Cloud vs On-Premise Access Control: Which Model Fits Your Client?
Essential Security Supplies
For New Zealand security integrators, the choice between cloud and on-premise access control is less about where the software runs and more about how the client manages credentials, handles outages, protects personal information and supports the system over its lifetime. Both architectures can provide professional access control. The right specification depends on the site's operational and security requirements.
What is cloud-based access control?
Cloud-managed access control uses a hosted management platform to administer doors, users, schedules and events. Authorised administrators typically access the platform through a browser or app, subject to the supplier's supported features and permissions. Some systems also support central management of geographically separate buildings.
Important: cloud management does not necessarily mean a door needs a live internet connection for every access decision. Many professional systems hold authorised credentials and access rules in local controllers, allowing doors to continue operating during a WAN outage. Others depend more heavily on connectivity. Verify the exact controller's offline behaviour, event buffering, synchronisation and licence requirements before specifying a system.
A real hardware example is the RBH Integra UNC100 two-door PoE controller. RBH documents the UNC100 family for its Integra32 and Axiom software ranges, but compatibility with a proposed cloud service and offline functions must be confirmed for the exact controller, firmware and subscription.

What is on-premise access control?
On-premise systems host the principal management software and database on a server or workstation under the client's control, usually at the site or within its own IT environment. Local door controllers, readers, door contacts and locking hardware remain part of the architecture. Remote management can be implemented, but its security and network design are the responsibility of the relevant parties.
On-premise should not be confused with standalone access control. A locally hosted enterprise platform can manage multiple buildings and thousands of credentials, while a standalone controller may operate without any central management software.
The RBH UNC-500 two-door TCP/IP controller illustrates networked field hardware used in RBH Axiom installations. A locally managed system still requires planned controller, server and network maintenance rather than simply installing a server and leaving it unattended.

Cloud vs on-premise: practical comparison
| Specification factor | Cloud-managed | On-premise |
|---|---|---|
| Administration | Hosted portal can simplify authorised remote or multi-site access | Client-operated management server, with remote access designed separately |
| Infrastructure | Less central server infrastructure on site, but local controllers and network equipment remain | Server or workstation provisioning, monitoring, updates and recovery are required |
| Ongoing costs | Check per-door, per-site or feature subscription terms and renewal consequences | Check software licences, support contracts, server replacement and maintenance |
| Internet outage | Depends on local-controller autonomy and offline event storage | Local management may remain available if the local network and server are functioning |
| Updates | Provider may maintain the hosted application; integrator still maintains field devices and configurations | Client or service provider schedules server, database and application maintenance |
| Data governance | Check hosting location, access, retention, export and contract terms | Client controls its server environment but remains responsible for security and privacy |
| Integrations | Confirm supported APIs and integration licensing | Confirm compatible versions, network access and ongoing integration maintenance |
Six questions to ask before specifying a platform
1. Who will administer users and doors?
A business with several branches may want one delegated management interface and consistent credential rules. A single secure facility may prefer management within an established IT environment. Confirm whether the client, integrator or managed-service provider will create users, remove departed staff, investigate alarms and approve access changes.
2. What happens when the internet, server or power fails?
Document the required behaviour for each entrance, including cached credentials, time schedules, anti-passback, alarm events and recovery. Test disconnection and restoration as part of commissioning. Specify UPS and network resilience separately from the management model. Fire alarm interfaces, emergency egress and lock failure modes must be assessed for the actual door and building, not assumed from a platform brochure.
3. What is the total cost over five years?
Compare equipment, installation, software licences, subscriptions, maintenance, cyber-security controls, backups and future expansion. Ask what happens to administrator access, stored credentials and event-history exports if a cloud subscription expires or the client changes service providers. For on-premise, budget for supported operating systems, server replacement and a tested restore process.
4. Where are access records stored and who can use them?
Access logs can identify individuals, so the client should define lawful purposes, retention periods, permission levels and procedures for responding to privacy requests. Under New Zealand's Privacy Act 2020, using a cloud service provider does not automatically transfer privacy responsibility away from the client. Overseas hosting is not automatically an overseas disclosure under Information Privacy Principle 12 when a provider processes information solely on the client's behalf; other arrangements may require a separate assessment. Confirm the vendor's actual data-processing terms rather than assuming that cloud or local hosting is inherently compliant.
5. What security responsibilities sit with each party?
For either architecture, require appropriate administrator authentication, least-privilege roles, prompt removal of former staff, supported firmware, secure remote access and documented incident response. Cloud hosting transfers some infrastructure tasks to the provider, but does not remove the client's or integrator's responsibility for configuration, devices, networks and user permissions. On-premise hosting provides direct control over infrastructure but also creates an obligation to maintain it.
6. What integrations are needed now and later?
Confirm actual support for intrusion alarms, CCTV, intercoms, lift control, visitor management and building-management systems. Request supported API documentation and verify whether integrations continue working during a WAN outage. Do not assume a platform offers an integration merely because it is described as open or cloud-ready.
Do not overlook the entrance hardware when comparing management models. The Akuvox A08K keypad access terminal illustrates a real RF card and PIN entry device, but the manufacturer's supported integration and management methods must be checked against the chosen access platform.

