Residences·Insights·Security

A practitioner's note

Home CCTV without the cloud – why footage from your house should not leave your property

Wojciech Tracichleba 17-minute readSecurity
Illustrative photograph — I do not publish photographs of completed projects.

In brief

A camera is a window somebody mounted in your house and pointed inwards. The question is not “does it record”, but: where does that footage go, who can access it, and how long does it sit there. In the most popular model sold today, the answer is: on the manufacturer’s server, you do not know who, and you do not know for how long. I write here about the model where the footage stays on your property – local recording, cameras with no route of their own to the internet, and a radical variant where the only thing that leaves the system is a signal that says “something is happening”. One caveat up front: I do not design CCTV systems. As the contractor, I am responsible for making room for them in the design – cable routes, power, a dedicated room – and for making sure those decisions are taken before the plastering.

Where the footage goes

A conversation about cameras usually starts with resolution and how much you can see at night. From my conversations with clients I know that the question of where the footage goes comes last, or not at all. And it is the first question.

The default model on the market works like this: the camera connects to the manufacturer’s server, and you watch the picture in an app on your phone. It works well, it is set up in fifteen minutes, and for the first few months there is no reason to think about it. You only have to say out loud what the arrangement means: recordings from the inside of your house physically sit on the server of a company you do not know, under the law of a country you did not choose. You have access to them on the terms written into the service agreement. And for as long as that company exists and keeps the service running. In some systems everything passes through that server; in others only the live view and notifications, while the recording itself stays at home – which functions travel which way is a question you put to the seller directly, because you cannot see it on the box.

There is no conspiracy theory in this. It is simply how the service is built. A recording that sits with whoever stores it is available to whoever stores it. It is available to anyone who successfully breaks in. And it can be handed over on a request from the authorities addressed to the keeper – not necessarily to you. All of that is decided by the terms of service nobody reads, not by the settings in the app everybody clicks.

Security researchers documented the case of a manufacturer who advertised that recordings “never leave your home” – while its cameras were sending material to company servers even with the cloud switched off. Deleting the recordings in the app did not remove them from the servers. I am not bringing this up to scare anyone. I bring it up because it carries the one practical lesson I take from it: the promise on the box and the actual traffic on the network are two different things, and only the second one can be checked.

Footage that stays on your property

The local model is older than the cloud and simpler than it sounds. In the arrangement I consider the benchmark, the camera gets one cable – a twisted-pair lead that carries power and picture at the same time. The cable ends in a recorder that stands in your utility room and writes the footage to its own disks. The picture has nowhere to go – on one condition, which I will come back to in a moment: that the cameras have not been given a side route of their own to the internet. The route in the design ends at a piece of equipment you can touch.

The thing that for years was the main argument for the cloud, namely working out what is actually in the frame, now runs on site. Telling a person from a deer, a line crossed at the fence, a car at the gate: a decent camera or recorder can do that today without asking the internet for its opinion. To be fair, let me also say where the cloud still has a real edge: matching faces against very large databases and tying many sites together. Neither of those is needed to keep watch over one house.

There is one more decision that settles your independence for years: whether the system speaks an open standard. There are widely adopted standards that let cameras and recorders from different makers talk to each other. A camera that supports them will work with a new recorder when the old one ages out – and the other way round. A camera from a closed ecosystem talks only to its maker’s equipment and its maker’s server; sometimes local access to the picture is deliberately blocked. In the first arrangement, years from now, you replace a component. In the second, you replace the system.

The camera that phones home

Now a thing surprisingly few buyers know: a camera is a computer. It has a processor, an operating system, and its own opinion about who it wants to talk to. The fact that it records to your local recorder does not mean it is not holding its own conversations with the internet on the side – with the manufacturer’s servers, with remote-access brokers, with update servers. The recorder does not switch those connections off. It does not even know about them.

That is why I treat locality as a property you demand and then verify. At the acceptance of the installation I put it plainly: the cameras and the recorder are to have no route of their own to the internet, and the whole system is to keep recording with the internet physically disconnected. That gets shown at the handover – it works or it does not. On top of that, one question worth asking the integrator directly: what does this equipment do when the internet disappears for a week. Some devices designed around the cloud behave badly when simply disconnected: they lose functions nobody would have suspected. This, too, is not something to assume. It gets checked before the handover, not after a break-in.

For those who want certainty about the electronic route, there is an even simpler arrangement – and I like it because you can see its boundary with the naked eye. The system records and analyses the picture by itself, with no connection to any network. The only thing that goes outside is a contact: two wires that can be closed or opened. Two states, nothing more. When the system decides something significant is happening, it closes the contact – and that is all the world gets to know. The alarm system receives the signal “something is happening” and carries on according to its own procedures.

