Should a custom system run in the client's cloud account or the supplier's?
Our default recommendation for an independent custom system is a cloud account owned by the client, with Wavesteam operating only through delegated, least-privilege access. The final architecture must still follow the project's data, continuity, compliance, cost, and operational constraints. Client ownership of the account does not mean the client must operate it alone.
“Where is it deployed?” combines four separate questions: where compute and storage physically run, who controls the account, who determines use of the data, and who handles security and incidents. These answers need not be the same.
When agreeing deliverables, handover, and ownership boundaries, also compare Can our system still be maintained if the supplier closes or its core team disbands? and Does Wavesteam support on-premises, private-cloud, public-cloud, and hybrid deployment?; the linked guidance adds context that should be considered in the same decision.
| Model | Control and operations | Benefit | Cost or risk | Best fit |
|---|---|---|---|---|
| Supplier-hosted SaaS | Supplier controls platform and most operations | Fast launch, low client workload | Less customization and stronger exit dependency | Common process with acceptable exit terms |
| Client cloud, supplier-operated | Client controls account; provider acts by role | Balances asset control and specialist operations | Client still manages authorization and bills | Default candidate for many custom systems |
| Client premises or dedicated environment | Client controls infrastructure and network | Meets specific isolation or locality constraints | Greater patching, capacity, backup, and upgrade burden | Hard constraint plus operating capability |
| Hybrid | Services and data cross environments | Supports site needs and cloud elasticity | More complex identity, networking, synchronization, and diagnosis | Only when a genuine boundary requires it |
NIST SP 800-145 defines public, private, community, and hybrid cloud deployment models. A private cloud is for exclusive use by one organization and may be managed by that organization, a third party, or both, on or off premises. It is therefore not synonymous with one server in an office and does not automatically satisfy a particular Chinese regulatory duty.
Wavesteam first maps users, payments, device data, files, logs, backups, third parties, retention, and network crossings. From the client's business locations, non-transferable data, offline needs, existing infrastructure, and budget, we derive capacity, response, recovery, and support requirements through environment inspection and representative tests. “Sensitive means on premises” can be the wrong conclusion when no one can patch, monitor, or recover that environment.
Acceptance should prove control and recoverability. The client signs in to the owner account, sees resources and billing, and verifies MFA, least privilege, logs, backups, and alerts. Someone other than the original developer deploys a test environment, rolls back a release, restores a backup, and checks exported records and files. Domain, certificates, repository, app stores, messaging, email, AI-model, and payment accounts also need verified ownership.
Deployment, data rights, intellectual property, and operational responsibility are separate contract topics. Wavesteam's proposal should include the data flow, deployment options, capacity and TCO, responsibility matrix, migration and fallback path, and conditions where our default is unsuitable. The quotation, architecture, permissions, and SLA—not this website statement—control the actual project.