuration change inside a deployment you already run. There is no tenant fee, no seat count to negotiate and no upgrade tier gating the feature you need.
- **Quoted once, against your deployment** — What we scope on the call is your environment, call volume, integrations and how much of the deployment you would like us to drive. You get one figure for that scope, and it does not change because your call volume grew.

## Signs you are past the hosted tier

- Call volume is high enough that per-minute platform fees have become a visible line item
- A security or procurement review has already stalled a cloud voice tool
- You operate in healthcare, legal, financial services or the public sector
- Call recordings have to remain in a specific country or on your own hardware
- You run multiple locations or departments and refuse to pay per tenant
- You have been repriced or deprecated by a platform vendor before

## The deployment path

- **01. Fit check** — A short call on your call volumes, target environment, integrations and compliance obligations. If a hosted deployment would genuinely serve you better, we will say so on this call rather than after a contract.
- **02. Architecture review** — We map the deployment against your infrastructure and security requirements — region, network topology, identity, key management, retention — and produce something your reviewers can actually sign off.
- **03. Commercials** — One licensing agreement and one quote for the scope agreed. No per-minute platform metering, no seat count, and no clause that reprices you as your call volume grows.
- **04. Deployment** — Our engineers deploy into your environment with your team, or hand over a packaged deployment your infrastructure people run themselves. Integrations, numbers and agent behaviour are configured against your live workflows.
- **05. Go live and support** — A validation pass on real calls, a walkthrough for the people who will operate it, and an ongoing support and update term with a named route to our engineers.

## What the license covers

- Deployment of the platform inside your own infrastructure
- Use across your own departments, locations and brands
- Your data, your storage, your encryption keys, your retention rules
- Configuration of agents, prompts, routing and integrations by your team
- A support and update term, with a named engineering contact

### What it does not cover

- Source code access — the platform is deployed, not handed over as code
- Reselling, sublicensing or hosting the platform for third parties
- Operating client-facing accounts for other businesses
- Rebranding the platform as your own commercial product

## Hosted, on-premise and white-label compared

|  | Hosted plans | On-premise license | White-label license |
| --- | --- | --- | --- |
| Where it runs | Our multi-tenant cloud | Your cloud account, VPC or hardware | Your infrastructure |
| Who holds the call data | We do, on your behalf | You do, exclusively | You do, exclusively |
| Platform cost shape | Monthly plan plus per-minute overage | One-time license, no per-minute platform fee | One-time license, no revenue share |
| Source code | Not included | Not included | Included in full |
| Resale to third parties | Not permitted | Not permitted | Permitted and expected |
| Runs under your brand | Agent behaviour only | Internal deployment, your identity stack | Every client-facing touchpoint |
| Built for | Teams that want it live this week | Regulated, high-volume and data-sensitive operations | Agencies, MSPs and resellers selling it on |

## Sectors that deploy this way

- **Healthcare and dental groups** — Appointment calls carry PHI in the first ten seconds. Keeping recordings and transcripts inside the environment your BAAs and safeguards already cover removes the hardest question in the review.
- **Law firms and legal services** — Intake calls are privileged the moment they connect. Privilege and client-confidentiality duties are far easier to defend when no third-party platform ever held the recording.
- **Financial services and insurance** — Card references, account details and advice given on a recorded line sit inside PCI and regulatory scope. On-premise keeps that traffic within the perimeter you already certify.
- **Government and public sector** — Procurement frequently mandates in-country residency and forbids shared-tenancy processing outright. A deployment in your own approved environment answers both requirements.
- **High-volume contact operations** — Once minutes run into the tens of thousands a month, a per-minute platform fee is the single largest controllable cost in the stack — and the only one a fixed license removes entirely.
- **Multi-location and franchise groups** — Dozens of sites, each with its own number, hours and routing, on one deployment — without a per-tenant or per-seat charge multiplying across the estate.

## Straight answers

### What actually reaches us after go-live?

Nothing from your call traffic. The platform runs in your environment and there is no telemetry pulling recordings, transcripts or caller records back to us. During the support term you decide what you share when you raise something — a log excerpt, a redacted transcript, a screen share — and that is the only path by which we see anything at all.

### What happens if we stop the support term?

Your deployment keeps running. There is no licence server to phone home to and no remote kill switch, so ending the term stops updates and engineering support rather than the platform. You can restart it later, and we would rather you leave and come back than stay because leaving was made painful.

