Documentation · Deployment

n7kel Vakhta deployment

Requirements for cameras, network, server and user workstations, hosting options and the installation procedure. A document for the client’s IT department, security department and integrator.

Version 1.0, October 11, 2026. This document is for information purposes only, describes a standard delivery and does not constitute an offer. The scope of work and terms are set out in the contract.

1. General provisions

1.1. As a rule, cameras do not need to be replaced: the suitability of each camera is checked during the site survey. A n7kel on-site unit is installed at the site; it works with the site’s IP cameras and continues analysis without any connection to the outside world.

1.2. n7kel AI is trained and tested on ordinary 2D images, so the cameras you already have are suitable. 3D cameras are supported too, if they are already on site or the task requires them.

1.3. The hardware configuration is selected based on the number of cameras on site. Before server hardware is supplied, the configuration is confirmed by a benchmark on the proposed machine; the benchmark takes a few minutes.

1.4. Installation and connection of equipment, software updates and configuration of recognition parameters are performed by n7kel specialists or an authorized partner. Installation at one fuel station takes 1 working day.

1.5. For other n7kel products, requirements are clarified during the site survey: for n7kel Voice, microphones in the service area or cameras with audio; for n7kel Access, readers, turnstiles and security entry airlocks; for n7kel Atlas, a server sized to the volume of connected sources and the retention period. All products run on the client’s equipment, with no foreign cloud services.

2. Hosting options

In both options, raw camera video does not leave the site, and employee face reference templates do not leave the on-site unit. Licensing terms are set out in the Delivery and licensing options document.

ParameterAutonomous optionHybrid option
What is installed on siteOn-site unit and server with dashboard, analytics and archiveOn-site unit: video intake, recognition, event recording
Where the dashboard and archive areOn the client’s hardware, in the client’s local networkServer in a data center in the client’s country; the location is specified in the contract
External connectivityNone; data does not leave the client’s networkOnly an outbound secure connection from the on-site unit to the server; no inbound connections from the internet
Operation without internetNo internet requiredAnalysis continues, and events are sent once the connection is restored: up to 72 hours — normal mode, up to 7 days — restricted mode
UpdatesAs a release file, under annual supportDelivered from the server and installed during a maintenance window
LicenseA file bound to the hardware; term under the contract, including perpetualSubscription; renewed automatically by the server

3. Camera requirements

ParameterRequirement
Camera typeExisting IP cameras with ordinary 2D images. 3D cameras are supported too, if they are already on site or the task requires them.
ProtocolRTSP; HTTP streams (MJPEG, HLS) are also supported. ONVIF-compatible cameras usually provide an RTSP stream.
ResolutionA 720p or 1080p camera substream. Resolution above 1080p does not improve accuracy but increases the load on the hardware.
Frame rateThe camera’s standard stream. The analysis rate is set for each camera; 5 frames per second by default.
AccountA separate camera account with view-only rights. The camera password is not shown in the interface.
Post camera angleFrom the side and above at 30–45°, with people at the post fully visible. A camera pointing straight down is not recommended.
Person size in the frameFor reliable PPE control, a person’s height should be at least 150 pixels; at 100 pixels accuracy decreases; below 48 pixels the camera is unsuitable.
Face identificationAt least 28 pixels between the eyes; the face lit from the front, with no backlight. Used only for employees with written consent.
Camera above the checkoutAbove the cashier’s position; the frame includes the cash drawer, payment terminal, counter and the cashier’s hands, and the cashier’s face for identification.
LightingNo constant glare in the post zone (window, floodlight, reflections). A post with glare is switched to the “undetermined” state without violations.
SuitabilityEvery camera goes through a built-in check with a 0–100 score and recommendations. Cameras scoring below 50 are not used for identification-based events until the causes are eliminated.

4. Network requirements

In the autonomous option, cameras connect to the on-site unit and users connect to the client’s server over HTTPS within the site network; there are no external connections.

From → toProtocolPurpose
On-site unit → camerasRTSP (usually TCP 554)Receiving the video stream within the site; view-only account
On-site unit → server (hybrid option)HTTPS (TCP 443), outbound onlyEvents, frames and event video clips, status information, license renewal, configuration, updates
On-site unit → client’s time serverNTP (UDP 123)Accurate event timestamps and license operation
Users → serverHTTPS (TCP 443)Web interface and the interface for external systems
  • cameras are placed in a separate network segment (VLAN); the on-site unit has two network ports: the camera network and the uplink to the server;
  • the site firewall allows the on-site unit to connect only to the platform server, cameras, DNS and NTP;
  • no access to the on-site unit is opened from the internet;
  • time synchronization is mandatory for the on-site unit and recommended for the tills, for accurate reconciliation;
  • bandwidth within the site: about 2 Mbps per camera at 720p and about 4 Mbps at 1080p; a gigabit network is more than sufficient;
  • external link for the hybrid option: 2–6 Mbps for 10–30 cameras. Transmitting the video streams themselves from 30 cameras would require 60–120 Mbps continuously, which is why video is processed on site.

