Why Waaban
On-premises or cloud: which is right for your tribe?
Cloud software is quicker to rent, but the data lives on a company's servers. On-premises software runs on your own computers, so you own it, control it, and keep the data in the building. For a sovereign government, that control is the point.
On your computers · works with the internet unplugged
The cloud is convenient: someone else runs the server, and you start fast. The trade is that your records sit with an outside company, you pay per person every month, and you depend on a vendor you cannot fully control.
On-premises keeps the records where you can see them, works with the internet unplugged, and is bought once instead of rented forever.
The question underneath the question
Every other question about government software resolves into this one. Where the records physically sit decides who can read them, whose law governs them, what happens when the connection drops, what you pay in year five, and what you keep if the relationship ends.
The Indigenous data sovereignty framing is exact here: mainstream data practice holds that data is subject to the laws of the nation in which it is stored. A tribe that stores its records on another government's soil, in another company's building, has quietly accepted that principle. A tribe that stores its records in its own building has not.
The same decision, from each seat
Tribal IT
You stay the owner of the deployment.
It installs on machines you already run, on your own network. You hold the encryption keys and the backup drive. There is no outside administrator with standing access to your records, and no vendor console you cannot see inside of.
Council
It answers to the tribe.
The records stay in the building, under your law, on hardware the tribe owns. If a company changes its pricing, its terms, or its owner, none of that reaches your records, because none of your records are in its custody.
Staff
It works on the days you least control.
An outage, a storm, or a cut line stops cloud software cold. Your office finishes the docket, because the software and the records are on the machine in front of you.
The five questions that settle it
- Where is the database, physically? Ask for the building, not the brand. A straight answer is a good sign.
- Whose law governs the servers? Records held off the reservation sit under someone else's jurisdiction.
- Who can read the records besides us? Administrators, support staff, and subprocessors all count.
- What happens with the internet down? Ask them to demonstrate it, unplugged, in the room.
- If we leave, what do we walk out with? The answer should be everything, in a format you can open.
Ask the last question first. A vendor whose answer to it is complicated has told you what you needed to know about the other four.
What a records system has to survive
The choice is not only about a normal Tuesday. It is about the audit, the grant closeout, the records request, and the year a machine dies. Federal rules already set the floor for how long records live and how they are handled, and they apply to your records wherever those records happen to sit.
| What you have to survive | The rule | What on-premises gives you |
|---|---|---|
| Grant record retention | Federal award records are kept three years from submission of the final financial report, and longer if litigation or an audit is open (2 CFR 200.334) | The complete sealed history is on your hardware for as long as you keep it, with no export project and no vendor request |
| Self-determination contracts | Under ISDEAA, financial records run three years from submission of the single audit report, and property records three years from disposition (25 CFR 900.41) | One record system carries both clocks, because the record and its history are the same object |
| Criminal justice information | Where a justice system handles CJI, the FBI CJIS Security Policy requires validated encryption and controlled access | Encrypted at rest on hardware inside your physically secure location, with access set by role |
| A machine failure | No rule, just Tuesday | Restore the encrypted backup you hold onto another machine and keep working |
The obligations follow the record, not the vendor. Owning the record is the simplest way to satisfy them.
Questions tribes ask about this choice
- Is on-premises harder for a small IT department to run?
- It installs as an ordinary app and starts on a single office machine. There is no data center to build and no fleet minimum. The work it adds is a backup drive you already know how to handle, and it removes the work of managing accounts with an outside company.
- What if we already have records in a cloud system?
- You import what exists today, from spreadsheets and from older systems, and the imported records enter the same sealed history as everything after them. Your old records stop being a separate problem.
- Does on-premises mean we are on our own?
- You own the deployment, and we stand it up with your staff so your IT can run it. The difference is that the knowledge and the keys end up with you rather than with a company you have to call.
Sources
- 2 CFR 200.334, Record retention requirements · Cornell Legal Information Institute. law.cornell.edu
- 25 CFR 900.41, How long must the contractor keep management standards records · Cornell Legal Information Institute. law.cornell.edu
- CJIS Security Policy, Version 6.0 (December 27, 2024) · Federal Bureau of Investigation. le.fbi.gov
- About Indigenous data sovereignty · US Indigenous Data Sovereignty Network. usindigenousdatanetwork.org