On-premise and offline

On-Premise Mailroom Software for Networks That Stay Closed

Install Traizr on your own infrastructure, or run it in a container entirely inside your network. No outbound connection is required and the data remains yours.

  • Your hardware, your data
  • No outbound connection
  • Updates on your schedule
Traizr operating as a self-contained system, with the mailroom record and its audit trail held entirely inside the organisation's own network
The same platform and the same audit trail, running securely inside your network.

When cloud is not an option, the mailroom's needs remain the same

The post still arrives. It still has to reach somebody, and somebody still has to prove that it did. Sites that cannot use cloud software usually end up running the mailroom on paper.

The result is that the mailroom reverts to paper records and spreadsheets.

  • Paper, because nothing else was permittedA logbook is not chosen on merit. It is what remains once every connected option has been ruled out.
  • The record cannot be searchedInvestigating an incident means reading through a book by hand, page by page.
  • Handovers between areas go unrecordedItems cross internal boundaries and those movements are exactly what nobody has evidence for.
  • No real proof of collectionA signature in a book proves somebody signed a book. It does not tie a named person to a specific item at a specific time.

If your constraint is about accountability rather than hosting, the standard deployment may be all you need. See government mail tracking and mailroom software for government buildings.

Deployment

Two ways to put it inside your network

  1. On your existing infrastructure

    Traizr is installed onto hardware you already run and already manage. It sits alongside your other internal systems, under the same controls, and is backed up by the process you already trust.

  2. Or as a container inside your network

    Traizr runs as a container on a Linux box or an internal web server, confined to your network. A great option when you require a deployment kept separate from everything else.

  3. Devices connect over your network

    Staff use your allowed iOS and Android phones and tablets, reaching the server across your own infrastructure. Those devices need no internet access, and there is no scanning hardware to buy.

  4. Updates arrive on your terms

    Releases are supplied to you and applied when you choose, through whatever change process governs your other systems. Nothing updates itself from outside the boundary.

Traizr running on a secure internal network: a web admin portal and mobile app connect to an on-site server behind the organisation's firewall, alongside scanning devices, printers, CCTV and local storage, with email notifications, audit logs, proof of collection and role-based access all handled inside the network

Everything still works when nothing reaches the outside

  1. Scanning an item in

    Barcode and QR scanning, label capture and photographs all happen on the device and are written to your server across your own network.

    Works closedFully. There is no external dependency at any point in the capture.
  2. Matching it to a recipient

    The recipient list lives on your install, so matching is a local lookup rather than a call to anything outside.

    Works closedFully. Lists are imported, or connected from systems inside your own network.
  3. Notifying the recipient

    Notifications to people inside the organisation travel over your infrastructure and reach them as normal.

    Works closedInternal channels, yes. SMS needs a route to an external provider, so on a fully closed site it is either unused or sent through a gateway you already permit. Worth going through your channel mix with us.
  4. Routing it onward

    Multi-hop movements between departments, floors and buildings are recorded as they happen, on the same record.

    Works closedFully. See multi-hop mail routing for what each leg records.
  5. Proving collection

    A QR code, a digital signature or a photograph at handover, timestamped against the item and the person who took it.

    Works closedFully. The evidence is captured and stored locally.
  6. Losing the network mid-round

    If a device drops off your network while somebody is working, capture continues on the device itself.

    Works closedFully. Items queue on the device and sync automatically when it reconnects, so nothing is lost or re-entered.
  7. Searching the history

    The audit trail is queried from your own install, by recipient, sender, reference or date.

    Works closedFully. The record never leaves your infrastructure, which is also what lets you export it on your own terms.

The audit trail is the reason most secure sites look at this at all. Chain of custody software covers what is recorded at each handover, and the mailroom audit trail covers what it looks like when somebody asks to see it.

The same platform, inside your perimeter

Hosting it yourself does not get you a reduced version. That is worth checking with any vendor offering an on-premise option.

  • Your infrastructure

    Installed on hardware you already run, or in a container confined to your network. Either way, the data sits with you.

  • No outbound requirement

    Nothing needs to call out for the mailroom to work. A disconnected site is a supported configuration, not a workaround.

  • Mobile scanning

    Ordinary iOS and Android devices over your own network. No dedicated scanners and no specialist hardware to maintain.

  • Capture without a connection

    Devices that lose the network keep working and sync when they return, so a dead spot in a building costs you nothing.

  • Multi-hop movements

    Every internal handover recorded on one record, across departments, floors and buildings within the site.

  • Proof at handover

    QR code, digital signature or photograph, timestamped and tied to the person who took the item.

