WHERE SURVEILLANCE STATION CONSTRAINS

NAS-locked. Per-camera license stacking. No cloud-native VMS.

The licences do not survive the hardware refresh

Camera License Packs are perpetual, which sounds generous until you read what they are bound to. Each one activates against a NAS serial number, so the site that buys fourteen licences today buys them again when it replaces the NAS in five years. Synology stopped publishing a per-camera list price, so an integrator sizing that second purchase is quoting from B&H and CDW catalogues rather than from the vendor.

The storage bottleneck is also the video bottleneck

Surveillance Station is a DSM package and runs nowhere else: not on a third-party NAS, not on commodity Linux, not in Docker outside DSM. So the box handling the file shares, the backups and the RAID rebuild is the same box writing every camera stream. A rebuild after a failed disk competes with the recording for the same spindles.

Remote viewing has no good answer behind CGNAT

DS cam reaches the NAS through QuickConnect, a Synology-hosted relay their own support describes as introducing latency, and r/synology reports 20-30 second waits to open a live view. The documented fix is DDNS plus an inbound port forward. A site on Starlink or mobile broadband cannot do that at all, because CGNAT leaves it no public IP to forward to. A site under PCI, ISO 27001, NIS2 or IRAP will not do it, because default-deny inbound is a baseline control. For both, the slow path is the permanent path.

Compromise the NAS and the evidence goes with it

The 25 Surveillance Station CVEs on cve.org all need an authenticated user, so the application is reasonably hardened. DSM underneath it is the exposure: SynoLocker mass-encrypted DiskStations in 2014, a pre-auth remote-code-execution chain through DSM Photos landed at Pwn2Own 2024, and CVE-2025-13392 broke DSM SSO in May 2026. One copy of the footage, on the machine with the largest attack surface.

The AI appliance line has gone quiet

The DVA1622 and DVA3221 run Deep Video Analytics on the appliance itself and both remain on sale, with no formal end-of-life. New models have stopped arriving: the release cadence slowed through 2024 and 2025 and by September 2025 r/synology was using the word "abandoned". Worth pricing a fallback before a customer commits to DVA at the next refresh.

AT A GLANCE

Synology Surveillance Station and TetherX, question by question

The 10 questions an integrator asks on a site walk, answered for both platforms.

Question Synology Surveillance Station TetherX
What you do with the recorders already on site The Synology NAS is the recorder. Surveillance Station runs only as a DSM package on Synology NAS, FlashStation, RackStation or DVA appliances - never on third-party NAS, commodity Linux or Docker outside DSM. They stay. The TetherBox sits alongside the existing NVRs, DVRs and panels and pulls from them. It runs as software on a server the site already owns, so nobody rips out working kit to start.
What your operators see on one timeline Video only. No access control and no intruder integration. Video, access control, intruder and automation. One operator, one timeline, one dashboard across all four.
Who monitors your alarms No monitoring-station workflow. A monitored site keeps a separate signalling path to the centre. It stays. TetherX signals Immix, Sentinel, CONXTD, MASterMind, Bold Patriot Manitou, Stages, CHeKT and others directly, so the existing ARC, SOC contacts and alarm SLAs carry on.
What you can still do when the Internet drops Recording is local to the NAS, so an outage does not stop it - but the NAS is also the single point of failure for the footage. Keeps recording and keeps working. Recording, doors and alarms run on the TetherBox on the local network, and the console picks up where it left off when the link returns.
What your uplink has to carry Remote viewing goes through the QuickConnect relay, which Synology support describes as introducing latency; field reports put live-view connect times at 20-30 seconds. The vendor fix is DDNS plus inbound port forwarding, which CGNAT and most corporate security baselines rule out. Thumbnails, metadata, and the clips an operator opens or chooses to sync. A thin rural line still records every camera, because recording never leaves the local network.
Where the AI runs Deep Video Analytics on the DVA appliances, where the new-model cadence has slowed noticeably through 2024-2025. At the edge on the TetherBox: person, vehicle and animal detection plus 63-class audio analytics, searchable across multi-site footage in seconds. The platform keeps evolving with additional analytics through the year.
Who you buy it from Retail and IT distribution. There is no first-party integrator console for managing several end-customer estates with per-tenant billing. Your installer, always. TetherX sells through the channel only and does not quote end customers direct, so the integrator keeps the account.
What you actually pay for Free camera slots first: 2 on a standard NAS, 4 on the NVR series, 8 on the DVA. Past those, every camera needs a perpetual Camera License Pack at roughly $45-66, depending on pack size and reseller. Licences bind to the NAS serial and do not transfer cleanly across a hardware refresh. An annual subscription by channel count, from £100/site/year. Not per operator seat, not per analytic, and no concurrent-user cap.
Where your recordings are stored On the NAS. C2 Surveillance is a per-camera-per-year cloud backup overlay at $8.99-$199.99 depending on retention and resolution, not a cloud-native recording layer. On the TetherBox at site by default. Cloud recording is optional per camera, into a UK, EU, US, Canadian, Indian or Australian region the customer picks.
What you keep if you stop paying The perpetual licences keep working, tied to that NAS serial. The exposure is the DSM host itself - compromise the NAS and the recordings go with it. The TetherBox keeps a local interface for live view and recent footage with no Internet and no subscription, so the site is never dark.

