Skip to content

WestPoint · Video software · Milestone XProtect

XProtect is open. That is its virtue and its small print.

It is the VMS with the largest integration catalogue in the sector: almost any camera and almost anything you want to connect has a module. What you have to understand before signing is what «open» means the day something breaks.

What it is, and who it was made for.

Milestone sells software and does not make cameras. That is not a detail: it is the decision everything else comes out of.

With no cameras of its own to place, its interest is that it works with all of them. Hence an enormous device list and a catalogue of third-party add-ons —video analytics, number plates, access control, supermarket tills— that almost nobody else has.

The problem it solves: an installation that has grown in pieces and has cameras from four brands bought in five different years. In a closed system that is a wall; here almost all of them get in and are seen on the same screen.

The trade-off, said now: when something fails you have to work out whose it is. The module belongs to another company, with its own version and its own support. Open means the module exists, not that there is a single telephone number to call.

How it is built.

One server in charge, one or several that record, and loose pieces around them that get forgotten in the sizing.

The management server keeps the configuration in SQL. The recording servers talk to the cameras and write the video. Around them there are more services —events, logging, mobile— and each one consumes: counting only cameras and terabytes leaves you short of memory.

The video goes into its own file store, one folder per device, with a consequence that gets discovered late: the recordings live tied to the server that wrote them. You can move a camera; its history stays where it was, so consolidating three servers into one forces you to keep the old ones switched on or to export.

Recording redundancy exists in the high editions, not in all of them. It is a product boundary and not a configuration one: if the project needs it, it may not be a matter of adding a licence but of changing edition, which is one of the most unpleasant jumps in price.

For several sites there are two routes that always get confused. The federated architecture joins large systems in a hierarchy. Interconnect is for the opposite: small sites with bad links, which record locally and from which the centre brings the video when it asks for it.

What connects, and what it costs.

The integration platform is its main asset. It is also where you learn to ask suppliers uncomfortable questions.

For access control and intruder detection it brings no platform of its own: it integrates yours with a module. There are three questions to ask first: who maintains it, which version of the access control system it has been tested with, and what happens when you update one of the two. «It is compatible» answers none of them.

The SDK is mature and widely used, and that is why the catalogue is large. For anyone who needs the video to appear inside their own plant application it is a genuinely open door, with the usual cost: what you develop you then have to maintain.

On cameras, being on the list means it is seen and it is recorded. The particular functions of each camera arrive or not depending on the specific module, and that is checked with the exact model in front of you, not with the brand.

How it is licensed, and what arrives in year three.

Two layers. The edition, which sets the ceiling: redundancy, federation, interconnect and video wall are edition functions. And the device licences, one per channel: an encoder with four analogue cameras uses four, not one.

On top, the maintenance subscription, which lets you move to new versions. Without it the system keeps recording; the problem is that the cameras you buy in two years need a module that comes in new versions. It means you can no longer buy modern cameras.

And the scenario to see coming: you come in on a mid edition because it is one site, and two years later they open the second one and want redundancy. That means licensing again. It is not the manufacturer taking advantage: it is that the three-year question never got asked.

Who it fits, and who it does not.

Its strength and its weakness are the same thing seen from two sides.

Gets the benefit

Installations with cameras from several brands and several eras. Anyone who does not want to depend on one hardware manufacturer. Anyone who needs to connect the video to something of their own and unusual. And many small sites with bad lines: interconnect is made for that.

Pays over the odds

Anyone with fifty cameras of a single brand, on one site, who is not going to integrate anything. You pay for an openness you will not use and you administer several services instead of one closed box. There the camera manufacturer's own family of equipment comes out simpler, and saying so is part of the job.

The typical miscalculation

Coming in on the minimum edition that covers day one. It signs cheap, it works, and two years later the second site forces a change of edition. We always ask what the installation is going to look like in three years, even when the question is awkward.

What we do.

What we do with any platform, plus the decisions this one in particular forces you to take.

  • The choice of edition, justified in writing against a three-year horizon. It is the most expensive decision to undo and it is taken before the first invoice.
  • The real load calculation: not only terabytes, also memory per server, devices per server, and what happens at the busiest viewing hour, when every operator opens the same thing at once.
  • The recording rules and schedules, which is where you save drive space without losing anything: continuous by day at lower quality and on event by night at full quality. It almost never gets discussed, because what comes as standard already works.
  • The migration: the previous history is not imported, and between XProtects with server consolidation the same warning holds: the recordings do not follow the camera. You either run both side by side or you export, and that time goes into the quotation.
  • The documentation: an inventory with model and firmware, which server records what, a map of the licences, and the list of third-party modules with their version, their supplier and their renewal. That last one is the one nobody has and the one you need on the day of the update.
  • The maintenance, in the right order: check the third-party modules first and update afterwards. The other way round is how you lose the access control integration for two weeks.

Who operates it afterwards.

This platform splits the work well. If it is not split, all of it stays with IT and nobody looks after the security side.

IT is on home ground with the infrastructure, and it has one task that gets forgotten: watching the space and the state of the recording drives, which fill up and wear out on a different pattern from an office server.

Security keeps users and permissions, which camera is seen by whom, recording rules, alarms and —above all— export. Who can take images out, with what authorisation and what gets logged is a data protection decision, not an IT one.

And it has to be handed over for real: a security manager who raises a ticket to add a guard ends up sharing passwords, and that is where the audit trail is lost.

The integrator is left with the version jumps, with the module inventory checked beforehand, the architecture changes, and the borderline faults, which here are most of them: something does not work and it is not clear whether it is the camera, the network or a third party's module.

Training: half a day for the operator on their own views, one long day for the security administrator and a technical session for IT. Plus a half-page script for each repetitive task, which is what actually gets used six months later.

Analytics: what comes with it, and where the limit is.

Here the honest answer starts with what it does NOT bring, because that is precisely its business model.

As standard it brings motion detection, which is geometry: pixels changing inside a rectangle. It is the reason a shift fills up with alerts when it rains.

What sets it apart is not the analytics it brings, it is the analytics you can add: third-party, specialised, sector-specific. If you are after one very particular analytic for one very particular niche, this is where it is most likely to exist.

And the price of that: every analytic added is another manufacturer, another licence, another support contract and another version that has to line up. Three suppliers in the same system is a coordination job, and it normally falls to the integrator.

The real limit, both of the included analytics and of almost all the added ones: it detects events defined in advance. What does not arrive is the understanding of the situation: that somebody is forcing something instead of using it, or that a group is behaving in a way that is not normal there at that hour.

And the declaration, which comes before the recommendation: in the same house there is IRIS Neural, the NVMS from Infinity Neural, the other company in the group. It is our own product, we make it, and so this is not a neutral opinion.

In practice they live together: XProtect governs the cameras, the recording, the permissions and the history; IRIS brings the understanding of the scene. And if what is needed is a rules-based analytic set up properly, that is the right answer, it costs less and we say so.

What IRIS Neural is

If you are comparing.

If you are between this one and a camera manufacturer's platform, the question is not which has more functions: it is how many camera brands you are going to have in five years.

Get started

How many camera brands have you got installed?

It is the question that decides whether this platform fits you, and almost nobody knows the exact answer. Tell us how many cameras there are, of which brands and from which years, how many sites and what lines join them, and we will tell you which edition you need, which licences have to be counted and which modules would have to be checked before promising anything.