Deploying conferencing software into high-security and sovereign environments: What you need to know 

When you’re deploying software into sensitive environments, security and compliance are front-of-mind. This is particularly true if that software is to underpin classified or mission-critical communications. 

These concerns have amplified in recent times. Organizations are worried about possible ramifications of legislation that can allow foreign governments to access data stored in other jurisdictions.  

There’s also some misunderstanding around the factors determining whether a solution can be deployed in a particular customer scenario. Can software from a non-EU vendor be used in sovereign EU environments, for example? (Spoiler alert: yes it can!). 

We’ve answered some of these common questions below, starting with the one about deploying within the EU as a non-EU vendor… 

Yes, absolutely. VQ Conference Manager is widely deployed in government, defense, intelligence, and enterprise worldwide, including in EU sovereign environments. 

This question comes about because some EU-based governments or enterprises discourage or prohibit non-EU-owned cloud services on sovereignty grounds. This is due to legislation such as the US CLOUD Act, which can allow the US government to access information on US-owned cloud platforms, wherever in the world the data is located. 

VQ Conference Manager is for self-hosted and air-gapped environments, where you retain full control over your infrastructure, data, and management layer.  

When you have this level of control, it doesn’t matter where the vendor is headquartered. 

What does matter for EU deployment is the vendor’s approach to security, and compliance with the EU Cyber Resilience Act (CRA). VQ Communications is already in compliance with the CRA reporting obligations – well ahead of the 11th September 2026 deadline for this.The second key date is 11th December 2027, the deadline for full compliance and CE-marking enforcement. We’ll be ensuring full compliance before this date. 

Yes it does. It has been tested by the United States government Joint Interoperability Test Command (JITC), and on the Department of Defense Information Network (DoDIN) Approved Product List*. This independent validation gives our customers all around the world confidence in VQ Conference Manager’s security credentials. 

The software also undergoes regular independent penetration tests, and as set out above, will be undergoing an independent EU CRA conformity assessment. 

* Following the sunset of the APL, discover how we are transitioning to the Vendor STIG program. 

Yes, all our security advisories are available on our website. 

Yes! Our software is built to support organizations who must comply with EU GDPR. There’s tooling to enable you to respond to personally identifiable information (PII) access and right-to-be-forgotten requests. 

Note that because VQ Conference Manager is not software as a service, VQ Communications doesn’t have access to any PII stored within your conferencing platform. We are neither the controller nor the processor of this data. 

Lastly, be aware that for self-hosted or air-gapped solutions, the country in which your software vendors are based does not affect your ability to comply with EU GDPR.   

VQ Conference Manager supports single sign-on (SSO) and multi-factor authentication (MFA) via SAML 2.0 systems. It also supports identity verification via keyboard smartcard/ID card readers.  

User identity and access management (IAM) can be integrated with enterprise IAM systems, such as Active Directory/LDAP.  

This enables VQ Conference Manager to be used in the world’s highest security environments, including across government, defense, and intelligence. 

VQ Conference Manager contains a range of measures to control access to meetings. 

This includes: 

  • Integration with enterprise SSO and MFA systems: Familiar login processes aligned to corporate standards 
  • Role-based access control, linked to LDAP/Active Directory: Determine which meetings, users, Cisco Meeting Servers, and product features people can access 
  • Multi-tenancy: Securely ringfence parts of your organization 
  • One-time, limited-duration meeting spaces, including for recurring calls: Prevent past attendees from joining subsequent sessions, or ‘staying on the line’ after a meeting ends 
  • Customizable meeting PINs/passcodes: Ensure only those with the code can join 
  • Waiting lobbies: Let the host determine who’s allowed in 
  • Host controls: Hosts can remove people from meetings 

Customers can choose the exact meeting security setup they want, thanks to the product’s rich configurability.  

Security and compliance remain at the very heart of our business, embedded within our core value commitment to always do the right thing. Our product and security teams continue to enhance our software, enabling our customers to enjoy cloud-like features within the assurance of a self-hosted or air-gapped environment. 

So if you’re looking to deliver private meetings, secure sovereign conferencing, or replace Cisco TMS, all in an ultra-secure ecosystem where you’re fully in control of every layer, then contact our team for a demo of VQ Conference Manager.  

End of Support Announcement for VQ Conference Manager 3.x

End of Support Announcement for VQ Conference Manager 3.x You might be aware that the operating system that underpins the VQ Conference Manager 3.x platform is called CentOS. The formal end of support for CentOS is 30th June 2024 by the Open Source community that maintains it. What does this mean for VQCM customers? The operating system that underpins the VQ Conference Manager 3.x platform is called CentOS. The formal end of support…

Sovereign Collaboration: The First Line of Modern Defense

Sovereign Collaboration: The First Line of Modern Defense In a world where the navigation system of an aircraft carrying the president of the European Commission can be jammed, forcing the pilot to use paper maps for landing, the importance of sovereign collaboration solutions for defense organisations is clear. Nation-state cyber threats have risen sharply, with 90,000 of the cyberattacks faced by the UK over the past two years believed to be state-linked. Other…

VQ Conference Manager vs Cisco TMS: Key feature comparison 

When we started building what has become the only complete on-premises replacement for TMS that Cisco recommends, our aim was always to do more than replicate TMS’s features. We wanted to give today’s time-poor conferencing administrators and technicians a genuine levelling-up: tools that take away the challenges of managing large-scale Cisco device estates.