In short
Around 2022-2023 several video wall vendors bet on a cloud-managed future — the wall configuration, the source routing, sometimes the video itself, all running through a SaaS control plane. By 2026 the verdict, in our assessment, is clear: cloud-only management rarely gets through the compliance review in regulated industries. What holds up there is the hybrid pattern. This article lays out what goes in the cloud, what stays on-prem, and why the split is not a compromise but the correct design.
Why cloud-only video wall management failed
The cloud-only pitch was attractive on paper: manage every wall across every site from one browser, push updates centrally, no on-prem server to maintain. The problem is that a video wall in a control room, NOC, or SOC carries content that regulators do not allow to leave the building.
A NOC wall shows live network topology and customer-impacting fault data. A SOC wall shows live security-camera feeds and SIEM alerts. A utility control room shows SCADA telemetry from critical infrastructure. Routing any of that through a third-party cloud — even just as a control signal that implies the underlying data — triggers a compliance review that cloud-only architectures rarely pass.
The four compliance walls
- GDPR (EU). Live camera feeds containing identifiable individuals are personal data under Article 4(1). Processing that data via a control plane hosted outside the EU — or by a US-headquartered cloud provider subject to the US CLOUD Act — requires a documented transfer mechanism and risk assessment (the EU–US Data Privacy Framework, in force since July 2023, or standard contractual clauses), which many facilities prefer not to take on.
- FZ-152 and FZ-187 (Russia). FZ-152 (Article 18(5)) requires Russian citizens' personal data to be recorded and stored in databases located in Russia. FZ-187 adds critical-information-infrastructure rules for sectors such as energy, transport and finance, which are commonly interpreted as keeping the operational layer in-country and often air-gapped.
- FedRAMP and DoD impact levels (US federal). A video wall in a federal facility handling controlled unclassified information cannot route through a commercial SaaS control plane unless the provider holds a FedRAMP authorisation at the matching impact level; classified information falls outside FedRAMP and stays on separate classified networks.
- BSI C5 (Germany). The German federal cloud-security criteria catalogue sets a bar that most general-purpose SaaS control planes do not meet, pushing German public-sector deployments toward on-prem or sovereign-cloud designs.
Any one of these can be enough to disqualify a cloud-only video wall from a regulated deployment. In practice most large control-room buyers face at least one.
The hybrid pattern — what goes where
The hybrid architecture splits the system along a clean line: the control plane can live in the cloud; the data plane stays on-prem. Mersive's Solstice Cloud is one example from the meeting-room world: the cloud portal manages the deployment, while screen content never leaves the on-site pod.
What can live in the cloud
- The management UI itself — the browser application an administrator uses to configure walls, hosted as a SaaS app
- Configuration metadata — layout definitions, named scenes, user accounts and permissions, source catalogues (the address of a source, not its content)
- Fleet telemetry — which walls are online, software versions, health status across sites
- Audit logs — the record of who changed what, when (the metadata of changes, not the content shown)
What must stay on-prem
- The video itself — every pixel of every source feed. Camera streams, dashboard renders, KVM sessions never leave the local network
- The compositor — the engine that lays sources onto the wall runs on the on-prem server, next to the displays it drives
- Source ingestion — NDI, RTSP, IPMX, KVM endpoints connect to the on-prem server, not to a cloud endpoint
- The fallback path — if the cloud control plane is unreachable, the on-prem server must keep the wall running with its last known configuration. The wall cannot depend on cloud connectivity to display.
The control plane in the cloud
The value the cloud control plane genuinely delivers, once the data plane is correctly kept local:
- Multi-site management — one interface for a NOC operator managing walls across a dozen facilities
- Centralised configuration rollout — push a new named scene to every site at once
- Fleet visibility — health and version status across the estate without touching each server
The constraint that makes this safe: the control plane handles addresses and definitions, never content. A cloud control plane that says "put the source at 10.20.30.40 into tile 3" is compliant. A cloud control plane that relays the video from 10.20.30.40 is not. The architecture has to enforce that line, not just document it.
The video plane on-prem
The on-prem server does the work that cannot leave the building: ingests every source, runs the compositor, drives the displays, and holds a complete local copy of the configuration so it survives a cloud outage. For a regulated deployment, the on-prem server is also the air-gap boundary — it can run with no outbound internet at all, with the cloud control plane simply unavailable and the wall managed locally.
This is the test for any vendor claiming "hybrid": unplug the internet, and the wall must keep running and stay locally manageable. If the wall degrades or the management UI becomes unreachable, the architecture is cloud-dependent, not hybrid.
KVM in the hybrid model
IP-KVM is the case where the on-prem boundary matters most. A KVM session is an operator taking live control of a source computer — the most sensitive traffic on the wall. In a hybrid architecture, the KVM session is strictly on-prem: the cloud control plane may know that a KVM route exists and who is authorised to use it, but the keyboard, video, and mouse traffic flows entirely on the local network. Any vendor whose KVM path touches the cloud has not built a compliant hybrid system.
Where Craft Wall fits
Craft Wall is on-premises only by design. The compositor, source ingestion, and the complete configuration run on a commodity Linux server inside the facility. The browser-based control UI is served from that same on-prem server, so every deployment can run air-gapped, with no cloud dependency at all.
Craft Wall has no cloud control plane: management and configuration stay on the on-prem server, so nothing — metadata included — has to leave the site, and the unplug-the-internet test above is passed by design. See the NOC reference architecture for the on-prem design and the eight-platform comparison for how vendors differ on the cloud-dependency question — it is one of the sharper dividing lines in the category.
Closing
The cloud-only video wall was a reasonable bet that the compliance environment has largely ruled out for regulated rooms. Hybrid is not a half-measure — it is the correct architecture: the cloud does what the cloud is good at (multi-site management, centralised rollout) and the on-prem layer does what regulation requires (every pixel stays in the building). The buyer's test is simple and physical: unplug the internet, and the wall keeps working. If it does, the architecture is hybrid. If it does not, it is cloud-dependent wearing a hybrid label.
Read next: the NOC reference architecture for the on-prem design, AI-augmented video walls for why on-prem inference follows the same compliance logic, and the Craft Wall vs Userful comparison for the cloud-dependency contrast in a real evaluation.