### Do we need a platform team to run this?

You need someone who owns your cloud account. Beyond that, no — our engineers can carry out the deployment and hand you a running platform with a runbook, and day-to-day work after that is configuration rather than engineering. Teams with their own infrastructure people usually prefer to drive the deployment themselves, and that option stays open.

## What you would be running

- [Inbound call answering](https://www.centricallai.com/features/voice-ai-receptionist)
- [Outbound call campaigns](https://www.centricallai.com/features/inbound-outbound-calls)
- [Round-the-clock cover](https://www.centricallai.com/features/24x7-availability)
- [Routing and escalation](https://www.centricallai.com/features/customizable-responses)
- [CRM and calendar sync](https://www.centricallai.com/features/crm-integration)
- [Recordings and transcripts](https://www.centricallai.com/features/call-summary-recording)

## On-premise FAQs

### What is an on-premise AI voice agent?

An on-premise AI voice agent license is a one-time license to deploy and operate a voice AI platform inside your own server or cloud account, so every call recording, transcript and customer record stays within your infrastructure instead of a vendor's multi-tenant SaaS. In practice it means the voice agent answering your phone runs on infrastructure you control, and no third-party platform ever holds the recording of a customer call.

### Is this the same as a self-hosted AI voice agent platform?

Yes — on-premise, self-hosted and private-cloud describe the same arrangement here, and buyers use the terms interchangeably. What matters is the tenancy: the platform runs in an account you own, whether that is your own hardware, a dedicated VPC in AWS, Azure or GCP, or a data centre you already operate. We deploy into whichever of those your security team has already approved.

### Will our call data ever touch Centricall servers after deployment?

No. Once deployed, the application, database, object storage, recordings, transcripts and user records all live inside your environment. There is nothing sending call data back to us, and we hold no standing production access. Anything you choose to share while raising a support issue is shared deliberately by you, and nothing moves without that.

### Do we get the source code?

No. This license covers deploying and operating the platform inside your own infrastructure for your own business; it does not include source code, and it does not include the right to resell, sublicense or host the platform for anyone else. If holding the code and selling the platform on to your own clients is what you are after, that is our white-label license instead.

### How is this different from the white-label license?

The on-premise license is for running the platform for your own organisation: your calls, your data, your locations, no resale. The white-label license is for selling it — it includes the full source code and the right to rebrand the platform and operate client accounts under your own name. Same platform, different rights, different buyer.

### Can we run this for multiple locations, departments or brands?

Yes, and there is no per-seat, per-location or per-tenant charge for doing so. Each site or team gets its own numbers, greeting, business hours, routing rules and agent configuration inside the deployment you already run. The only thing that grows as you add locations is infrastructure and usage, billed to you at provider rates.

### Does on-premise deployment help with HIPAA, GDPR and security reviews?

Substantially, because it removes the questions those reviews usually fail on. Security assessments rarely stall over encryption — they stall over where data physically lives and who else can reach it. Running the platform inside your own environment puts call recordings and transcripts under the controls, safeguards and agreements you have already had audited, and makes GDPR export and erasure requests queries you run yourself rather than tickets you file with a vendor.

### What infrastructure do we need?

A cloud account or server environment you control, plus provider accounts for telephony and for speech and language models. The exact sizing depends on concurrent call volume, and we work it out with your team during the architecture review before anything is committed, so there are no surprises on your first infrastructure invoice.

### How long does deployment take?

Most deployments go live within days of the agreement and infrastructure access being in place. Where it takes longer, the reason is almost always on the approval side — a security review, a network change or a carrier porting window — rather than the deployment itself, and we will flag which of those apply to you on the fit-check call.

### What does an on-premise license cost?

It is a one-time license, quoted once against your deployment scope, with no per-minute platform fee and no per-seat or per-location charge. What varies between deployments is the environment, the integration work and how much of the deployment you would like us to drive — so we quote it accurately for your situation rather than publish a figure that would be wrong for almost everyone reading it. Telephony and model usage are billed to you directly by those providers at their rates, with no margin taken by us.

### How does the cost compare with per-minute SaaS pricing?

The difference is structural rather than a discount. Per-minute platform pricing rises every time the agent answers another call, so the better the system works the more the platform costs. An on-premise license fixes the platform line permanently and leaves only genuine usage — carrier minutes and model inference — variable. That is why the case is strongest for high-volume operations and weakest for low, occasional volumes, where our hosted plans are the honest recommendation.

### Can we integrate it with our internal systems?

Yes, and being inside your own network makes it easier rather than harder. There are documented REST APIs and webhooks, plus HubSpot, Salesforce, Google Calendar, Outlook and Calendly integrations out of the box. Because the platform sits inside your perimeter, it can reach internal databases, practice-management systems and line-of-business tools that you would never expose to an external SaaS vendor.

