Deployment

Your traffic
never leaves the building.

For a growing number of networks, sending telemetry to a third party is not a preference to be weighed. It is the thing that rules a product out on the first slide.

On-premise network monitoring runs entirely inside your own perimeter: the collectors, the analysis, the storage and the interface are all on hardware you control. Nothing is sent outward, which matters when the traffic itself is sensitive, when the network is segmented from the internet, or when a regulator asks where the data resides. Net-Monitor is on-premise by design rather than as a deployment option — including on networks with no outbound connectivity at all, which is where cloud-first platforms cannot follow.

Why it matters

Six reasons this is not a preference.

01

The traffic is the sensitive thing

Packet capture is a copy of what actually crossed the network. Sending that to a third party is a different proposition from sending a CPU metric, and it is the point where most security teams stop the conversation.

Ask any cloud-based product exactly what leaves your network and in what form. The answers vary enormously.

02

Segmented and air-gapped networks

OT environments, classified networks and regulated segments often have no outbound path by design. A product that needs to reach a cloud service cannot monitor them at all.

If any part of your estate is isolated, that part decides the architecture for all of it.

03

Data residency and sovereignty

Where the data physically sits is a question with a regulatory answer in many sectors. "In our cloud region" is an answer that satisfies some auditors and not others.

On-premise makes the question trivial rather than requiring a documented argument.

04

The cost curve is different

Cloud monitoring is usually priced on ingested volume. Packet-level telemetry is high volume by nature, which makes that model expensive in a way that scales badly and unpredictably.

Model the cost at full packet volume, not at metric volume. The difference is often an order of magnitude.

05

It keeps working when the link does not

A cloud-hosted monitoring platform is least useful during an internet outage — which is one of the incidents you most need it for.

Ask what the product can still show you when the WAN is down. This is a short conversation.

06

Nobody else can change it

No feature deprecations you did not schedule, no retention policy changed by someone else, no dependency on another company remaining in business.

Relevant for long-lived infrastructure, where the monitoring is expected to outlast several vendor strategies.

How Net-Monitor deploys

  • Everything runs inside your perimeter. Collection, analysis, storage and the console — on hardware you control, in a location you choose.
  • No outbound connectivity required. The platform functions fully on an isolated network, which is what makes it usable in OT and segmented environments.
  • Agentless. Nothing is installed on the monitored equipment; the platform works against the protocols the devices already speak, plus a mirror port or TAP for capture.
  • Licensed on network size, not on ingested volume. Which means retaining more telemetry does not change the bill.
Common questions

Short answers.

What is on-premise network monitoring?

Monitoring where every component — collectors, analysis engine, storage and user interface — runs on infrastructure you own and control, rather than on a vendor-hosted service. No telemetry leaves your network, which makes questions about data residency, third-party access and regulatory scope straightforward to answer.

Can it monitor an air-gapped network?

Yes. Because there is no dependency on outbound connectivity, the platform functions completely on an isolated segment. This is the case that most cleanly separates on-premise products from cloud-first ones, since the latter cannot operate there at any price.

Is on-premise more work to run?

There is infrastructure to host and maintain, which is real. What you get in exchange is that nothing changes underneath you, the cost does not scale with data volume, and the platform keeps working when the internet connection does not. For long-lived infrastructure that trade is usually favourable.

What about monitoring cloud workloads?

An on-premise platform monitors the network paths to and from cloud services, and the traffic crossing your own infrastructure to reach them — which is where most user-facing problems with cloud applications actually originate. What it does not do is instrument inside another provider's environment.

Have a segment that cannot reach the internet?

That is usually the part of the estate that decides the architecture. We will look at it with you.

Chat with an engineer