How do local and cloud sleep scoring differ?
| Question | Local (on-premise) | Cloud service |
|---|---|---|
| Where are recordings processed? | On a workstation you control | On the vendor's servers |
| Must recordings leave the building for analysis? | No | Yes, they are uploaded |
| Internet needed to analyse a study? | Not for the analysis itself | Yes |
| Who secures the computer and storage? | Your organisation (access, disk encryption, backups) | Mostly the vendor, under your agreement with them |
| Who applies software updates? | Your team, usually with the provider | The vendor |
| Main contractual question | Licensing and support terms | Data processing, storage location and retention |
Neither model is automatically safer. Local processing removes the upload, but the workstation still needs proper access control, encryption, backups and updates. A cloud service shifts much of that work to the vendor, but your data then sits under their controls and your contract with them.
When does local processing make sense?
- Your policies restrict sending identifiable recordings to external services.
- Internet access at the scoring workstation is limited or unreliable.
- You want staging to work the same way regardless of a vendor's servers.
- Your IT team can own workstation security, backups and updates.
What should you ask any sleep-scoring vendor?
- Where exactly is each recording processed and stored, and for how long?
- Does any data leave the workstation, including logs, telemetry or crash reports?
- Who can access recordings and results, and how is that access controlled?
- How are backups made and restores tested?
- What is the software's validation and regulatory status for your jurisdiction?
- Who supports the system, and under what written terms?
How InEpoch handles study data
InEpoch's application runs locally. Studies and results are stored in a local data folder, staging runs on the workstation's CPU, and the application's internal server accepts connections only from the same computer, so no cloud upload is required for analysis. Access, disk encryption, backups and any authorised support arrangements are configured with your organisation during deployment. See Local by design.