Guide · 9 min read

Cloud vs On-Premise Access Control: Choosing an Architecture for a Commercial Building

For IT directors, property managers, architects and estimators deciding how a new or replacement access control system should be hosted. This guide compares cloud-managed, on-premise and hybrid architectures, the platforms commonly specified for each, what happens when the internet drops, and how the cost picture changes over a ten year life.

Published
September 12, 2026
By
Telelink Business Services
CSLB #472017 · Licensed C-7 contractor Person tapping an access card on a wall-mounted reader

The short answer

In a cloud-managed access control system the door controller stays on site while the credential database and administration console are hosted by the vendor and billed as a per door subscription. In an on-premise system both run on a server the owner controls, under a perpetual license plus an annual support agreement. Controllers on both architectures keep unlocking doors from a cached credential database when the network or the server is unavailable, so the practical difference is who patches the software, who backs up the database, and how the recurring cost appears.

Key points
ArchitecturesCloud-managed, on-premise server, hybrid
Cloud platformsBrivo, Verkada, Avigilon Alta
Hybrid platformUniFi Access, local console with cloud access
Enterprise on-premiseGenetec Synergis, LenelS2 OnGuard and NetBox
MultifamilyButterflyMX video intercom and smart access
Equipment listingUL 294 access control system units
Reader protocolOSDP v2 with Secure Channel preferred over Wiegand

Three architectures: where the controller, database and admin live#

Every access control system has four parts: a reader at the door, a controller that decides whether to unlock, a database of credentials and schedules, and an administration interface. The architecture question is where the last two live.

In a cloud-managed system the controller is on premises, in a telecom room or above the door, and reports to a vendor-hosted service over an outbound internet connection. The database of record and the admin console are in the vendor’s cloud. Nothing on site needs a static IP or an inbound firewall rule.

In a fully on-premise system the database and admin console run on a server the owner controls: a physical server in the MDF, a virtual machine, or an embedded appliance. Controllers talk to that server over the building LAN. Nothing leaves the building unless the owner sets up remote access.

A hybrid system keeps the server and controllers on site and adds a cloud layer for remote administration, mobile credentials or multi-site reporting. Decisions and records stay local; the vendor cloud is a relay for remote login.

The distinction matters less at the door than in the IT department. The reader, door position switch, request-to-exit device, lock power and cabling are the same in all three cases. What changes is who patches the software, who backs up the database, and what the invoice looks like in year six.

Platforms commonly specified for each architecture#

The table lists platforms that appear most often on California Division 28 specifications. Telelink installs and configures ButterflyMX and DoorKing systems and installs the others to the project specification. We claim no certification, authorization or partnership with any manufacturer.

PlatformArchitectureTypical fitNotes on naming
Brivo AccessCloud-managed, controller on premisesMulti-site commercial, property portfoliosReader-agnostic controllers, Wiegand and OSDP
Verkada AccessCloud-managed, controller on premisesOffices, schools, sites with Verkada camerasOwn readers and controllers, per-door license terms
Avigilon Alta AccessCloud-managed, controller on premisesOffices, mobile-first credential programsFormerly Openpath; acquired by Motorola Solutions and rebranded. Older specs still say Openpath
UniFi AccessHybrid: local console, cloud remote accessSmall and mid-size commercial on UniFi networkingRuns on a local UniFi console; no recurring per-door license as of 2026
ButterflyMXCloud-managed intercom and accessMultifamily and senior housing entries, elevators, package roomsProperty-wide subscription; resident app and video intercom
DoorKing (DKS)On-premise controllers, optional cloud managementVehicle gates, telephone entry, parkingLong-standing gate and telephone entry line
Genetec Security Center SynergisOn-premise server, cloud options availableEnterprise, campus, public agency with IT operationsUnified with Genetec Omnicast video
LenelS2 OnGuard and NetBoxOn-premise server or embedded applianceEnterprise, healthcare, governmentOnGuard for large enterprise; NetBox for mid-size

Names change. Openpath became Avigilon Alta, Avigilon’s on-premise line became Avigilon Unity, and several manufacturers sell the same controllers under both a subscription and a perpetual license. Verify the current name and licensing model before pricing.