5. Hardware by number of cameras

The specific graphics card model is selected during the site survey. Estimated values for a 1080p stream and an average of three people in the frame; for servers with a graphics card, this is an estimate confirmed by a benchmark on the proposed machine before delivery. Storage capacity for the autonomous option is calculated for the default retention periods (video clips 30 days, frames 90, events 365); if the periods are extended, capacity is recalculated.

ParameterPilot, 1–2 cameras10 cameras20 cameras30 cameras
PlatformCompact server or workstation (supplied by n7kel)1–2U or tower server1–2U or tower server1–2U or tower server
Processor8 or more cores16 x86-64 cores, 2.4 GHz or higher24 x86-64 cores, 2.4 GHz or higher48 x86-64 cores, 2.4 GHz or higher
Graphics cardIntegrated graphics acceleratorGraphics accelerator with at least 12 GB of memoryGraphics accelerator with at least 12 GB of memoryGraphics accelerator with at least 20 GB of memory
RAM16 GB32 GB32 GB32 GB
SSD, autonomous option512 GB512 GB512 GB1 TB
SSD, hybrid option512 GB512 GB512 GB512 GB
Network ports1 GbE2 × 1 GbE2 × 1 GbE2 × 1 GbE
Camera traffic within the site8 Mbps40 Mbps80 Mbps120 Mbps
External link (hybrid only)2 Mbps2 Mbps4 Mbps6 Mbps
UPS650 VA1000 VA1000 VA1500 VA
  • minimum values for an on-site server: 8 cores, 32 GB RAM, 512 GB storage — even if the calculation gives less;
  • storage: an industrial-grade NVMe SSD; where fault tolerance is required, a mirrored array (RAID 1);
  • UPS runtime of at least 10 minutes with a signal for a clean shutdown; the camera switch and router are connected to the same UPS;
  • when cameras lose power, the platform shows “camera offline” and raises no violations from empty frames; a power outage does not corrupt saved evidence;
  • the equipment is placed in a restricted-access room, as a system that processes personal data.

6. User workstation

ParameterRequirement
ComputerA personal computer with HTTPS access to the platform server
BrowserA current version of Google Chrome or Microsoft Edge
ScreenBrowser window at least 1280 pixels wide
Software installationNot required: the web interface runs in a browser without external resources, including on a closed network

7. Installation procedure

The standard procedure for one site. The scope of work and timelines are set out in the contract and the deployment plan.

  1. Site survey

    Posts, cameras and angles, network, space and power for equipment, POS system. Built-in camera suitability check.

  2. Preparation of the client’s documents

    An internal policy on video analytics, a staff notice (we provide a template), consents to identification — only from those who wish to give them, video surveillance signs. When the corresponding modules are enabled: a notice that audio is recorded (n7kel Voice), a procedure for obtaining and withdrawing patient or customer consent, an agreement with the authorized body (wanted-list checks).

  3. Equipment installation

    On-site unit (and server, in the autonomous option), connection to the camera network, time synchronization, license installation. For a fuel station, 1 working day.

  4. Camera connection

    View-only accounts, stream quality check and suitability score for every camera.

  5. Defining posts and zones

    Post zones, hazardous zones, checkout positions: cash drawer, terminal, counter, customer zone; shifts and PPE requirements.

  6. Reference data and access

    Sites, shifts, employees with consent flags, users and roles, data retention periods, privacy settings.

  7. POS connection

    For the Fuel Station Checkout module: tills and cashier logins, transaction transfer via API or as a CSV/XLSX export. Other client systems are connected under an integration project.

  8. Readiness check and acceptance

    Checklist-based verification and signing of the acceptance certificate.

8. Readiness check

8.1. The following checks are performed before the acceptance certificate is signed:

  • the on-site unit is “online”, the license is “valid”, and the cameras have good stream quality and suitability scores;
  • the dashboard shows posts and the shift; events appear in the event log with a frame and a video clip;
  • the integrity check for the operating period shows no errors;
  • a test disconnection of a camera for 30 seconds: the camera is “offline”, no “unattended post” or “absence” is raised during the outage, and after restoration it is “online”;
  • a check of the on-site unit’s outbound connections: there are no connections to unrelated addresses. The result is attached to the acceptance certificate as the answer to the security department’s question about where the on-site unit connects.

9. What is required from the client

  • camera access: a view-only account;
  • space, power and a UPS for the equipment; in the autonomous option, a server or agreement on its supply;
  • an export of POS transactions or access to the POS API (for the Fuel Station Checkout module);
  • a person responsible for deployment and for reviewing violations;
  • an internal policy and a staff notice; written consents to identification — only from those who wish to give them;
  • when the corresponding modules are enabled: a notice that audio is recorded (n7kel Voice), a procedure for obtaining and withdrawing patient or customer consent, an agreement with the authorized body (wanted-list checks);
  • in the hybrid option, outbound HTTPS to the platform server; the autonomous option needs no internet.

Questions about the documentation

We will answer questions from security, IT, legal and procurement, survey your site and prepare a proposal.