### Who handles updates and support?

Updates and engineering support are covered by an ongoing term agreed at deployment, so platform improvements — model, voice and telephony changes included — reach your instance on a schedule you control rather than being pushed at you mid-shift. You choose when to apply them, and if you end the term your instance keeps running exactly as deployed.

### What if Centricall changes pricing or is acquired?

Your deployment is unaffected, which is much of the point. The platform runs on your infrastructure under a license already granted, so there is no account for anyone to reprice, throttle or switch off. Your only exposure to us is the optional support and update term, and ending it leaves the platform running.

### What happens on the first call?

We cover your call volumes, the environment you want to deploy into, your compliance obligations and which integrations matter, then walk you through the platform and the architecture so your technical people can interrogate it properly. If on-premise is the wrong shape for you, we will tell you on that call. There is no obligation at any stage.

### What deployment model should a regulated company use: SaaS, private tenant, or self-hosted?

It follows from one question: who is allowed to hold the call recording. If a shared multi-tenant platform holding customer audio is acceptable to your reviewers, SaaS is simplest. If it is not, a private tenant narrows the blast radius but the vendor still holds the data. Self-hosted is the only model where recordings, transcripts and caller PII never leave infrastructure you control, which is why regulated buyers usually end up there regardless of where they started.

### What enterprise deployment features should we look for?

Role-based access control, single sign-on, audit logging of who accessed which recording, configurable retention and deletion, data residency you can evidence, and an integration model that does not require broad standing credentials into your core systems. Ask how each is evidenced to an auditor rather than whether it exists.

### How do you handle data residency and multiple regions?

Because you choose the cloud account, region and data centre, residency stops being a vendor promise and becomes a line in your own infrastructure inventory. For organisations operating across regions, separate deployments can be run per region so data never crosses a boundary it should not.

### Does Centricall claim SOC 2, HIPAA, PCI or GDPR compliance?

We do not publish compliance certifications as marketing claims, and we would encourage the same scepticism toward any vendor that does without showing you the report and its scope. What an on-premise deployment does is remove us from the data path entirely: the controls, the residency and the retention become yours, inside an environment your auditors already assess.

### How do we evaluate the security of a voice AI platform?

Ask where audio is processed and stored, which sub-processors touch it, how long it is retained by default, who inside the vendor can access a recording, how access is logged, what happens to your data if you leave, and whether any model provider retains prompts or audio for training. The answers to those seven questions separate platforms far more reliably than a certification badge.

### Can it handle enterprise call volumes and concurrency?

Concurrency is provisioned against your measured peak rather than an average, and because the deployment runs on your infrastructure you control the headroom rather than sharing a pool with other tenants. Size it from your busiest hour, not your monthly total, because the busiest hour is what fails.

### Can we run a private AI answering service on our own server?

Yes, and that is precisely what this license is. The platform is deployed inside your own cloud account, VPC or data centre, answering your phone lines, with no per-minute platform fee and no call data leaving your environment.

## By territory, and the reading behind this page

What changes about a self-hosted deployment depending on which regulator your board answers to, plus the pieces that cover the architecture itself.

- [Self-hosted for regulated US industries](https://www.centricallai.com/locations/on-premise-ai-voice-agent-usa): The business-associate chain, the continuing duty to assess service providers, and why state AI guidance keeps going stale.
- [On-premise with Canadian data residency](https://www.centricallai.com/locations/on-premise-ai-voice-agent-canada): When Canadian law genuinely requires in-country processing, which is less often than most vendors imply.
- [A private AI answering service on your own server](https://www.centricallai.com/article-and-insight/private-ai-answering-service-own-server): What running the platform yourself actually involves, from provisioning through to handover.
- [A security checklist for connecting a voice agent](https://www.centricallai.com/article-and-insight/security-checklist): The seven questions that separate platforms more reliably than any certification badge.
- [Build vs buy](https://www.centricallai.com/article-and-insight/ai-voice-agent-build-vs-buy): The comparison worth doing honestly before licensing rather than building one internally.
- [white label AI voice agent platform](https://www.centricallai.com/partners/white-label-licensing): The other licence: rebrand the platform and resell it to your own clients rather than running it for yourself.

---

Every page on https://www.centricallai.com is available as markdown at the same URL with `Accept: text/markdown`, or by appending `.md`. Site index: https://www.centricallai.com/llms.txt · https://www.centricallai.com/sitemap.xml