Synology Surveillance Station column built from: Synology Surveillance Station, Synology C2 Surveillance pricing, CVE records for Synology Surveillance.

SURVEILLANCE STATION vs TETHERX

NAS-bound bundle vs cloud-native open platform.

Both record from IP cameras. The honest read on where each one wins and where each one costs you something.

Synology Surveillance Station

Strengths

Free DSM add-on - genuinely useful for two cameras on a NAS the customer already owns

Wide ONVIF Profile S / T camera compatibility (Synology claims 8,300+ models on the C2 page, 17,000+ on the en-uk surveillance page)

Mature CMS for the end customer wanting multi-server / multi-site within a single Synology estate

Strong Synology hardware ecosystem - NAS + Surveillance Station + C2 backup all from one vendor

Trade-offs

Every camera past the free slots needs a perpetual licence welded to that NAS serial, and the site buys them again at the next hardware refresh

The NAS hosting the recording is also the largest attack surface on the network, and it holds the only copy

TetherX

Strengths

Open to 1,000+ integrations (ONVIF / RTSP) including the cameras already paired with Surveillance Station

No per-camera license stacking - annual platform subscription priced by channel count through the qualified installer

cloud recording optional per camera, TetherBox for hybrid edge-plus-cloud retention - no NAS bottleneck

First-party integrator / MSP console with per-tenant billing across multiple end customers

ARC integration a la carte (Immix, Sentinel, CONXTD, MASterMind, Bold Patriot Manitou, Stages, CHeKT and others) - the customer picks the monitoring partner, the installer guides the choice

Trade-offs

You have a Synology NAS, two cameras and no plans to add more. Free Surveillance Station is the simpler buy.

Pricing figures, ownership, acquisition dates and product behaviour cited on this page are point-in-time and drawn from public sources - see the disclaimer at the bottom of this page for sourcing, "as of" date, and how to flag corrections.

WHICH ONE FITS

Pick the one your site points at

Find the column that describes the job in front of you.

Choose Synology Surveillance Station if

  • The customer already owns a Synology NAS, wants two or four cameras on it, and has no growth plan
  • Everyone who views the footage is on the local network, so relay latency never bites
  • IT already runs and patches the NAS as part of its normal work
  • A perpetual licence suits the budget better than an annual subscription

Choose TetherX if

  • Camera counts are growing and per-camera licence packs, bound to a NAS serial, will not survive the next hardware refresh
  • The site is behind CGNAT or a security policy that forbids inbound port forwarding, so remote viewing has no good answer
  • You manage several end customers and need one console across all of them
  • Cameras, alarms and doors have to reach one operator, with a monitoring station on the end of it
FAQ

Questions before you switch from Synology Surveillance Station

Because "use the NAS you already bought" stops being the deal somewhere around the fifth camera. The pitch is honest for the free slots, and a great many small sites never need more than those. Search traffic for this page is almost entirely people who did.

The table above sets out what changes past that point, and the pricing question below carries the reseller figures. TetherX takes the opposite shape: the recording layer is not a box you also use for file shares, the licences are not welded to a serial number, and an integrator gets one console across every customer rather than one login per NAS.

Synology Surveillance Station ships with free camera slots that vary by product line: standard NAS = 2 free, NVR-series = 4 free, DVA-series AI NVR = 8 free. Each additional camera requires a perpetual Camera License Pack purchase. Dual-reseller anchors as of June 2026 - B&H Photo: CLP1-E US$54.99 (~US$55/cam), CLP4-E US$204.99 (~US$51/cam), CLP8-E US$359.99 (~US$45/cam); CDW: CLP1 US$65.99, CLP4 US$244.99 (~US$61/cam), CLP8 US$435.99 (~US$54.50/cam). Working per-camera spread is USD around $45-66/cam. Synology no longer publishes a per-camera list price on the vendor product page; the range is only available through reseller catalogues. Licenses are perpetual but bound to the NAS serial and do not transfer cleanly across hardware refresh. TetherX is an annual platform subscription priced by channel count (from £100/site/year) through the qualified installer with no per-camera license stacking and no hardware-bound activation. For a 16-camera site the Synology license stack is roughly US$720-870 perpetual (depending on reseller and pack mix) + the NAS + drives + the Surveillance Station feature ceiling; TetherX is the annual platform fee covering everything in the channel count.

