Documentation · Deployment
n7kel Vakhta deployment
Requirements for cameras, network, server and user workstations, hosting options and the installation procedure. A document for the client’s IT department, security department and integrator.
On this page
Version 1.0, October 11, 2026. This document is for information purposes only, describes a standard delivery and does not constitute an offer. The scope of work and terms are set out in the contract.
1. General provisions
1.1. As a rule, cameras do not need to be replaced: the suitability of each camera is checked during the site survey. A n7kel on-site unit is installed at the site; it works with the site’s IP cameras and continues analysis without any connection to the outside world.
1.2. n7kel AI is trained and tested on ordinary 2D images, so the cameras you already have are suitable. 3D cameras are supported too, if they are already on site or the task requires them.
1.3. The hardware configuration is selected based on the number of cameras on site. Before server hardware is supplied, the configuration is confirmed by a benchmark on the proposed machine; the benchmark takes a few minutes.
1.4. Installation and connection of equipment, software updates and configuration of recognition parameters are performed by n7kel specialists or an authorized partner. Installation at one fuel station takes 1 working day.
1.5. For other n7kel products, requirements are clarified during the site survey: for n7kel Voice, microphones in the service area or cameras with audio; for n7kel Access, readers, turnstiles and security entry airlocks; for n7kel Atlas, a server sized to the volume of connected sources and the retention period. All products run on the client’s equipment, with no foreign cloud services.
2. Hosting options
In both options, raw camera video does not leave the site, and employee face reference templates do not leave the on-site unit. Licensing terms are set out in the Delivery and licensing options document.
| Parameter | Autonomous option | Hybrid option |
|---|---|---|
| What is installed on site | On-site unit and server with dashboard, analytics and archive | On-site unit: video intake, recognition, event recording |
| Where the dashboard and archive are | On the client’s hardware, in the client’s local network | Server in a data center in the client’s country; the location is specified in the contract |
| External connectivity | None; data does not leave the client’s network | Only an outbound secure connection from the on-site unit to the server; no inbound connections from the internet |
| Operation without internet | No internet required | Analysis continues, and events are sent once the connection is restored: up to 72 hours — normal mode, up to 7 days — restricted mode |
| Updates | As a release file, under annual support | Delivered from the server and installed during a maintenance window |
| License | A file bound to the hardware; term under the contract, including perpetual | Subscription; renewed automatically by the server |
3. Camera requirements
| Parameter | Requirement |
|---|---|
| Camera type | Existing IP cameras with ordinary 2D images. 3D cameras are supported too, if they are already on site or the task requires them. |
| Protocol | RTSP; HTTP streams (MJPEG, HLS) are also supported. ONVIF-compatible cameras usually provide an RTSP stream. |
| Resolution | A 720p or 1080p camera substream. Resolution above 1080p does not improve accuracy but increases the load on the hardware. |
| Frame rate | The camera’s standard stream. The analysis rate is set for each camera; 5 frames per second by default. |
| Account | A separate camera account with view-only rights. The camera password is not shown in the interface. |
| Post camera angle | From the side and above at 30–45°, with people at the post fully visible. A camera pointing straight down is not recommended. |
| Person size in the frame | For reliable PPE control, a person’s height should be at least 150 pixels; at 100 pixels accuracy decreases; below 48 pixels the camera is unsuitable. |
| Face identification | At least 28 pixels between the eyes; the face lit from the front, with no backlight. Used only for employees with written consent. |
| Camera above the checkout | Above the cashier’s position; the frame includes the cash drawer, payment terminal, counter and the cashier’s hands, and the cashier’s face for identification. |
| Lighting | No constant glare in the post zone (window, floodlight, reflections). A post with glare is switched to the “undetermined” state without violations. |
| Suitability | Every camera goes through a built-in check with a 0–100 score and recommendations. Cameras scoring below 50 are not used for identification-based events until the causes are eliminated. |
4. Network requirements
In the autonomous option, cameras connect to the on-site unit and users connect to the client’s server over HTTPS within the site network; there are no external connections.
| From → to | Protocol | Purpose |
|---|---|---|
| On-site unit → cameras | RTSP (usually TCP 554) | Receiving the video stream within the site; view-only account |
| On-site unit → server (hybrid option) | HTTPS (TCP 443), outbound only | Events, frames and event video clips, status information, license renewal, configuration, updates |
| On-site unit → client’s time server | NTP (UDP 123) | Accurate event timestamps and license operation |
| Users → server | HTTPS (TCP 443) | Web interface and the interface for external systems |
- cameras are placed in a separate network segment (VLAN); the on-site unit has two network ports: the camera network and the uplink to the server;
- the site firewall allows the on-site unit to connect only to the platform server, cameras, DNS and NTP;
- no access to the on-site unit is opened from the internet;
- time synchronization is mandatory for the on-site unit and recommended for the tills, for accurate reconciliation;
- bandwidth within the site: about 2 Mbps per camera at 720p and about 4 Mbps at 1080p; a gigabit network is more than sufficient;
- external link for the hybrid option: 2–6 Mbps for 10–30 cameras. Transmitting the video streams themselves from 30 cameras would require 60–120 Mbps continuously, which is why video is processed on site.
