Natalia Analytics On-Premise Documentation
VM appliance running on your infrastructure. 3 contractual modes depending on your GDPR requirements. No data has to leave your datacenter.
Data sovereignty
Your data stays on your infrastructure. In Strict mode, no outbound connection is required.
3 contractual modes
Strict (no DPA) / +72h Support (light DPA) / Connected (full art.28 DPA). You choose.
GDPR by design
Pseudonymization, RBAC, immutable audit log, GDPR art.17 (right to erasure).
Pick your contractual mode
Three modes, three GDPR postures, one appliance. The choice is yours and reversible: you can move from Connected to Strict at any time without losing data.
| Strict Air-gapped | +72h Support On-demand tunnel | Connected Permanent link | |
|---|---|---|---|
| Outbound connectivity | None | Outbound SSH tunnel, on-trigger only, 72h max | Permanent HTTPS to Natalia |
| DPA art.28 | None required (you are sole controller) | Light Support DPA, art.28 §3 a-h | Full art.28 DPA with sub-processor schedule |
| Typical use case | Bank, mutual, defense, public-sector OIV | Mid-market, integrators wanting reactive support | Organizations wanting qualitative textual analysis of CDR conversations (Natalia Analytics SaaS) |
| RFP cycle gain | −3 to −6 weeks (no DPA review) | −1 to −2 weeks (light DPA) | Standard SaaS cycle |
Architecture per mode
One appliance, three network postures. The diagram you can show your CISO depends on the mode you pick.
Strict
flowchart TB
subgraph LAN_S["Your premises"]
PBX_S["Alcatel PBX"]
APP_S["Natalia appliance"]
USER_S["Your teams"]
end
PBX_S -.->|Billing tickets| APP_S
USER_S -->|HTTPS local| APP_S
style LAN_S fill:#eef2ff,stroke:#6366f1,stroke-width:2px
Zero outbound connection. The appliance never talks to Natalia or the public internet.
+72h Support
flowchart TB
subgraph LAN_T["Your premises"]
PBX_T["Alcatel PBX"]
APP_T["Natalia appliance"]
USER_T["Your teams"]
end
SUPPORT_T["Natalia support"]
PBX_T -.->|Billing tickets| APP_T
USER_T -->|HTTPS local| APP_T
APP_T -.->|On-trigger SSH, 72h| SUPPORT_T
style LAN_T fill:#eef2ff,stroke:#6366f1,stroke-width:2px
style SUPPORT_T fill:#fef3c7,stroke:#d97706
Outbound SSH tunnel, opened only on your trigger, closed after 72h. Light Support DPA art.28.
Connected
flowchart TB
subgraph LAN_C["Your premises"]
PBX_C["Alcatel PBX"]
APP_C["Natalia appliance"]
USER_C["Your teams"]
end
CLOUD_C["Natalia Cloud + AI"]
PBX_C -.->|Billing tickets| APP_C
USER_C -->|HTTPS local| APP_C
APP_C -->|HTTPS permanent| CLOUD_C
style LAN_C fill:#eef2ff,stroke:#6366f1,stroke-width:2px
style CLOUD_C fill:#dbeafe,stroke:#2563eb
Permanent HTTPS to Natalia. Unlocks Natalia Analytics: qualitative textual analysis of every conversation — recurring topics, customer pain points, agent gaps. Full art.28 DPA, sub-processor schedule.
Inside the appliance
Two screens, two promises kept: the appliance boots in minutes and gives your teams a clean local UI. Nothing leaves your network.
5-step wizard, 30-45 min
Admin password, license, network mode, PBX, first collection. No internet required.
CDR analytics dashboard
Volume per day, inbound/outbound ratio, top callers, cost per extension. Accessed via HTTPS on your LAN, role-based.
Documentation sections
Contractual modes
Canonical matrix Strict / +72h / Connected. DPA, outbound connectivity, sub-processors, use cases.
On-Premise security
RFP-ready CISO reference: GDPR, encryption, RBAC, audit log, NIST SP 800-53 / ISO 27001 / ANSSI.
OVA installation
Hardened Debian OVA appliance. VMware / Proxmox / Hyper-V. 5-step wizard, 30-45 minutes.
CISO frequently asked questions
The eight questions we hear most often in security reviews. Every answer is screenshot-friendly.