Every security questionnaire asks the same question forty different ways: where does our data go, and who can get to it?

By the time that questionnaire arrives, your deployment model has already answered. On-prem, managed cloud and SaaS are usually compared on cost and convenience. The more consequential difference is what each one lets you truthfully say about your customers' audio, video and recordings — and a deployment diagram is a compliance argument whether or not anyone drew it that way.

This post compares the video deployment models on that basis: the claims each supports, and the ones it quietly rules out.

The three video deployment models

The labels get used loosely, so here they are pinned to the two questions that matter: whose infrastructure the media runs on, and who operates the software.

Model

Media runs on

Software operated by

Typical example

On-prem

Your own hardware, in your own facilities

You (or a vendor under your access rules)

Government, defence, regulated banking

Managed cloud

Infrastructure dedicated to you — your cloud account or a single-tenant environment

A vendor, or shared with you

Enterprises that want control without running hardware

SaaS

The vendor's shared, multi-tenant infrastructure

The vendor

Most meeting tools and video APIs

Hybrid

Media on your side; some management functions on the vendor's

Split

Platforms that separate the media path from administration

The components underneath are the same in every model — the seven things a self-hosted stack runs — and the three that carry media, the SFU, TURN and recording, are the ones whose location changes the story. So what does each model let you say?

What the video deployment models let you claim

Here are the claims customers and auditors actually ask about, and whether each model can support them without qualification.

Claim

On-prem

Managed cloud

SaaS

"Media never leaves our network or country"

Yes

Yes, if the region and relays are pinned

Only if the vendor contractually pins every component

"Only our people can access recordings"

Yes

Depends on who holds admin access and keys

No — the vendor's operators can, under their policies

"We can name every party that touches the data"

Yes

You plus the cloud provider plus the vendor

The vendor's full subprocessor list

"We decide when the software changes"

Yes

Usually

No — the vendor ships on its schedule

"A legal order served on a vendor cannot reach our media"

Yes

Depends on who has possession or control

No

"We are covered by the vendor's certifications"

No — you earn your own

Partly

Yes, within the vendor's scope

Read down the SaaS column and the pattern is not that SaaS is insecure — the last row is a real advantage. It is that SaaS converts most claims about your data into claims about someone else's policies. Two rows in that table do more work than the rest in comparing video deployment models, starting with the one people most often get wrong.

Residency is not sovereignty

Residency is where data physically sits. Sovereignty is who can be compelled to hand it over. They are routinely treated as the same thing, and they are not.

The clearest illustration is US law. Under 18 U.S.C. § 2713, added by the CLOUD Act in 2018, a provider of electronic communication or remote computing services must disclose data "within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States."

The operative words are possession, custody or control — not location. A recording stored in an Indian or European data centre by a provider subject to that statute is resident in-country and still within reach of the order. Choosing a local region answers the residency question and leaves the sovereignty question where it was. What each jurisdiction actually requires about location is the subject of where your media legally has to live.

The same logic cuts against self-hosting done carelessly. Running your own SFU on a hyperscaler still places stored recordings in that provider's custody; encrypting them with keys only you hold is what narrows the question to "who can compel you." The deployment model sets the starting point. Key custody and relay placement finish the answer — the argument made at a strategic level in the case for communication sovereignty.

The second row that matters across video deployment models is about everyone else in the chain.

Every subprocessor is part of your data story

A video service is rarely one company. The media servers may run on one cloud, TURN relays on another, recordings in a third-party object store, and transcription through an AI provider. Under the GDPR, each of those is a sub-processor, and Article 28(2) requires that "the processor shall not engage another processor without prior specific or general written authorisation of the controller."

In practice, that means the list of parties who can touch a customer's video is your vendor's subprocessor list, and it changes when the vendor's suppliers change. On-prem shortens that list to you. Managed cloud shortens it to you, your cloud provider and your vendor. SaaS inherits all of it — and when the vendor itself changes hands, the list can change wholesale, as happens when a video provider is acquired or shuts down.

The honest counterweight: on-prem moves responsibility, not risk

None of this makes on-prem automatically the safest of the video deployment models. It makes you responsible.

