Self-hosted · on-premise · air-gapped

Run it on infrastructure you control

Ollasync is designed to be deployed on your own servers — private cloud, on-premise, or fully air-gapped. Encrypted meetings, webinars, recordings and deal rooms, where the media, the files and the data never leave your walls.

Deployment models

From fully managed to fully sovereign

The same platform ships four ways. Move along the spectrum as your assurance requirements grow — the product experience stays identical.

Fastest

Managed · EU

We host and operate it for you in the EU (Frankfurt). Zero infrastructure to run; your data stays in the EU and your messaging stays end-to-end encrypted.

Isolated

Single-tenant

A dedicated instance operated by us but isolated to your organisation — your own database, storage and media relay, in the region you choose.

Sovereign

On-premise

The full platform deployed inside your datacenter or private cloud. You hold the keys, the storage and the network. We never touch it.

Highest assurance

Air-gapped

No inbound or outbound internet required for meetings. Runs entirely on an isolated network for the most sensitive environments.

Your environment

What runs inside your network

A small set of components, all operated by you. Every one speaks only to the others — there is no dependency on a service we run.

Application & API

The core service — rooms, deals, documents, tokens and the messaging delivery service. Speaks only to components you run.

Media relay (SFU)

Forwards live audio and video between participants. Self-hosted, so meeting media stays on your network — not a third party’s.

Encrypted object storage

Holds recordings and document blobs on storage you control, with encryption at rest per your disk/volume configuration.

Identity & SSO

Self-hosted sign-in with email, magic-link, passkeys, TOTP and OIDC single sign-on to your own IdP. No third-party identity SaaS required.

Your compliance boundary

The compliance story is simple: the data never leaves

When the software runs on your estate, regulated data stays inside the controls you already have certified. There is no third party to add to your audit scope.

  • Meeting media, recordings and documents never leave infrastructure you operate.
  • Your existing controls, audits, DPAs and retention policies apply unchanged — there is no external subprocessor to justify.
  • Data residency is exactly wherever you deploy — a region, a country, or a disconnected network.
  • Access is governed by your own identity provider and your directory, via OIDC single sign-on.
Footprint

Straightforward to run

Built on standard infrastructure your ops team already knows. No exotic dependencies.

Runtime
Standard Linux hosts with a container runtime. Orchestrate with your existing tooling.
Footprint
Starts small — a handful of CPU cores — and scales horizontally with concurrent meeting load.
Transport
TLS 1.3 everywhere; you supply certificates for your own domain.
Identity
Bring your own OIDC provider (Okta, Entra ID, Google Workspace…) or use the built-in accounts.
Updates
Versioned container images. You choose when to pull and roll forward — including in disconnected environments.
Backups
Durable state is in a standard SQL database you back up with your normal processes.
FAQ

Self-hosting questions

Do you have any access to a self-hosted instance?

No. When you run Ollasync on-premise, it talks only to the components you operate. We have no tunnel into your deployment, no telemetry back-channel is required, and we hold none of your keys, media or documents.

Can it run fully air-gapped?

Yes. Meetings, messaging and deal rooms work on an isolated network with no internet access. You pull versioned container images through your normal offline software process and deploy them internally.

How do updates work on-premise?

We publish versioned images. You decide when to update and roll forward on your own schedule — nothing auto-updates without your action, which is essential for change-controlled and air-gapped environments.

Where does data reside when self-hosted?

Entirely wherever you deploy. There is no default egress to us. Media stays on your media relay, recordings and documents on your storage, and durable state in your database — in the jurisdiction and network you choose.

Is messaging still end-to-end encrypted when self-hosted?

Yes. Messaging uses the IETF MLS standard (RFC 9420) with keys generated on devices — that’s true whether we host it or you do. Self-hosting additionally keeps meeting media and documents inside your own trust boundary.

What does self-hosting cost?

On-premise and single-tenant deployments are priced per deployment, not per seat, with a support agreement. Talk to us about your scale and we’ll size it with you.

Deploy it in your own datacenter.

Tell us about your environment — region, air-gap, identity provider, scale — and we’ll help you stand up a proof of concept on your infrastructure.

Talk to sales See the security model