MICKAI®ArticlesCan you replace Microsoft Teams w…
Article · 12 July 2026

Can you replace Microsoft Teams with software that keeps every message, call and meeting on your own infrastructure?

Yes: message, call and meeting collaboration can run entirely on hardware you own, sealed behind a perimeter with no route out.

Author
Micky Irons
Published
12 July 2026
Follow Micky Irons
LinkedInX
microsoft teams alternativeon-premise collaborationdata residencysovereign intelligence operating systemzero-egress
Can you replace Microsoft Teams with software that keeps every message, call and meeting on your own infrastructure?

Yes. Every message, voice call and video meeting can stay on hardware you own, sealed inside a perimeter you control, when collaboration is delivered as part of a Sovereign Intelligence Operating System rather than a hosted service. Mickai is such a system, and our collaboration capability, Convene, replaces the working core of Microsoft Teams: group chat, direct messages, voice, video meetings and shared files, all held on operator-owned infrastructure. This is possible because the system is built to run offline, so there is no default route off the box for a conversation to take.

This question matters in 2026 because the mainstream collaboration suites are, by design, hosted services. Their convenience depends on messages and recordings leaving your estate for a provider's cloud. For a bank, a hospital, a government department or a defence supplier, that movement is the precise act a data-residency rule exists to prevent. The location of a message has become a compliance fact rather than a preference.

How does an on-premise replacement for Teams actually work?

Convene runs on servers and endpoints inside your own estate. Chat, presence, voice and video are handled locally, and files stay on local storage. The assistant that summarises a meeting or drafts a reply runs on sovereign models held on the same hardware, never a public endpoint. No part of a conversation is sent to a public AI service, because a regulated operator cannot compliantly route restricted data to one. Where the assistant makes a judgement, it uses cross-model consensus: more than one local model checks the same output before it is shown, so a single model's error is caught inside the building. The design is documented in 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD, all patent pending.

How does the perimeter stop a call leaving the building?

The system runs behind a zero-egress inbound perimeter. Traffic can be accepted from your own users and devices, but the system opens no outbound path of its own: no telemetry, no cloud sync, no vendor phone-home. There is nothing to disable and no policy to trust, because the egress route is absent by construction. A meeting recording written to local storage has no channel to a third party. This is the difference between a hosted suite that promises regional data storage and a system that has no way to send data out at all.

When collaboration runs on hardware you own, the location of every message stops being a clause in a contract and becomes a fact you can verify.

What can an auditor actually check?

Every action is cryptographically sealed into an append-only audit ledger. Sending a message, joining a call, sharing a file and generating a summary each write a signed entry. The ledger is signed with post-quantum digital signatures: FIPS 204, ML-DSA, is the primary standard, with FIPS 205, SLH-DSA, available as a hash-based alternative. Because those signatures verify offline, an auditor can confirm that the record has not been altered without contacting any vendor and without a network connection. The test is simple: take the ledger to an air-gapped machine and check the signatures. If they hold, the history is intact.

Which rules make sovereign collaboration necessary?

Several 2026 regimes push in the same direction. DORA, in force across the EU financial sector since January 2025, holds firms responsible for the resilience and control of their operational systems, including where those systems run. NIS2 extends network and information security duties to a wide set of essential and important entities. GDPR governs where personal data may reside and who may reach it. The US CLOUD Act is the reason foreign-hosted data is exposed to foreign legal process, which is exactly what a sovereign deployment removes. ISO/IEC 42001 sets a management standard for the AI now embedded in collaboration suites. On the EU AI Act, the high-risk obligations under Annex III, once due on 2 August 2026, were deferred by the Digital Omnibus to 2 December 2027, with embedded high-risk systems under Annex I moving to 2 August 2028 and the Article 50 transparency duties largely unchanged.

How is identity handled, and who can join a call?

