Voice AI that never
leaves the building
One sealed unit in your own server room answers the phone, understands the caller, acts on it, transfers the call and records what happened. No model API, no transcript crossing your firewall, no telemetry going back to us. We install it and we keep it running, with you.
- No route to the public internet
- Your own phone line terminates on the unit
- Dutch entity, European law
- A file per call that stays with you
Everything inside the dashed line runs in your own network.
Two cables, and nothing else
A phone line in, your own network out, and no route to the public internet. That is the entire footprint.
Public internet — no route in, no route out
The phone line
Delivered over a private connection, not the open internet
Your own network
The systems the assistant reads from and writes to, on your own LAN
Attack surface: two cables and the door to the room.
Why it matters
- The supplier assessment comes before the contract is awarded
- Supply-chain accountability is law since August 2026
What you gain
- No third party in the call path
- One fixed cost, no price per minute
Who it is for
One line first, with what falls outside it written down.
From briefing to running line
- 1Technical briefing
- 2Security dossier and assessment input
- 3A pilot on one line
- 4Installed and maintained
Some calls cannot cross a border, let alone an ocean
Organisations that cannot afford a breach rarely reject voice AI because they doubt what it can do. They reject it because they cannot say where the audio went.
Procurement now tests your suppliers
Security frameworks for contracts with a national-security interest assess a supplier on organisation, staff screening, physical security and digital security, cloud services included. In the Netherlands that is ABRO, in force since 1 January 2026, and the assessment has to be passed before the contract is awarded. A hosted voice service has to argue its way through that. A unit without an outbound route does not.
Supply-chain accountability is law
The Dutch Cybersecurity Act, the national implementation of NIS2, has applied since 15 August 2026 without a transition period. Every party that processes your calls falls inside your scope, so each one is a question you have to be able to answer.
The call itself is the risk
One phone call can hold a patient, a case file, a design, a supplier price or a customer account. Once a third party has transcribed it, all you can do afterwards is ask where it went. The only reliable control is that it never left.
One unit, the whole line
Not a model in a container and not a licence for you to build around. A working telephone line, in a machine that stands in your building, with the software that runs it and the tooling to manage it yourself.
The line lands on the unit
Your trunk terminates on the machine itself, or on one we arrange for you. Calls are not routed through an external platform first.
Our own orchestration layer
The software that actually runs a call: routing, transfers, tool calls, recording, retention and failure handling. It is the same layer that runs live phone lines for paying customers today, not a variant built for this occasion.
Listening, on the machine
Speech recognition runs on the unit and processes the caller while they are still speaking. It was selected on Dutch, and the line switches language mid-call without being asked. On the models we install, we have a recorded call that runs in four languages with a single voice.
A model picked for response time
The model that carries the conversation has to answer inside a second and still keep track of what the caller wants. It handles everything that has to be answered right now.
The voice, on the machine
Speech synthesis runs on the unit as well. One fixed voice, the same in every language, and no supplier can change it or withdraw it.
A heavier model behind it
A larger model sits on the same deployment for work that is allowed to take longer: reading a file, comparing records, preparing a summary. The line delegates to it and keeps talking.
Dashboard, API and documentation, in your network
Your own people manage the line: prompts, numbers, transfers, recordings, retention and users. The same dashboard and the same API our cloud customers use, served from the unit, with the documentation next to it. Nobody has to call us to change an opening greeting.
It answers in a second and thinks for as long as it needs
The usual objection to running everything yourself is that it becomes either fast and simple or slow and clever. This deployment separates the two, which is why it can be both.
Answers immediately
Anything the line can handle itself is handled on the spot, in the model that sits in the conversation.
Hands off the heavy work
Anything that needs real reasoning or a lookup in your systems goes to the heavier model as a task.
Keeps the conversation going
The assistant does not go silent while it waits. It carries on, asks what it still needs and stays in the call.
Comes back with the answer
Once the result is in, it is said out loud in two or three sentences, in the language the caller is using.
To the caller it sounds like a colleague looking something up, not like a queue.
The parts we left out on purpose
A deployment like this is judged on what it cannot do as much as on what it can. These are commitments in the design, not settings in a menu.
No outbound route is needed to hold a conversation. The line, the models and the orchestration all run inside the unit.
No emotion recognition. It has been prohibited in the workplace in the EU since February 2025, and we do not build it.