Three common NZ project scenarios
Multi-site offices and distributed facilities
Cloud management can reduce the effort of administering multiple locations where internet connectivity is reliable and the client accepts the provider's commercial and data-governance arrangements. Check that each site's controllers retain the required local functions during a WAN outage.
Facilities with strict network or data requirements
On-premise deployment may align with a client's internal hosting, integration or network-segmentation policies. This is a design consideration, not a guarantee of greater security. Document patch ownership, backup recovery, remote-support access and server redundancy.
Sites that need central visibility and local resilience
A hybrid approach may suit projects that require remote administration while preserving essential door operation locally. The distinction is often between where administrators manage the system and where access decisions are executed. Check the exact product architecture, because hybrid capabilities differ by manufacturer.
Installer's commissioning checklist
- Confirm controller and reader compatibility with the selected management platform.
- Record the required offline access and event-buffering behaviour; test it.
- Test power-loss, fire-interface and emergency-egress scenarios appropriate to each door.
- Document administrator roles, MFA options, remote access and credential revocation.
- Confirm data location, retention, export, deletion and support arrangements.
- Record all recurring licence charges and what stops working if a licence lapses.
- Provide the client with an ownership, backup, recovery and maintenance handover.
Cloud vs on-premise access control: FAQs
Will doors still operate if the cloud service or internet fails?
Some professional systems make normal access decisions at local controllers using stored credentials and schedules; other functions, such as remote administration and live reports, may be interrupted. Test the exact system's behaviour for new credentials, revoked credentials, event buffering and recovery before handover. Neither a cloud label nor an on-premise label guarantees continuity.
Can on-premise access control manage several locations?
Yes, many locally hosted platforms support multi-site management, subject to the licensed edition, network design and supported controllers. Compare administrator permissions, secure remote connections and the effort of maintaining infrastructure at each location, rather than assuming multi-site capability belongs only to cloud products.
Does overseas cloud hosting automatically breach New Zealand privacy law?
No. The client's obligations depend on the personal information involved and the provider's role and contract. Under section 11 of the Privacy Act 2020, a provider processing information solely on the client's behalf is treated differently from one using it for its own purposes. Overseas disclosures may raise additional requirements under Information Privacy Principle 12. Review the actual service terms and the Office of the Privacy Commissioner's guidance before choosing a deployment.
Can a client migrate from on-premise to cloud later?
Possibly, but do not assume existing controllers, card formats, software licences or integrations can be transferred unchanged. Ask the manufacturer for a documented migration route, an inventory of supported hardware and a plan for exporting users and event history. Allow for outage testing, training and a controlled changeover.
Explore access control solutions
Essential Security Supplies supports New Zealand security integrators with access control equipment and door hardware. For system fundamentals, read How Does Door Access Control Work?, and for field-device considerations see Door Monitoring: Contacts, REX and Forced-Door Alarms. For platform-specific background, compare RBH Axiom and Integra32 access control. Contact Essential Security Supplies with your door count, site layout, integration requirements and preferred management approach to discuss suitable equipment.
Manufacturer and NZ privacy references
- RBH AxiomCLOUD: manufacturer overview of hosted access management.
- RBH UNC100: manufacturer controller specifications and platform family.
- RBH official technical document library: UNC-500 and Integra32 documentation.
- Akuvox A08K: manufacturer product and model information.
- Office of the Privacy Commissioner: Storing personal information in the cloud.
- Office of the Privacy Commissioner: Sending information overseas.
- Office of the Privacy Commissioner: Working with third-party providers.