SovereigntyProcurement

Why on-premise matters for seized-device data

A seized phone contains the private life of everyone who ever messaged its owner, most of whom are not suspected of anything.

Published 4 August 2026 6 min read Alexandre Ansart

There is a version of the cloud argument that treats on-premise deployment as nostalgia. Modern infrastructure is more secure than most organisations can manage themselves, the reasoning goes, and a laboratory insisting on its own servers is protecting a feeling rather than the data.

In most industries that argument is largely right. In this one it misses what the data is.

What is actually on the device

A seized phone does not contain a suspect’s data. It contains the private life of everyone who ever communicated with that person: their messages, their photographs, their locations, their medical appointments, their relationships. Most of those people are not suspected of anything and will never learn that their conversations were examined.

A laboratory holds that material under a legal authority that was granted for one case and one purpose. Everything about how it is handled follows from that: who may see it, how long it is kept, what happens to it afterwards. Copying it to infrastructure the service does not control is not a technical decision. It is a decision about the scope of an authorisation, and in several European jurisdictions it is simply not available.

Three constraints, and only one of them is technical

Legal. The authority under which evidence was seized rarely contemplates transfer to a commercial third party. Where processing by a third party is permitted at all, it usually requires a specific legal basis, a contract with defined terms, and an assessment. Some services will do that work. Many will conclude it is not worth it for a tool, and they are making a rational judgement.

Jurisdictional. A European public authority evaluating a cloud service has to consider whether a foreign legal instrument could compel disclosure of data held by the provider, regardless of where the servers are. This has been argued extensively and it is not settled to everyone’s satisfaction. For an authority handling criminal evidence, an unsettled question of that kind is usually treated as a no.

Operational. A significant number of forensic laboratories work on isolated networks. Not as a policy preference but as an architecture: the examination network has no route to the internet, because that is the simplest way to guarantee several other properties at once. Software that requires a connection, including for licensing, cannot be installed there at all.

That last point is worth dwelling on, because it is the one vendors most often discover late. A licence check that phones home is a small implementation detail in most markets. Here it makes the product unusable, and it usually surfaces during installation rather than during procurement.

What on-premise has to mean to be worth anything

The term has been diluted. A product described as on-premise that requires an outbound connection for authentication, model inference, telemetry or updates is a cloud product with a local component.

The properties worth checking are specific:

  • Does it work with no internet connection, indefinitely, including after a restart?
  • Is there any outbound connection at all, including licensing and crash reporting?
  • Where does AI inference happen, and if it is local, are the model weights present in the installation package or fetched?
  • Can the vendor reach the deployment for support, and if so, by what route?
  • What happens at renewal if the network was never connected?

Every one of those has a yes or no answer that can be verified during a demonstration. The most reliable test takes ten seconds: unplug the network cable and keep working.

The second-order argument

Sovereignty is usually presented as a defensive requirement, a box to be ticked. There is a commercial argument alongside it that lands harder with a finance director than with a security officer.

A deployment that runs local models on the customer’s own hardware, with the models replaceable, carries no exposure to a single AI supplier’s pricing, availability or terms. The supplier can triple its prices, change its acceptable-use policy, exit the market or be subjected to an export restriction, and the deployment continues working exactly as before.

For a public authority planning a five-year budget, that is not an abstract benefit. It is the difference between a predictable cost and a dependency on a commercial relationship nobody in the service controls.

Where the cloud argument is genuinely right

None of this makes cloud deployment illegitimate. Where a service is permitted to place seized-device data with a third party and has decided it is comfortable doing so, hosted infrastructure is often better run than a small laboratory’s own, and the cost is usually lower.

The failure is not choosing cloud. The failure is a product that only offers it, sold to a market where a large share of buyers are structurally unable to say yes. That constraint is not going to relax, and a laboratory that cannot place evidence in a third-party environment is not a niche. In Europe it is most of the market.

VERA

VERA is forensic analysis software for seized devices. It structures a raw Full File System extraction, makes it searchable and questionable with every answer cited, and runs entirely offline on your own infrastructure.

Request a demonstration

See it running on a real extraction

Thirty minutes, on fictitious data, with time for your questions. If VERA does not fit what your service needs, that is a useful answer too.

Every request is reviewed before access is granted.