To choose a VMS, assess ten points: compatibility with the cameras you already own, deployment model (cloud, on-premise or hybrid), AI features, multi-tenancy, white-label, API and webhooks, privacy compliance, pricing model, support and scalability. The decisive test is practical: ask to connect one of your own cameras during the demo — if the vendor cannot, the rest of the conversation does not matter.
If you are still working out what a VMS does, start with the guide What is a VMS? and come back with the vocabulary fresh.
The 10 criteria
1. Camera and protocol compatibility
The biggest hidden cost in a VMS is the hardware it forces you to replace. Platforms that depend on their own cameras, or on a short list of certified brands, turn every expansion into a hardware purchase. Prefer platforms that accept IP cameras, DVRs and NVRs of any brand over open protocols — RTSP and RTMP (see the difference in RTSP, RTMP and P2P). Be wary of "ONVIF support" pitched as a differentiator: ONVIF is a discovery and control standard; the video itself travels over RTSP.
What to ask the vendor: "Do my current cameras, brand by brand, join the platform without replacement? Over which protocol? And cameras behind CGNAT, with no public IP?"
2. Cloud, on-premise — or both
Sites with good internet and few cameras do well in the cloud; sites with many cameras behind a limited link, or with a restrictive data policy, call for local recording. Since most operations have both profiles, platforms that only do one model force an artificial choice. The article On-premise or cloud VMS takes that decision apart dimension by dimension.
What to ask: "Does the platform run cloud and local-server recording at the same time, in the same dashboard? How is each mode priced?"
3. AI: where it runs and what it covers
If the AI runs on the camera, every new feature needs new hardware. If it runs on the server (cloud or local), any compatible camera gains analytics — person, vehicle, object, fire and PPE detection — plus LPR and facial recognition. Check the tuning too: detection zones, sensitivity, trigger conditions and schedules are what stop the AI becoming a false-alarm factory.
What to ask: "Does the AI process on the server or does it require a smart camera? Which analytics exist, and how do I tune zones, sensitivity and schedules per camera?"
4. Real multi-tenancy
For integrators and central stations, multi-tenancy is not "several logins": it is registering isolated accounts, enabling modules per account, grouping cameras and guaranteeing that each user sees only what belongs to them. Without it, the operation becomes a pile of loose accounts.
What to ask: "Can I create isolated accounts, enable modules individually and see the usage of each one? Can one account, under any circumstance, see another account cameras?"
5. White-label
If you resell monitoring, the brand the end customer sees matters. Partial white-label (just the logo) is common; complete white-label covers your own domain, colours, favicon, support contacts, app store links and even the legal terms. See what a complete white-label VMS includes.
What to ask: "Does the end customer sign in on a domain of mine? Do the app, the emails and the terms of use show my brand or the vendor’s?"
6. API and webhooks
A platform without an API is a dead end: data goes in and never comes out. A documented, public API — with token authentication, published limits and endpoints for cameras, recordings and events — lets you wire the VMS into the rest of the operation; webhooks carry real-time alerts to your system. Be sceptical of "we have an API" with no open documentation.
What to ask: "Is the API documentation public? Can I read it before signing? Are there event webhooks with a signature so I can validate the origin?"
7. Privacy and auditing
Video is personal data; plates and faces, more sensitive still. The VMS has to give the customer control over retention, permission-based access, and an audit trail recording who saw what and when — API calls included. Without an audit trail, any privacy incident becomes a question with no answer.
What to ask: "Where do I see the record of who accessed each camera and each plate or face query? Who sets the retention, and what happens to the video when it ends?"
8. Pricing model
Compare structures, not isolated numbers: perpetual license + server + maintenance on one side; per-camera subscription (resolution × retention) + modules on the other. Watch for the costs that show up later — version upgrades, an extra channel, an AI module billed separately per camera. Pro-rated billing by days of use avoids paying a full month for a camera installed on the 25th.
What to ask: "What exactly makes up the monthly fee? What happens when I add or remove cameras mid-cycle? Is there a minimum?"
9. Support and rollout
The rollout reveals the vendor: whoever can connect one of your cameras during the demo itself has a mature product; whoever promises an "integration project" just to show you an image does not. Check the support channel and language too, and the self-service material (knowledge base, tutorials).
What to ask: "Will you connect one of my cameras live during the demo? What is the support response time, and through which channels?"
10. Scalability
Think about the operation three years from now: more sites, more cameras, more customers. In the cloud, growing should be a matter of subscribing to more; on-premise, ask what happens when the server saturates. And scale is not only infrastructure — permissions, groups and per-account billing have to survive the growth without turning into a side spreadsheet.
What to ask: "What changes — in price and in operation — when I double the camera count? And when I have ten times more customers?"
The checklist to take into the meeting
Copy it and tick it off during the conversation with each vendor:
[ ] 1. My current cameras connect without replacement (RTSP/RTMP, CGNAT included)
[ ] 2. Cloud AND on-premise recording on the same platform
[ ] 3. Server-side AI, tuned per camera (zones, sensitivity, schedules)
[ ] 4. Multi-tenancy: isolated accounts, modules and usage per account
[ ] 5. Complete white-label: own domain, brand, contacts and terms
[ ] 6. API with public documentation + signed webhooks
[ ] 7. Privacy: retention under my control + auditing of every access
[ ] 8. Clear pricing: what the monthly fee is made of, and the pro-rata rule
[ ] 9. A demo with one of my own cameras connected live
[ ] 10. A growth plan: cost and operation when the base doubles
With the checklist in hand, the next step is to compare real candidates: run the ten points against each vendor and keep the answers side by side — the gaps usually show up on points 1, 6 and 8.
Want to apply the checklist now? The Xeqmate VMS SaaS page answers all ten criteria one by one — and the free demo covers criterion 9 in practice: we connect one of your cameras live, in about 30 minutes.