The question is not where the software lives. It is where the video goes, and whether it goes anywhere at all.
A camera produces a continuous stream. Something has to look at it and decide what matters. Whether that something sits in a cabinet in your building or in a data centre in another country changes your bandwidth bill, your failure mode during an outage, and — the part usually discovered late — the set of legal questions you have to answer.
Where inference runs
The four differences that matter
| On-premise inference | Cloud inference | |
|---|---|---|
| Upstream bandwidth | Near zero — only alerts and metadata leave | Continuous, per camera, permanently |
| Behaviour when the line drops | Keeps detecting; alerts queue | Stops detecting entirely |
| Cross-border transfer question | Does not arise | Arises, and must be answered |
| Cost shape | Capital up front, flat after | Low up front, scales with cameras and retention |
The second row is the one that decides it for most sites with a real security purpose. A system that stops detecting when the internet drops is not a security system; it is a security system with a documented way to be switched off from outside the building. For a perimeter or a safety application that is the wrong dependency to accept, and it has nothing to do with how reliable your provider is.
Bandwidth is not a detail at eight cameras
Streaming video off site is a continuous upload, and upstream capacity is the scarce direction on most connections. A single camera at a usable resolution is manageable. Sixteen of them, permanently, is a different conversation with your provider — and unlike a monthly licence, it is a cost that does not appear on the software quote.
Vendors handle this by sending less: lower frame rates, lower resolution, or only clips triggered by basic motion. Each of those is a reasonable engineering response and each reduces what the model can see. It is worth asking directly what is actually uploaded, because "cloud AI" applied to a downsampled stream is doing a different job from the same model applied to full-rate video on site.
The compliance difference is a removed question, not a better answer
Video of identifiable people is personal data. Oman's Personal Data Protection Law, issued by Royal Decree 6/2022 and enforceable since February 2026, controls transfers outside the country. Sending footage abroad for processing is therefore something you must be able to justify and document.
Processing on site does not answer that question better. It removes it. There is no transfer to justify, no processor location to disclose, and no dependency on somebody else's retention behaviour. For organisations whose procurement already asks where data resides — banks, government bodies, anyone handling regulated work — this is usually the deciding factor, and it is a shorter conversation than any amount of contractual reassurance.
One caution against over-claiming: on-premise processing does not make video surveillance automatically lawful. You still need a purpose, a retention period, controlled access and appropriate notice. And if the system identifies specific individuals rather than detecting generic objects or people, that is biometric processing, which under Article 5 of the PDPL requires a Ministry permit — as attendance systems have to reckon with. Location of processing and category of processing are separate questions.
When cloud is the better choice
It would be dishonest to present this as one-sided. Cloud processing is the better answer for a thin estate across many small sites — a chain of retail units with two cameras each, where putting hardware in every location costs more than the bandwidth and nobody local can maintain it. It is better where the workload is genuinely occasional rather than continuous. And it is better when you have no capital budget and a monthly figure is what can be approved, which is a real constraint rather than a poor reason.
The pattern that suits most Omani industrial, port and institutional sites is the opposite shape: many cameras in one place, a continuous workload, a real security purpose, and procurement that asks about data residency. That is what tips it on site.
What to establish before choosing
Measure your actual upstream bandwidth at the site, not the figure on the contract, and multiply by the camera count you intend to reach rather than the count you are starting with. Ask what the system does during a two-hour outage and whether detections from that window are recoverable. Establish exactly what leaves the premises — full video, clips, still frames, or only metadata — and get it in writing, because "we process in the cloud" covers all four. Confirm where processing happens geographically if anything leaves. Ask who maintains on-site hardware and what the response time is when a box fails. And separate the retention question from the processing question: where footage is stored and how long for is a decision you should be making regardless.
The honest summary
For a single site with many cameras and a genuine security purpose, on-premise inference wins on bandwidth, on behaviour during an outage, and on the compliance question it removes entirely. For a scattered estate of small locations, cloud is the sensible answer. The failure is not choosing wrong; it is choosing without measuring your upstream capacity or asking what leaves the building.
Incogniv is built by Muscat Tech Solutions to run models on-premise, so no footage leaves your site and alerts fire the moment a violation happens. To work through the trade-off for your own estate, talk to us.
Related posts
-
How GCC Statement Formats Differ, and Why It Matters
A parser that works in Muscat can be wrong by a factor of ten in Dubai.
21 April 2026 -
Why Visitor Data Is Harder Than Employee Data Under the PDPL
No contract, no employment relationship, and a person who will never log in again.
07 April 2026 -
Employee Data Under the PDPL: The Questions HR Now Has to Answer
The transition period ended in February 2026. Payroll holds most of the data the law is about.
24 March 2026


