Self-Hosted Voice AI

Your callers' data never leaves your infrastructure.

On a managed platform, every second of caller audio is processed on someone else's servers, in another country. We build voice agents that run on hardware you control — your cloud region, your premises, or fully air-gapped.

Saudi PDPLUAE PDPLDIFCHIPAADeployed in your accountFull source handover

Should you buy this?

Three reasons to own the stack. Only three.

The law requires it — data-residency rules under Saudi PDPL, UAE PDPL, DIFC or HIPAA: caller audio and transcripts can't be processed abroad

Volume changed the math — past ~25,000 minutes a month, owning beats renting. At 60,000 min/month it saves around $5,500 a month

A client contract forbids third-party processing — their compliance obligations are now yours

If none of those is you, don't buy this. Below ~15,000 minutes a month, self-hosting costs more. Start on the managed track, prove the use case, and we migrate you when volume justifies it — your conversation design and integrations carry over. Managed track →

Monthly minutesManagedSelf-hostedNote
5,000~$1,700~$2,400Managed wins
15,000~$3,200~$2,900Roughly even
30,000~$5,700~$3,500Saves ~$2,200/mo
60,000~$10,200~$4,700Saves ~$5,500/mo
150,000~$24,700~$8,300Saves ~$16,400/mo

Usage + support + infrastructure, at a $0.15/min blended managed cost.

Two options

Choose by what your rules actually require.

Everything is identical — same agents, same integrations, same ownership, same handover. One question decides your tier: may an AI provider process your data at all, once identifiers are removed?

Air-gapped deployment

Shielded

No

Isolated

Yes

Compute requirement

Shielded

Standard compute

Isolated

GPU capacity

Build time

Shielded

6–8 weeks

Isolated

8–12 weeks

See exactly what this means for Shielded, component by component, below ↓

Both tiers include the full integration suite — see all 9 modules

Included in both tiers

  • CRM integration
  • Knowledge base (RAG)
  • Calendar / booking sync
  • Payments
  • Outbound campaigns & follow-ups
  • Messaging channels (WhatsApp / SMS / webchat)
  • Supervisor tooling & QA
  • Audit logging
  • Full source + infrastructure-as-code handover

Support scope and response times are confirmed at scoping, alongside your infrastructure and hardware sizing.

Shielded — What runs where

Exactly what crosses your perimeter.

ShieldedIsolated
Language model runsProvider APIYour hardware
What leaves your perimeterCall audio · de-ID text · response textNothing
Call handlingYour cloudYour cloud
Conversation logicYour cloudYour cloud
Logs, recordings, transcriptsYour cloudYour cloud
CRM / booking / business dataYour systemsYour systems
PII de-identification layerIncludedNot needed — nothing leaves
Third-party outages affect youYesNo
Model choiceAny frontier providerOpen-weight models

If you're unsure, you're probably Shielded. We'll say so at scoping rather than sell you the larger build. Isolated exists for requirements that are genuinely absolute.

What the PII shield does on Shielded+

Names, dates of birth, national ID and passport numbers · phone numbers, emails, addresses · card numbers, IBANs, account numbers · medical record and patient identifiers · your own patterns — all tokenised before text leaves your perimeter, and restored locally so the output stays useful.

You also get: a redaction log for every call · detection rules tuned to your vocabulary · a measured accuracy report on your own real calls before go-live.

Deployment

Your account. Your infrastructure. Your bill.

Deployed into environments you control

  • Client cloud
  • On-premises
  • Air-gapped
  • Deployed into your cloud or hardware, in whatever region you require. We host nothing
  • We work through a scoped service account — deploy and monitor the voice stack only, never your wider environment
  • Revocable anytime, with no effect on the running system
  • End the engagement and everything keeps running — you hold the account, the infrastructure and the source

You'll need: a cloud account or hardware in your region · someone who can approve infrastructure provisioning · (Shielded) your own provider accounts · infrastructure budget, sized and quoted at scoping.

Proof

We've shipped this, not just scoped it.

  • A fully local voice pipeline — speech recognition, language model and voice, all on the client's own hardware, for a client requiring zero cloud dependency
  • An on-premise AI document review system for forensic reports, running entirely inside the client's environment — Read the case study →
  • 7+ years building production AI across healthcare, call centres and sales

What we won't claim

Compliance certification.

We build the technical capability that makes data residency achievable — where data flows, where it's stored, what's logged — and hand your compliance specialist the architecture documentation they need. Certifying it against HIPAA, PDPL or GDPR is their work, not ours. Be wary of any vendor who tells you otherwise.

Why it's safe to say yes

Nothing here asks you to commit blind.

Technical discovery comes first, and stands alone — architecture, data-flow map, infrastructure and GPU sizing, deployment plan and cost model. Scoped and priced separately, credited in full against the build. The documents are yours whether or not you proceed

Hear it before you provision anything — we build a working prototype of your hardest call flow in our own sandbox, so you judge the conversation before your team touches infrastructure

Success is a number in the contract — a containment target agreed at discovery and tested against your real calls

Milestone-based delivery — payments tied to deliverables you can inspect, not to a calendar

Pilot on a defined slice of live traffic before full rollout, tuned daily, with exit criteria agreed in advance

Revoke our access anytime — the agent keeps running. You hold the account, the infrastructure and the source

Your security review, procurement process and compliance approvals set the real timeline. We plan around them and tell you at scoping which milestones depend on your side.

FAQ

Questions

How is this priced?+

A fixed build fee plus a flat monthly retainer for engineering. You pay your cloud provider — and, on Shielded, your AI providers — directly, at cost. We never mark up usage.

Which languages work self-hosted?+

Whatever open-weight models genuinely support, not what a roadmap promises. We assess your language at scoping and demonstrate real output before you commit.

What hardware do we need?+

Sized at scoping against your concurrency and latency targets, then quoted before you commit. Isolated needs GPU capacity; Shielded runs on standard compute.

Can we start managed and move later?+

Yes — the right sequence for most businesses. Conversation design and integrations carry over. Managed track →

What if you disappear?+

You hold the account, the infrastructure and the full source. Revoke our service account and nothing stops. That's the architecture, not a promise.

Own the stack. Own the data. Own the economics.

Bring your volume, your jurisdiction and your constraints. We'll tell you which tier fits — including when the answer is “neither, yet.”