You cannot send a picture down that route – so you cannot steal a picture down that route. There is no clever security product to thank for this. It is physics: through a switch that knows two states, not a single frame will fit. You do not have to trust software settings or a manufacturer’s declarations. You just look at two wires. (An electrician will confirm it faster than an IT specialist can open his laptop.)

And here honesty requires finishing the sentence: there is no absolute security in this. There is the removal of one route – the remote one. The physical route remains: someone who enters the room and takes the recorder or the disks themselves. That is why the second layer of this variant concerns the storage media. The password to the recorder protects its menu. From a disk taken out of the unit, the recordings can be recovered on another computer, if the writing is not encrypted. Encryption of the recordings is a feature you ask about directly at purchase. So that the theft of the recorder means the loss of hardware, not the leak of private footage. It has its price, and I name it here: the strongest variants can require a human being at every start-up, because after a power cut the system will not come up on its own. That gets settled with the installer when the equipment is chosen.

The price of this choice

You will not see the live view from the airport – at least not in the variant cut off from the network. That sentence has to be said plainly, because the whole inconvenience of this model lives in it. Checking what happened in the night means walking up to the equipment. For some people that is too much – and I understand it, because the convenience of a live view is real, and so is the unease on a longer trip.

For that I have an answer my conversations with clients have taught me: a deliberately mixed arrangement. A few cameras in a convenient ecosystem with an app, pointed where the picture is half-public anyway (the driveway, the wicket gate, the entrance gate), treated as if their footage were public, because in practice it is. The framing of those cameras still keeps to your own property – the boundaries from the section on the law apply to them just the same. And the rest of the house separated: interiors locally only, or not at all. It is a decision, not a technical compromise: you choose how much convenience you are buying for how much privacy, and you know what you are giving away. My job is to show what is being given away. The choice is yours.

Who watches the recordings

In a house where people work (cleaning, childcare, the garden, servicing), the archive of recordings is a record of everyone who spends time in it. A system where everybody knows the same code and viewing the archive leaves no trace is not a system.

The principle is the same one I described with the alarm: everyone gets access to what they need for their work. In CCTV that means separate accounts instead of a shared code, different permissions for different roles, and a record of who viewed the archive. The live view and the archive are two different permissions. The service code is not the owner’s code, and a service technician needs access to the settings, not to your last week of footage.

And the question you ask before the acceptance of the installation, not after: what remains after the technician leaves. Remote access “just in case”, left behind after commissioning, is a back door into the system – even if nobody had bad intentions, and most of the time nobody did. Good companies raise this themselves. The rest have to be asked.

The law: when a camera stops being a private matter

Here I slow down, because the ground stops being technical. As long as the cameras cover only your house and your plot, and only the household spends time there, CCTV is, as a rule, a private matter. That status is easy to lose. And it is usually lost without knowing it.

The first boundary: people who work in your house. The moment your home becomes someone’s workplace, recording stops being purely a technical question. There are rules: what the monitoring may serve, which rooms it must not cover, how long the recordings may be kept, and what people have to be told before the system goes live. Employment, a contract, or an outside firm: the scope of the obligations varies, and that is exactly what you ask a lawyer about. The second boundary: the frame. A camera that catches the street or the neighbour’s garden steps outside your private matter; such cases have already gone before the courts. The third: sound. Recording conversations is a different category from recording pictures and the bar is much higher; in practice the microphones stay off until a lawyer says otherwise.

I will not write out here how to arrange it, for a simple reason: I am not a lawyer and I do not intend to pretend to be one. I write this so that you know these boundaries exist, and that the conversation with a lawyer should happen before the camera goes up – ideally while the layout is still on paper. Moving a camera on paper costs as much as a pencil line.

Where it physically stands

The recordings have to sit somewhere. In the local model they sit on disks in your house, on a physical piece of equipment. One camera recording around the clock produces, depending on picture quality, from a few to several dozen gigabytes a day; a handful of cameras over a month is single terabytes. The recorder works day and night all year round. Disks for that kind of duty are different from the ones in a laptop and they wear like any working part – at some point they will need replacing. The unit runs warm, hums, and wants to breathe; a tight, closed cabinet with no airflow shortens the disks’ lives faster than anyone assumes. And when the space runs out, the recorder overwrites the oldest footage. A disk too small means the material from the one day that matters may no longer exist.