No voice biometrics and no speaker identification. A caller is identified the way your process already identifies them, or not at all.
No training on your calls. Not by us and not by a model provider, because no third party is in the call path.
No hidden telemetry. The unit does not report usage, errors or transcripts back to us in the background.
No silent updates. A new version is prepared, approved by you and installed in a window you open. Between windows the unit does not change.
Every call leaves a file, and the file stays with you
The hard part of an audit is rarely the policy. It is producing the evidence for one specific conversation on one specific day.
A record per call
Which version answered, which instructions it ran on, which tool it called, where it transferred to, what was recorded and who listened to it afterwards.
Retention you set
You decide how long recordings and transcripts are kept, per line, and the platform deletes them when the term expires.
Logs stay on the machine
Recordings, transcripts and logs are written inside your own network. Exporting them is an action someone takes, not a default.
A security dossier with the delivery
The deployment includes the documentation your own assessment needs, including the input for a data protection impact assessment.
Built for the lines that cannot be outsourced
We scope the first line narrow and write down what falls outside it, because a line that promises less is a line your security officer can approve.
Banks and insurers
Internal service desks, and lines where the caller is asking about an account, a claim or a pension.
High-tech manufacturing
Internal helpdesks and supplier desks, where what is said about a machine, a process or a supplier is the manufacturer's own intellectual property and may not become a transcript somewhere else.
Hospitals and clinics
Administrative lines: appointments, transfers, requests and call-backs. Explicitly not triage, so it stays outside the medical device regime.
Government and public bodies
Citizen-facing lines with a back office that cannot be exposed, at organisations that already have to apply the procurement assessment themselves.
Defence and police
Service desks, exercises, training roles and locations that have no route to the outside world at all.
Four steps, and a briefing first
Technical briefing
An hour with your security officer in the room. We walk through the architecture, what runs where and what the unit does not do. You leave knowing whether this is a fit, and so do we.
Security dossier and assessment input
We write the documentation your own process needs, in the shape your assessment asks for, before anything is installed.
A pilot on one line
One real line, on site, with a scope that fits on a page. Measured on your own network, against your own systems.
Installed and maintained
The unit is delivered, installed and handed over, with a maintenance arrangement and an update rhythm you control. The failure scenario is agreed in writing before it ships.
Pricing is per deployment, because the hardware follows the number of concurrent calls and the work follows your own requirements. We quote after the briefing and not before.
Available as a project, not yet as a button
A full on-premise deployment, installed and operated together with our engineers. The platform, the models and the tooling are ready for it, and the briefing can be scheduled straight away.
Provisioning an on-premise unit yourself from the dashboard, the way you already provision a cloud line. That is on the roadmap and it is not there yet, so for now a deployment is arranged with us.
The eight questions every security officer asks
Does it work without an internet connection?
Yes. Holding a conversation needs no route to the public internet, because the line, the models and the orchestration all run on the unit. The trunk can be delivered over a private connection rather than the open internet, which we arrange with the carrier as part of the deployment. The only other cable is the one to your own network.
Who can access the unit?
Your own people, through the dashboard on the machine, with roles you assign. Our engineers only in a maintenance window that you open, for work you asked for. There is no standing remote access.
What happens when a model should be updated and we are offline?
A model update is a planned action. We prepare and test a version, you approve it, and it is installed during a window. You are never forced to take one, and nothing changes underneath a running line.
What if the unit fails?
A unit is one machine, so the fallback is something we choose in advance rather than discover along the way. Before delivery we write down which one it is: a second unit, a fall-back to your existing switchboard, or an agreed period during which the line is unavailable.
Can we keep our own numbers and our own trunk?
Yes. Your trunk terminates on the unit and your numbers stay yours. If you would rather we arrange the line, we can do that too.
Which languages does it speak?
Dutch, and it switches language during a call without being asked. On the models we install we have a recorded call that runs in four languages with one voice, and we play it during the briefing.
Do you have access to our conversations?
No. We do not receive your audio, your transcripts or your logs. If you want us to look into something, you send us what you want us to see.
Can our own auditor test it?
Yes. That is the point of a unit: it stands in your building on your network, so your auditor can inspect it, log it and test it without asking a cloud provider for permission first.
Book a technical briefing
An hour, your security officer included, and a concrete answer about whether this fits your line. You get the architecture, the boundaries, and what we will not do.