Identity is hardware-attested. A device proves what it is before its user is admitted, and that attested identity is bound into the same audit chain that records the conversation. A participant is not a username and a password that could be replayed from anywhere: they are a known device and a known person, tied to a signed record of what they did. This closes the common weakness of cloud collaboration, where a leaked credential grants access from any browser on earth. In a sealed deployment, there is no browser on earth that can reach in.

What are the honest limits of a like-for-like migration?

Sovereignty has a cost, and stating it plainly matters. A sealed deployment does not federate with external Microsoft Teams tenants, because federation is an egress path. Organisations that must speak with outside parties keep a separate, clearly bounded channel for that, rather than pretending the sealed system does both. You also own the operational burden a cloud provider otherwise carries: capacity, updates and resilience run on your team. The trade is deliberate. You give up frictionless public federation and gain a collaboration estate whose every message, call and meeting you can prove never left your control.

Frequently asked questions

Can Microsoft Teams itself be configured to keep all data on-premise?

Not fully. Teams is a hosted service, so its calling, meeting and messaging backends run in Microsoft's cloud, and even on-premises adjuncts still depend on cloud services for core functions. Regional data storage commitments control where data sits, but not whether it leaves your estate. A truly on-premise replacement has to be built as a self-contained system rather than a cloud client.

What is a zero-egress perimeter in plain terms?

It is a network design where the system accepts connections from your own users but opens no outbound connection of its own. There is no telemetry, no cloud synchronisation and no vendor callback. Data cannot leave because there is no route out, rather than because a policy is asked to block one. That absence is what makes the guarantee checkable.

How can we prove to a regulator that a message never left our infrastructure?

Through the signed audit ledger. Every action writes a post-quantum signed entry, and those signatures verify offline using FIPS 204. A regulator or auditor can take the ledger to an isolated machine and confirm the record is complete and unaltered without trusting any vendor. Combined with the zero-egress perimeter, that gives a demonstrable boundary rather than an asserted one.

Does an offline system still give meeting summaries and AI assistance?

Yes. The assistant runs on sovereign models held on your own hardware, so summaries, action points and drafting work locally. Because it uses cross-model consensus, more than one local model checks important outputs before they are shown. No transcript or recording is sent to a public AI service to obtain these features.

Which regulations most often drive this requirement?

For financial firms, DORA and its focus on operational control. Across critical sectors, NIS2. For personal data everywhere, GDPR, with the US CLOUD Act explaining why foreign-hosted data is exposed to foreign legal process. ISO/IEC 42001 increasingly frames the AI components. Together they turn data residency from a preference into an obligation.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/convene-sovereign-teams-alternative-on-premise. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
18 Aug 2026
How Telecoms Operators Meet the Telecommunications Security Act With AI That Never Leaves the Network
Telecoms operators meet the Telecommunications Security Act code of practice with AI that runs inside the security-critical boundary on operator-owned hardware. A zero-egress perimeter keeps network configuration and signalling data within operator control, so nothing sensitive crosses out to a public cloud service.
18 Aug 2026
Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?
Yes. Energy operators can run forecasting and anomaly detection on grid and OT data entirely on their own hardware, and this satisfies the Cyber Assessment Framework more cleanly than cloud analytics, because telemetry never leaves the audited perimeter and no third-party processor exists to assess.
18 Aug 2026
How Airports Meet EASA Part-IS from February 2026 with On-Site AI
Part-IS applies to aerodrome operators from 22 February 2026 and makes the airport, not its vendor, accountable for information-security risk. Running AI on operator-owned hardware behind a zero-egress perimeter keeps passenger and operational data inside that boundary, so a supplier's SOC 2 cannot discharge it.
18 Aug 2026
Can Automotive Suppliers Use AI on OEM Design Data While Keeping TISAX Prototype Protection?
Automotive suppliers can run AI on OEM design and prototype data and keep TISAX prototype protection, but only when the model runs on their own hardware inside the protected zone. Public cloud AI transmits the data outward, which prototype protection forbids.