Yes. TetherX runs 1,000+ integrations across ONVIF / RTSP - Axis, Hanwha, Hikvision, Dahua, Bosch, Avigilon, Pelco, Uniview, i-PRO, Mobotix, VIVOTEK, Reolink, Amcrest, plus the ONVIF-compatible IP cameras already wired into the Synology NAS. The migration path is non-destructive: keep the existing camera fleet, point them at a TetherBox or directly at the cloud, and the Synology NAS can be repurposed for backup / file-sync (its strongest use case) while video moves to a platform that was designed cloud-native from the start.

Synology offers C2 Surveillance / C2 Backup for Surveillance as a cloud overlay on top of Surveillance Station. It is a backup product - the NAS is still the recording layer; the cloud holds an off-site copy. Pricing ranges US$8.99 - US$199.99 per camera per year depending on retention and resolution.

TetherX is cloud-native from the start: cloud recording is an optional per-camera service that records directly to the cloud, with optional TetherBox edge-recording for sites with patchy connectivity. The same platform handles single-site, multi-site, multi-tenant - one architecture, not "NAS plus backup overlay".

The product itself is reasonably hardened. A search of cve.org for "Synology Surveillance" returned 25 records (May 2026); all 25 require an authenticated user. The procurement-relevant exposure is the DSM host operating system, not Surveillance Station: Synology DSM has been picked at Pwn2Own for pre-authenticated remote code execution chains in successive years (2024 DSM Photos chain is the most-cited example). If the NAS is compromised, the recordings on it are too.

Historical NAS-level events: SynoLocker (2014) ransomware mass-encrypted DiskStation drives; CVE-2025-13392 (DSM SSO bypass, disclosed May 2026) sat on the DSM host side. None of these are Surveillance Station bugs - they are reasons the recording surface should not be the only copy. TetherX cloud retention is the off-site, off-NAS layer that survives a local DSM compromise. See NDAA Section 889 for the broader compliance ringfence pattern.

Synology ships dedicated DVA-series NVR appliances (DVA1622, DVA3221) with on-device Deep Video Analytics - face recognition, people counting, intrusion detection, advanced object detection. Basic motion detection is free on any NAS; DVA requires the dedicated hardware or a paid DVA module. DVA-series free-camera slots are higher than standard NAS - 8 free slots vs 2. In September 2025 the r/synology community used the word "abandoned" about the DVA NVR product line (KermitFrog647 verbatim). Synology has not formally EOL'd the line and DVA1622 / DVA3221 remain on sale; the underlying signal is a slowed model-release cadence rather than a formal end-of-life. Worth tracking at refresh. TetherX runs AI search in the cloud or on TetherBox - no dedicated AI NVR purchase required, and product-line refresh cadence is on the SaaS side rather than on a hardware appliance the customer has bought.

Out of the box DS cam (the Synology mobile app for Surveillance Station) connects to the NAS through Synology QuickConnect, a vendor-hosted relay service. Synology's own support reply in their community forum is verbatim: "QuickConnect usually involves a relay service that can cause potential latency. On the other hand, port forwarding would build a direct connection between DS cam and Surveillance Station which may be better for latency-concerned environments." Field reports on r/synology describe 20-30 second buffer and connect times on live view through QuickConnect. Synology built the product expecting the customer or installer to set up DDNS plus inbound port forwarding on the router, so DS cam reaches the NAS directly. QuickConnect is meant to be the fallback while that is configured.

The problem is that in many real environments port forwarding is not available - either technically or by policy:

CGNAT. Starlink, mobile broadband, most ISP-managed routers, and many corporate WANs share a single public IPv4 address across many customers (Carrier-Grade NAT). There is no public IP to forward a port to. Verbatim r/synology user: "I cannot figure out how to get DDNS to work because I have Starlink which uses CGNAT and doesn't have an accessible external IP address."

Corporate IT policy. Most managed network environments operating under PCI-DSS, ISO 27001, NIS2, NIST 800-53, IRAP / Essential Eight or equivalent will forbid an inbound port forward on the perimeter firewall as part of "default deny inbound" baseline controls. The integrator can explain QuickConnect is slow until port forwarding is set up; the IT director can equally explain port forwarding is never going to be set up.

Net result: across a meaningful share of real deployments the QuickConnect relay never gets replaced. It is the permanent state, and the 20-30 second buffer is the permanent live-view experience.

TetherX uses an outbound-only connection from the customer site to TetherX cloud (the customer's router initiates the connection, no inbound port needed), which works through CGNAT and inside default-deny corporate firewalls without an exception, and live view does not depend on a vendor relay queue.