Licensing: subscription, perpetual, and what each one buys#

Cloud platforms are sold as a subscription, usually per door per year, sometimes per user or per site. It covers hosting, updates, the admin console, mobile credentials on most platforms, and support. Some vendors sell one to ten year terms up front; others bill annually. Stop paying and, after a grace period, the doors keep working on the last downloaded database but administration stops.

On-premise platforms are sold as a perpetual license plus an annual support agreement priced as a percentage of the license. The license does not expire. The support agreement buys upgrades, patches and vendor support, and most owners keep it current because an unsupported server on a corporate network is a liability. Add server hardware, an operating system license, database licensing on larger platforms, and a refresh cycle.

The comparison is a visible annual fee against a set of less visible annual costs. On a ten year view for a 20 door building the two often land in a similar range. The subscription is easier to budget; the perpetual license is easier to defend where a server room and a patching schedule already exist.

What happens when the internet or the server goes down#

Cloud-managed controllers on the platforms above hold a local copy of the credential database and schedules. When the internet fails, the controller keeps reading cards and unlocking doors on the last synced rules, and buffers events until the link returns. Two things do not work during the outage: console changes (a new hire, a revoked badge) do not reach the door until the controller reconnects, and mobile credential modes that route through the cloud may fall back to Bluetooth or stop.

On-premise systems behave the same way when the server goes down: controllers continue on cached rules. The difference is who recovers. On a cloud platform the vendor’s availability is in the contract. On an on-premise platform, server recovery is the owner’s job: backups, a spare, and someone who knows the system.

Two habits cover both cases. Put controllers on a UPS so a power blip does not reboot them mid-day. Set the fail-safe or fail-secure behavior of each lock deliberately; doors in the path of egress must allow free exit at all times regardless of what the software is doing.

Credentials and readers: prox, smart cards, mobile, and OSDP#

The 125 kHz proximity card that most buildings installed in the 1990s and 2000s transmits its number in the clear and can be copied with a handheld cloner. Replacing 125 kHz prox cards removes the easiest attack on the system.

13.56 MHz smart cards (MIFARE DESFire, HID Seos and iCLASS SE are the names you will see) store the credential in an encrypted application and authenticate with the reader before releasing it. Mobile credentials use Bluetooth Low Energy or NFC from a phone and are issued and revoked from the console without printing anything.

Between the reader and the controller there is a second choice. Wiegand is a one-way, unencrypted interface that has been the default for decades. OSDP version 2 with Secure Channel is bidirectional and encrypted, supports reader supervision, and allows firmware updates over the same wires. Specify OSDP for new construction. For a retrofit, an OSDP reader on existing wiring is usually possible.

Regardless of platform, specify UL 294 listed access control equipment, which is what an inspector and an insurer will ask about.

Integrating access control with video and intercom#

The reason to pick a platform is often not the controller but what it connects to. Video association ties a door event to a camera clip so an operator reviewing a forced door sees the person, not just the log entry. Platforms that make both cameras and controllers do this natively; cross-vendor integrations exist through APIs and are worth testing before the specification names them. On any project touching federal funds the camera line must meet Section 889 and 2 CFR 200.216; see our NDAA compliant cameras guide.

Intercom integration lets a visitor call a resident or a front desk and lets that person unlock the door from a phone or a station. In multifamily this is the core of the system: a ButterflyMX lobby panel calls the resident’s phone, the resident sees video and unlocks, and the same platform runs amenity keypads and elevator access. In commercial buildings the intercom is more often a SIP device at a secured entry tied to the phone system. Our intercom and entry systems page covers both.

Elevator control, visitor management and identity provider sync (Microsoft Entra, Okta, Google Workspace) are the next tier. Identity sync is worth pricing on any office project because it deactivates the badge when HR closes the account.