That is why the recorder has its place in the design: a utility room, power with backup, ventilation, and a locked door. Who holds the key to that room is part of the system – physical access to the device everything sits on is the weakest point of the whole local arrangement. And the advice I have been repeating for years with ordinary houses: when the electrician is roughing in the wiring, ask him to add cables for cameras to the place where a recorder could stand. Cameras – unlike an alarm, which can be wireless – are genuinely worth running on cable. Even if in the end you install nothing, the cables disappear under the plaster and wait. With a residence this advice stops being enough: add the room, the power, the cooling and the disks, that is, things that have to be in the design. All of it is settled before the plastering, together with the electrical installation. And for outdoor cameras the same decision comes back once more at the facade, the soffit and the fencing – the routes run through there as well.

When CCTV is theatre – and what I don’t promise

A camera stops nothing. It records. If stopping is what you care about, the conversation is about the alarm system – the camera records, the alarm responds, and those are two different questions – and at the end of that ladder stands the protected room, which I have written about separately. CCTV answers the question of what happened and who it was. That is a lot. But do not confuse it with preventing the event.

There is also CCTV that is pure theatre: cameras bought because it seemed proper to have them, hanging where the cable was easiest to run, with recordings nobody has ever watched and never will. More often than adding cameras, I suggest to clients taking some away. The question “what are we defending against” works here too. Sometimes the answer is: against nothing, it just seemed proper.

And the boundary talked about least, because it is not technical: a house under constant observation cannot be unseen. A camera in the living room pointed at the sofa changes the way people sit on that sofa – adults and children alike. That is a cost too, only paid by the family, not by bank transfer. Interiors get covered sparingly or not at all, because a home is supposed to remain a home.

I do not start with the number of cameras. I start with the question of what you actually want to see: the gate, the approach to the house, the interiors – or simply to have a recording if something happens. The rest depends on preference and on the neighbourhood. Not every house needs the same things, and that is fine.

What I do not promise: that a local system will stop somebody who came with intent, because stopping is the job of other layers; that cutting off the network settles the matter of security, because it only removes the remote route; and that I will tell anyone, publicly or privately, how arrangements of this kind look in specific clients’ homes.

What I ask before I say “yes”

  1. Where does the footage from the cameras go, and can it be shown that it goes nowhere further?
  2. Do recording and analysis work with the internet disconnected – and will I see that at the handover?
  3. Do the cameras speak an open standard – and what exactly works over it, and what only in the manufacturer’s app?
  4. What exactly leaves the system: pictures, events, or a bare contact?
  5. Who has which account, who can see the archive, and where is the trace that somebody viewed it?
  6. What remains after the service technician leaves, and who knows about it?
  7. Are the recordings on the disks encrypted, and what happens to the system after a power cut?
  8. Where does the recorder stand, who has the key to that room, and when do we plan to replace the disks?
  9. Where do the outdoor routes run, and are the camera positions agreed before the facade and the fencing are closed?

Frequently asked questions

Can CCTV without the cloud be viewed on a phone?

At home, yes – over the house network, with no outside server involved. Away from home it can be done too, but the honest answer is: every remote view opens some route into the system, and the difference lies in whether that route was built deliberately and who controls it. If the view from a trip matters to you, tell the integrator at the start – a route designed and written into the documentation is a different thing from a factory route through the manufacturer’s server that nobody told you about.

Can cameras be added after the build?

They can, and it is done often – only then you can see that somebody was late: trunking, chased walls, or a compromise in the one spot the cable could no longer reach. Cameras need cable more than an alarm does, which can be wireless. The inexpensive move is to ask the electrician for cables while the wiring is being roughed in, even if the camera decision comes two years later. What is hardest to add after the fact is the room where all of it is supposed to stand.

Can I record the people who work in my house?

That is a question for a lawyer, not for a contractor, and I say that without dodging. The moment your home is someone’s workplace, rules apply concerning the purposes of the recording, the places it must not cover, the storage period, and telling people in advance. It can be arranged honestly and lawfully, but not by eye. Consult the camera layout while it is still on paper.

How much does CCTV without the cloud cost?

I do not price it per camera, because the cost comes from somewhere else: the number of cable routes, the utility room, the disks and their replacement every few years, the possible encryption, and how far the cut from the network is meant to go. The cloud model shifts part of the cost into a subscription: less at the start, a fee every month for years, and terms set by the provider. The local model is the other way round – more at the start, then mostly electricity and disks. The conversation about specifics starts after the decision which model is in play at all.


This content is educational and stops at the level of decisions and requirements; the execution stays outside the text. The rules on recording people and spaces require legal assessment in each specific situation. Answers to common questions about privacy and discretion are collected in the Questions section.

If you are thinking about a house where privacy is part of the design, this conversation should happen before the installation is designed. Let’s talk about your project.

Back to Insights