5. Hardware by number of cameras
The specific graphics card model is selected during the site survey. Estimated values for a 1080p stream and an average of three people in the frame; for servers with a graphics card, this is an estimate confirmed by a benchmark on the proposed machine before delivery. Storage capacity for the autonomous option is calculated for the default retention periods (video clips 30 days, frames 90, events 365); if the periods are extended, capacity is recalculated.
| Parameter | Pilot, 1–2 cameras | 10 cameras | 20 cameras | 30 cameras |
|---|---|---|---|---|
| Platform | Compact server or workstation (supplied by n7kel) | 1–2U or tower server | 1–2U or tower server | 1–2U or tower server |
| Processor | 8 or more cores | 16 x86-64 cores, 2.4 GHz or higher | 24 x86-64 cores, 2.4 GHz or higher | 48 x86-64 cores, 2.4 GHz or higher |
| Graphics card | Integrated graphics accelerator | Graphics accelerator with at least 12 GB of memory | Graphics accelerator with at least 12 GB of memory | Graphics accelerator with at least 20 GB of memory |
| RAM | 16 GB | 32 GB | 32 GB | 32 GB |
| SSD, autonomous option | 512 GB | 512 GB | 512 GB | 1 TB |
| SSD, hybrid option | 512 GB | 512 GB | 512 GB | 512 GB |
| Network ports | 1 GbE | 2 × 1 GbE | 2 × 1 GbE | 2 × 1 GbE |
| Camera traffic within the site | 8 Mbps | 40 Mbps | 80 Mbps | 120 Mbps |
| External link (hybrid only) | 2 Mbps | 2 Mbps | 4 Mbps | 6 Mbps |
| UPS | 650 VA | 1000 VA | 1000 VA | 1500 VA |
- minimum values for an on-site server: 8 cores, 32 GB RAM, 512 GB storage — even if the calculation gives less;
- storage: an industrial-grade NVMe SSD; where fault tolerance is required, a mirrored array (RAID 1);
- UPS runtime of at least 10 minutes with a signal for a clean shutdown; the camera switch and router are connected to the same UPS;
- when cameras lose power, the platform shows “camera offline” and raises no violations from empty frames; a power outage does not corrupt saved evidence;
- the equipment is placed in a restricted-access room, as a system that processes personal data.
6. User workstation
| Parameter | Requirement |
|---|---|
| Computer | A personal computer with HTTPS access to the platform server |
| Browser | A current version of Google Chrome or Microsoft Edge |
| Screen | Browser window at least 1280 pixels wide |
| Software installation | Not required: the web interface runs in a browser without external resources, including on a closed network |
7. Installation procedure
The standard procedure for one site. The scope of work and timelines are set out in the contract and the deployment plan.
Site survey
Posts, cameras and angles, network, space and power for equipment, POS system. Built-in camera suitability check.
Preparation of the client’s documents
An internal policy on video analytics, a staff notice (we provide a template), consents to identification — only from those who wish to give them, video surveillance signs. When the corresponding modules are enabled: a notice that audio is recorded (n7kel Voice), a procedure for obtaining and withdrawing patient or customer consent, an agreement with the authorized body (wanted-list checks).
Equipment installation
On-site unit (and server, in the autonomous option), connection to the camera network, time synchronization, license installation. For a fuel station, 1 working day.
Camera connection
View-only accounts, stream quality check and suitability score for every camera.
Defining posts and zones
Post zones, hazardous zones, checkout positions: cash drawer, terminal, counter, customer zone; shifts and PPE requirements.
Reference data and access
Sites, shifts, employees with consent flags, users and roles, data retention periods, privacy settings.
POS connection
For the Fuel Station Checkout module: tills and cashier logins, transaction transfer via API or as a CSV/XLSX export. Other client systems are connected under an integration project.
Readiness check and acceptance
Checklist-based verification and signing of the acceptance certificate.
8. Readiness check
8.1. The following checks are performed before the acceptance certificate is signed:
- the on-site unit is “online”, the license is “valid”, and the cameras have good stream quality and suitability scores;
- the dashboard shows posts and the shift; events appear in the event log with a frame and a video clip;
- the integrity check for the operating period shows no errors;
- a test disconnection of a camera for 30 seconds: the camera is “offline”, no “unattended post” or “absence” is raised during the outage, and after restoration it is “online”;
- a check of the on-site unit’s outbound connections: there are no connections to unrelated addresses. The result is attached to the acceptance certificate as the answer to the security department’s question about where the on-site unit connects.
9. What is required from the client
- camera access: a view-only account;
- space, power and a UPS for the equipment; in the autonomous option, a server or agreement on its supply;
- an export of POS transactions or access to the POS API (for the Fuel Station Checkout module);
- a person responsible for deployment and for reviewing violations;
- an internal policy and a staff notice; written consents to identification — only from those who wish to give them;
- when the corresponding modules are enabled: a notice that audio is recorded (n7kel Voice), a procedure for obtaining and withdrawing patient or customer consent, an agreement with the authorized body (wanted-list checks);
- in the hybrid option, outbound HTTPS to the platform server; the autonomous option needs no internet.
Questions about the documentation
We will answer questions from security, IT, legal and procurement, survey your site and prepare a proposal.