Cloud providers draw this line explicitly. AWS's shared responsibility model says the provider is responsible for "protecting the infrastructure that runs all of the services offered in the AWS Cloud," while for services like EC2 the customer owns guest operating system updates, security patches, installed applications and firewall configuration. Move from SaaS to managed cloud and more of that list becomes yours. Move to on-prem and all of it does — including the physical security and certifications a large vendor already holds.

For many organisations, a well-run SaaS is more secure than the on-prem deployment they would actually operate. The right question is not "which model is most secure" but "which claims do we need to make, and can we operate the model that supports them?"

Choosing a video deployment model

Start from the claims you must be able to make, then pick the least demanding of the video deployment models that supports them.

If you must be able to say…

The least demanding model that supports it

"We use a reputable, certified provider"

SaaS

"Our data stays in this country"

SaaS with contractually pinned regions and relays, or managed cloud

"Only our staff can reach recordings"

Managed cloud with customer-held keys, or on-prem

"No foreign order to a vendor reaches our media"

On-prem, or a hybrid where the media path, relays and recordings are yours

"Media never touches the public internet"

On-prem on an isolated network

The hybrid row deserves a closer look, because it is where many organisations land: the media path, TURN relays and recordings run on infrastructure you control, while a vendor handles software delivery and administration. The questions to ask of any hybrid are precise ones — which data crosses to the vendor side, in what form, and under whose jurisdiction — and they are answered by tracing where the media flows in each deployment.

Build, buy, or deploy

Building on open source gives you whichever model you are prepared to operate, with every responsibility that comes with it; what that costs is laid out in what running it yourself actually costs. Buying SaaS gives you certifications and speed, and makes your data story the vendor's. Deploying a platform on your own infrastructure sits between them.

Samvyo is one such option: based on SFU architecture, shipping the same embeddable SDKs a CPaaS provides, with OEM and white-label depth and a managed-service option — and with the media path, TURN and recording running on infrastructure you control, resilient by design. Where it does not fit: if your requirements are met by a certified SaaS provider's standard terms, that is simpler; and if you need to operate and modify every layer yourself, building is the more direct route.

The Bottom Line

Video deployment models are usually compared on cost and convenience, but their real difference is what they let you truthfully claim about your customers' media. Residency is not sovereignty — a legal order follows possession and control, not location — and every subprocessor is part of the story.

Decide which claims you need to make first. Then choose the least demanding model that lets you make them, and one you can actually operate.

What's Next

The technical companion traces where the media flows in each deployment and what each path lets you prove. For the legal side of location, see where your media legally has to live.

Frequently Asked Questions

What are the main video deployment models?

On-prem, where media runs on your own hardware; managed cloud, where it runs on infrastructure dedicated to you but may be operated by a vendor; and SaaS, where it runs on the vendor's shared infrastructure. Hybrids keep the media path on your side and leave some administration to a vendor.

Is data residency the same as data sovereignty?

No. Residency is where data is stored; sovereignty is who can be compelled to disclose it. Under 18 U.S.C. § 2713, US-covered providers must disclose data in their possession, custody or control regardless of where it is located, so in-country storage alone does not settle who can reach it.

Which of the video deployment models is most secure — on-prem or SaaS?

Not automatically. On-prem gives you control and makes you responsible for patching, configuration, physical security and certification. Many organisations are more secure on a well-run SaaS than on the on-prem deployment they would realistically operate. Choose by the claims you need to make and your ability to operate the model.

What should I ask a video vendor about subprocessors?

Ask for the full list of parties that can process your media — cloud hosts, TURN relay providers, storage, transcription and support — and how you are notified of changes. Under GDPR Article 28(2), a processor needs the controller's written authorisation to engage another processor.

Can a hybrid deployment keep media on our infrastructure?

Yes. In a hybrid, the media path, TURN relays and recordings run on infrastructure you control while the vendor handles software delivery and administration. Samvyo works this way. Ask any hybrid vendor exactly which data crosses to their side and in what form.

Which video deployment model do I need to keep recordings in-country?

Any model can, provided every component that stores or relays media — including TURN and recording storage — is pinned to the country. SaaS needs that commitment in the contract; managed cloud and on-prem let you configure it directly.