The Job Site Reality
You're bidding a retail chain with five locations. Each store manager wants "the cloud thing" because they saw a Verkada demo. IT says cloud is fine as long as it doesn't touch the corporate WAN. Facilities wants 30 days of retention and doesn't care where it lives. Security leadership wants failover that actually works.
Then you start the math. One site has 8 Mbps available upload. Another has a carrier that throttles video at peak hours. The third location has a flaky fiber connection that drops for 20 minutes most Tuesday mornings. Suddenly pure VSaaS doesn't look so clean. Neither does on-premise NVR alone.
Most integrators default to whatever they installed last year, or whatever the vendor rep pushed hardest. The right call depends on constraints that nobody writes down until week two of the project.
Map Your Constraints First
Before you touch a camera or a storage calculator, answer these in writing:
Uplink capacity and reliability. Check the actual committed SLA at each site, not the "up to" number from the ISP. Is it 5 Mbps, 25 Mbps, 100 Mbps? Does it drop during business hours? Has it failed in the past six months? A single retail location with 12 cameras at 2 Mbps each needs 24 Mbps sustained upload for live streams plus cloud recording. Most broadband can't do that without dropping other traffic.
Retention window. Insurance, compliance, and incident response usually demand 14 to 90 days. Cloud storage at scale gets expensive fast. 30 days of 4K retention across five sites can run $500 to $1500 per month depending on camera count and bitrate. On-premise NVR is a capital cost upfront, but you own it.
Incident response speed. If a theft happens at 2 a.m., who pulls the footage? If it's VSaaS only, someone has to log in to a cloud portal, find the right camera, and download clips. If it's hybrid with local NVR, the store manager can grab it in 30 seconds from a browser on the local network. That matters more than marketing teams admit.
Failover tolerance. What happens when the internet goes down? Pure cloud video stops recording. Hybrid systems with local NVR keep recording and sync when the link comes back. If you're in a market with frequent outages (construction, weather, aging infrastructure), hybrid is not optional.
Network isolation and security. IT will ask if cameras can be segmented from guest WiFi and point-of-sale systems. VSaaS platforms like Verkada and Eagle Eye handle this at the appliance level. Open NVR stacks with ONVIF cameras need VLAN design and firewall rules that your integrator has to specify.
The Three Paths
Pure Cloud (VSaaS)
When it works: Single location. Fast, modern uplink. No on-site IT staff. Simple multi-site management from one dashboard. Vendors like Verkada, Rhombus, and Eagle Eye have done the heavy lifting on cybersecurity, firmware updates, and cloud architecture. You don't run a server. Retention is metered per month.
Real costs: Monthly recurring. Bandwidth must be reliable. No recording if the internet fails. Vendor lock-in is real. Switching platforms later means pulling all your footage and re-hosting it.
Gotchas: ISP throttles video. Cloud platform has an outage (rare, but it happens). You want local footage fast but the cloud UI is slow. Retention gets expensive at 90 days.
Hybrid (Local NVR + Cloud Backup)
When it works: Multi-site chain. Some locations have weak uplinks. You need fast local retrieval and cloud redundancy. Capital budget exists for NVR hardware. IT wants to own the local recording and let cloud be the safety net.
Architecture: NVR records everything locally on a 16 or 32 TB drive. Selected high-priority cameras (entry, cash, loading dock) also stream to the cloud. Or the NVR uploads a compressed copy of all footage to cloud storage for long-term backup. Internet fails, local recording keeps going. Internet comes back, sync resumes.
Real costs: NVR hardware ($2k to $8k per site). Cloud bandwidth for sync or live streams (much cheaper than full VSaaS because it's not the primary recording). Local IT effort to manage NVR updates and storage.
Gotchas: You own the NVR uptime. If it fails, you lose recording until it's fixed. Storage fills up and someone has to notice. Two systems to monitor instead of one.
On-Premise Only (Traditional NVR)
When it works: Single location or small cluster. No internet requirement. Highest compliance bar (healthcare, law enforcement, nuclear facilities). You want zero cloud dependency.
Real costs: NVR hardware. Local UPS and cooling. Someone manages backups and storage. No multi-site dashboard unless you build a custom integration.
Gotchas: If the NVR fails, there's no cloud copy. If the building burns down, your footage burns with it. Scaling to five sites means five separate systems and five different management consoles.
The Build Sequence
-
Document the constraint spreadsheet. Uplink speed, reliability history, retention days, failover tolerance, incident response SLA, VLAN requirement, compliance rules. Show it to IT and Facilities before you spec hardware.
-
Size the uplink or request upgrade. If pure VSaaS, you need 30-50 Mbps upload headroom at each site. If hybrid, you need 5-15 Mbps for sync and live streams. If on-premise only, internet is optional but you still want 2-3 Mbps for remote viewing.
-
Pick the platform based on uplink and budget. Weak uplink + capital budget = hybrid. Strong uplink + monthly budget preference = VSaaS. No internet tolerance = on-premise.
-
Design the network.
- VSaaS: Firewall rules to allow camera IP range to the cloud endpoint. VLAN for cameras if IT requires it. Bandwidth throttling if needed.
- Hybrid: Local VLAN for NVR. Separate VLAN for cameras if you have IT resources. Firewall rules for cloud sync.
- On-premise: Local network only. UPS and battery sizing.
-
Test failover before go-live. Unplug the internet at one site for 15 minutes. Verify local recording continues (hybrid or on-premise). Verify cloud catches up when link returns (hybrid). Don't find out at 2 a.m. that the failover doesn't work.
-
Document retention and purge policy. Who owns storage management? How does the system alert when space is low? On-premise NVR needs a scheduled check. VSaaS handles this automatically. Hybrid needs both.
Common Pitfalls
-
Undersizing uplink for VSaaS. 15 cameras at 3 Mbps each is 45 Mbps. Most retail broadband peaks at 25 Mbps upload. You need to compress, reduce frame rate, or go hybrid.
-
Picking VSaaS for a site with known outages. If the ISP drops for 30 minutes every other week, pure cloud recording will have gaps. Hybrid or on-premise is the only answer.
-
Forgetting VLAN design. IT will ask. If you say "we'll just put them on the main network," you've already lost the deal or created a security debt.
-
Not testing cloud sync. You spec a hybrid system, NVR records locally, but the cloud upload is configured wrong. Nobody knows until you need the footage and it's not there.
-
Assuming VSaaS is cheaper long-term. Five sites, 20 cameras each, 30 days retention, 2 Mbps per camera. That's roughly $300-500/month in cloud fees. Over five years, that's $18k-30k in recurring cost. A $15k hybrid NVR investment pays for itself in two years and you own the hardware.
Wrapping It Up
There's no universal answer. A single office tower with gigabit fiber and a modern IT team picks VSaaS and moves on. A five-location retail chain with mixed uplinks and compliance requirements picks hybrid and never regrets it. A hospital with zero internet tolerance builds on-premise and owns the ops burden.
The mistake is choosing based on vendor noise or last year's project. Write down your constraints, run the numbers, and tell your customer why. They'll trust you more and you'll sleep better when the system actually works.
If you're working through this for a specific site and want to talk uplink math or VLAN design, reach out. That's the work that separates a working system from a three-alarm fire six months in.
Related: Cloud Based vs On Premise Surveillance Making the Right Choice, IP Camera Bandwidth and Storage Math for Commercial Deployments, Designing Secure VLANs for Surveillance Cameras and Access Control Systems