Sovereign by default. Auditable by design.
On-premises does not automatically mean secure. Tessavox puts a control at every layer — identity, permissions, transport, meeting rooms and audit — and keeps every byte of video, voice, recordings and AI processing inside your perimeter.
Six layers, each with its own controls
An internal security review and hardening round was completed in September 2026. We support customer security assessments, vulnerability scanning and audits.
Identity
Signed access tokens for every function · passwords stored as one-way hashes · automatic lockout after repeated failures · tokens revoked on logout or password change.
Permissions
System administrator, meeting administrator and user roles · admin functions by role · sensitive data such as room PINs visible to administrators only · disabled accounts cannot sign in.
Room access
Members, PINs, scheduled guest lists and time windows decide who enters which room · external devices cannot dial themselves in · captions and translated voice follow the same rules.
Transport
Web, media and caption connections encrypted in transit · a private certificate authority restricted to your internal addresses · desktop apps verify the server certificate.
Minimal exposure
Database and control interfaces reachable only inside the server · only required ports exposed, behind a firewall · services use a least-privilege database account.
Audit
Logins, room entries, permission denials, PIN failures, recording access and listen-in sessions are all recorded · administrator room entries too · clients can only report a fixed set of events, so the log cannot be forged.
Who can enter which room is decided by rules, not luck
| Room / caller | Who can enter |
|---|---|
| Fixed rooms | Members enter directly. Non-members with the correct PIN receive a 12-hour pass. Rooms without a PIN are members-only. |
| Scheduled meetings | The guest list (including the organizer), from 15 minutes before the start to 30 minutes after the end. |
| Personal rooms | The owner and the people the owner invites. |
| System administrators | Any room — and every entry is logged. |
| External devices and callers | SIP and H.323 devices are dialed out by someone in the meeting. Callers on a trunk: whitelist or voice PIN. |
| Captions and translated voice | The same rules. No permission, no captions. |
PIN guessing stopped
Five wrong PINs for the same room within 15 minutes pauses that person. Failures and successes are both logged.
Two checkpoints
Browser and desktop clients check before joining and ask for a PIN when needed; the switch checks again and rejects any unregistered room number.
Smooth rollout
Three modes — off, log-only, enforce. Observe in log-only, confirm the member lists, then switch to enforce without disturbing meetings in progress.
Nothing to send, nothing to leak
Video, voice, chat, recordings, transcripts, captions and accounts are stored on the server in your room. Speech recognition, translation and speech synthesis run there too. Tessavox works on a network with no internet connection at all.
- Recordings and transcripts never leave your storage; access is supervised and logged
- Live listening is off by default and governed by the customer
- Retention periods set by you, not by a vendor's terms of service
See it live — on our hardware or yours
A 60–90 minute demo: command-center layout, a drone on the TAK map, radio translation and the phone system, shown end to end. Online, or at your site fully offline.