Some organisations cannot put voice on somebody else's servers, whatever the encryption. push.tt is built to be deployed as ordinary software on an ordinary Linux box — which is most of the way to a self-hosted product, and honestly short of all of it.
It was not designed for on-premise as a feature. It is possible because of decisions taken for other reasons, and those decisions happen to leave nothing cloud-shaped in the stack at all.
For an organisation with a data-residency rule or an air-gapped network, the meaningful property is that there is nothing to phone home to.
The gap between "the software runs on your box" and "you can buy this" is real, and it is the part we have not built.
If you need this, say so — it moves up the list based on who is actually asking. What we will not do is take an order for it today and work out the rest afterwards.
For most organisations asking about on-premise, the actual requirement is "our provider must not be able to read this". That one is already met, today, without any of the above.
Residency, air-gap, procurement policy or a security review — the answer differs for each, and for some of them we already have one.