  • Role-based access

    Users see and do only what their role permits, with administrative access controlled separately.

  • Multi-factor authentication

    Enforced for privileged access, with six-digit PIN and biometric login supported on mobile devices.

  • Searchable audit trail

    The full history of any item, by recipient, sender, reference or date, queried entirely from your own install.

  • Reporting

    Volumes, pending items, turnaround and scan activity, exportable without anything leaving your network.

  • Updates you control

    Applied on your schedule through your own change process, rather than pushed in from outside.

  • Thirteen languages

    The same multilingual interface, which matters on international and coalition sites.

Paper V Traizr on a Closed Site

The comparison is not cloud against on-premise. On these sites the real alternative is a logbook, because that is what the policy left available.

Paper on a closed siteTraizr on a closed site
A logbook at the doorA digital record per item, held on your server
Cannot be searchedSearchable by recipient, sender, reference or date
Internal handovers unrecordedEvery hop scanned onto the same record
A signature in a bookQR, signature or photo tied to a named person
No view across sitesThe same process at every site, and comparable
Investigations mean interviewsInvestigations become a search
The process lives with one personThe process lives in the system and survives them
Chosen because nothing else compliedComplies, and does the job properly

What your security team will want to know

  • Independently assessed. Our most recent external security assessment.
  • Backups are encrypted. Encrypted backups are stored separately from production, and traffic is protected in transit with HTTPS and TLS throughout.
  • Access is controlled by role. Users see and do only what their role permits, with multi-factor authentication enforced for privileged access.
  • Documentation on request. The data processing agreement, security overview, incident response plan and assessment summary are sent on request.
An illustration of a complete and verifiable mailroom audit record, the evidence a security review asks to see

Frequently asked questions

What does an on-premise install actually mean?

Traizr runs on hardware you control instead of hardware we control. There are two ways to do that. It can be installed onto infrastructure you already run, or it can run as a container that sits entirely inside your network on a Linux box or an internal web server. In both cases the software and the data stay on your side of the boundary.

Can it run with no internet connection at all?

Yes. That is the reason this deployment exists. Staff devices reach the server over your own network, and the server never needs to call out to anything. A site can be completely disconnected from the public internet and still scan, notify, route and prove collection exactly as any other site does.

Where does the data physically sit?

On your infrastructure, in whichever facility that is. Nothing is written to a system we host, and nothing synchronises to an external service unless you deliberately configure it. If your objection to cloud software is about jurisdiction rather than technology, this is usually the shortest answer to it.

How do notifications work on a closed network?

Anything that stays inside the network works normally. Notifications to internal recipients travel over your own infrastructure, and the app behaves as it does anywhere else. Channels that need an external provider, such as SMS, require a route out to that provider. On a fully closed site those channels are either not used or sent through a gateway you already permit. It is worth going through your specific channel mix with us rather than assuming either way.

How are updates applied to a disconnected site?

Updates are supplied to you and applied on your own schedule. Nothing is pushed in from outside. That is the trade you make with this deployment: you gain full control of the boundary, and you take on the decision about when to update. Most sites treat it the same way they treat any other internal system.

Do staff still use their phones?

Yes. Scanning, photographing and capturing signatures all happen on ordinary iOS and Android devices connected to your network. There is no dedicated scanner to buy, and those devices do not need any internet access.

What about sites that are only sometimes connected?

This is common with remote and mobile operations. If a device loses its connection, items queue on the device and sync automatically once it is back. That behaviour is standard in Traizr rather than something specific to the on-premise install.

Is the software different from the cloud version?

No, it is the same platform. You are not given a reduced build in exchange for hosting it yourself. It is worth checking that point with any vendor offering an on-premise option, because it is not always the case.

What certifications does Traizr hold?

Traizr does not hold ISO 27001, and we would rather say so plainly than let it be assumed. The data centre facilities used for our hosted service are certified, which is a statement about those facilities and not about us. Our most recent external security assessment, carried out by HackerGuardian, a Qualys Approved Scanning Vendor, returned zero findings. The Trust Centre holds the documentation and we send it on request.

Who is this deployment for?

Anyone whose network policy does not permit a cloud service. That usually means defence sites, government buildings, secure facilities and critical infrastructure. It also suits organisations with a data residency requirement their legal team will not compromise on. If your constraints are about accountability rather than hosting, government mail tracking covers the standard deployment.

Every deployment of this kind has site-specific constraints. Get in touch with what your network policy requires and we will tell you plainly whether it fits.

Ready to Simplify Secure Speed Up Optimise Your Building?

Bring your network constraints and your security questionnaire. We will tell you what fits and what does not. About 20 minutes.