The honest comparison set is not just Surveillance Station. The decision typically lands between (a) staying on Synology and absorbing the license stack, (b) moving to a closed-ecosystem cloud like Verkada or Rhombus, (c) moving to an open cloud like Eagle Eye / Brivo or TetherX. Closed ecosystems rip-and-replace the camera fleet. TetherX keeps the existing fleet (the ONVIF cameras already on Surveillance Station included) and gives the integrator the channel margin instead of selling around them. See the best VSaaS providers shortlist for the full open-vs-closed split.

Yes. 30-day free trial through an integrator partner with a TetherBox, full platform access, can run alongside an existing Surveillance Station install for direct comparison. Extensions on request.
COMPANY HISTORY

Synology: Taiwan NAS giant, Surveillance Station as a DSM app

Synology Inc. (群暉科技股份有限公司) was founded in January 2000 in Taiwan by Cheen Liao and Philip Wong, both former Microsoft Taiwan / Microsoft Exchange engineers. First NAS shipped 2004 (DS-101). Headquartered in Far Eastern Telecom Park (Tpark), Banqiao District, New Taipei City. Subsidiaries: Synology America Corp (US), Synology France SARL, Synology GmbH (Germany), Synology UK Ltd. Privately held - revenue passed NT$10B by 2014, estimated NT$4.2B profit 2018 (Commonwealth Magazine via Wikipedia). Approximately 600 staff at Taiwan offices as of 2017; current company-wide headcount undisclosed.

Surveillance Station is the video-surveillance application that ships as a free package inside DSM (DiskStation Manager) - Synology's Linux-based NAS operating system. It does not run on third-party hardware: only Synology NAS / FlashStation / RackStation / DVA NVR appliances. Marketing claim: 13 million+ installations; camera-compatibility claim ranges 8,300 - 17,000 models depending on the page.

Procurement-relevant points: Synology is private, not listed on TPE despite occasional confusion with similarly-named Taiwanese firms, and sits in Taiwan jurisdiction outside the Section 889 covered-entity list. All 25 Surveillance Station CVEs are authenticated, and the DSM host carries the annual Pwn2Own RCE chain risk. The Glassdoor employer profile from May 2026 reads 3.3 / 5 across 314 reviews, with senior management at 2.6, the lowest sub-score in its industry band.

The manufacturer's site is the authoritative source for current product status. The DVA AI NVR product line's future is the open question; the broader NAS + DSM business is healthy.

Free comparison PDF

Not ready to talk? Take the comparison with you.

A one-page open cloud VMS versus locked-platform breakdown: what you keep, what you cut, what it costs. We will email it over, usually the same working day.

Please complete the verification.

No sales call; your details stay with us. We route serious enquiries through accredited local TetherX installers.

Want this at your site?

Get a quote from a certified TetherX installer. We will match you with a local partner who knows your area and your needs.

Certified Installers
Local to You
No Obligation
Prefer to browse partners first? See our partner directory →

Still have questions about license stacking, cloud retention or DVA migration?

Try TetherX free for 30 days

Run TetherX alongside an existing Surveillance Station install. Trial extensions on request.

Start Free Trial

Across the partner network

TetherX partners hold the accreditations security-procurement buyers and insurers filter on. Coverage varies by partner.

NSI 9 ISO 9001 7 SSAIB 5 SafeContractor 5 BAFE 4 CHAS 4 ConstructionLine 4 Cyber Essentials 3 NICEIC 2 ISO 14001 2 ISO 27001 1

Counts reflect partners currently in the TetherX directory holding each accreditation.

Anything wrong on the Synology Surveillance Station comparison?

Flag an inaccuracy, an outdated fact, or a missing nuance on the Synology Surveillance Station page. We update the per-vendor pages and the /compare hub from this inbox - real reply, real human.

Please tell us what to call you.
Please enter your email address.
Please tell us what to fix or add.
Please complete the verification.

We reply within 1 business day. No newsletter, no follow-up sequence.

[1] About this comparison. Information about other vendors is drawn from their public product pages, datasheets, integrator forums (Reddit, vendor user groups), public CVE databases (NVD, CISA), publicly-listed LinkedIn company pages (headcount, headquarters, founding year, leadership transitions and corporate ownership signals) and customer conversations - accurate to the best of our knowledge as of Q2 2026. Pricing, features, security posture and policies change. A vendor may have shipped a fix, dropped a price, added a region or changed an architecture since this page was last reviewed.

If you believe anything here is inaccurate or out of date, please contact us and we will review and correct it. Trademarks and product names belong to their respective owners and are referenced here for identification only.

30 days free. No card. Talk to a local installer.