IT security considerations the spec should state#

An access controller is a network device with a web interface and a firmware version. Treat it that way. Require a dedicated VLAN for physical security devices (controllers, IP readers, cameras, intercom panels) segmented from the corporate network, with firewall rules that allow only what the platform needs: outbound HTTPS to the vendor for cloud platforms and nothing inbound; server-to-controller LAN traffic for on-premise.

Require multi-factor authentication on every administrator account, single sign-on where supported, and role-based permissions so a leasing agent who issues fobs cannot change door schedules. Require a firmware update policy: cloud platforms push updates, which the owner should be able to schedule; on-premise platforms leave the owner to apply them, so name who does it. Require audit logging of admin actions, default credentials changed at commissioning, and a closeout package with the IP addressing, VLAN assignments and firewall rules as installed.

These items are routinely missing from Division 28 specifications and get argued at commissioning. Writing it down moves the argument to bid time.

Ten year cost view and a decision table by building type#

The figures below are California commercial planning ranges as of 2026, not quotes. Door hardware, door count and existing pathways move them more than the platform choice. Our access control installation cost guide covers installed cost per opening in detail.

Cost elementCloud-managedOn-premiseNotes
Installed cost per door (reader, controller share, cabling, labor)SimilarSimilarRoughly $2,000 to $6,000 per door before electrified hardware
Electrified door hardwareSameSameDivision 08 or C-28 scope, coordinated, not in the low voltage number
Software, year 1Per-door subscriptionPerpetual license plus first-year supportRoughly $150 to $600 per door per year, about $12 to $50 per door per month, by platform and term
Software, years 2 to 10Same subscriptionAnnual support, often 15 to 20 percent of licensePlus at least one server refresh in ten years
Server, OS, backups, staff timeNone on siteOwner’s costOwner cost, not invoiced by the vendor
Building typeUsual recommendationWhy
Multifamily and affordable housingCloud (ButterflyMX at entries, cloud or hybrid at staff doors)Resident turnover, remote management, no on-site IT
Senior and assisted livingCloud or hybridStaff doors and nurse call coordination; local decisioning is essential
Office, tenant improvement, multi-site businessCloudIdentity sync, mobile credentials, one console across sites
K-12 and higher educationFollows district or campus standardLockdown functions and existing standards outweigh preference
Government and public agencyOften on-premise or hybridIT security policy, data residency, procurement rules
Healthcare and clinicsSmall clinics cloud; hospitals on-premise enterpriseIntegration with existing enterprise systems
Industrial and warehouseCloud with DoorKing gate controlVehicle gates, shift schedules, remote sites

The smaller the on-site IT operation and the more sites in the portfolio, the stronger the case for cloud. The larger the existing security operation and the stricter the data policy, the more on-premise or hybrid fits. If you are still deciding who should install it, our guide on how to choose a low voltage contractor in California covers what to ask.

Next step#

Send us the door schedule, the building type and the platform you are leaning toward, or ask for a recommendation, and request a bid. We will return a per-door scope with the electrified hardware handoff, the network requirements and the licensing model stated plainly. General contractors can find our standard exclusions on the for general contractors page, and the full service description is on our access control systems page.

This article is general information for planning and specification, not a bid, engineering advice or legal advice. Codes and standards change; confirm the current edition with the authority having jurisdiction. Scope and price for a specific building come only in a written proposal.

FAQ

Questions we hear about this

Do doors stop working if the internet goes down on a cloud access control system?

On the platforms commonly specified, no. The door controller holds a local copy of the credential database and schedules and keeps making unlock decisions. What stops is administration: a badge you revoke during the outage is not revoked at the door until the controller reconnects, and events are buffered until then.

Link to this answer
Is cloud access control more expensive than on-premise over the long run?

It depends on door count and whether the on-premise server, patching and staff time are costed in. A per-door subscription is visible on every invoice. An on-premise system carries server hardware, operating system patching, annual software support, backups and staff time. On a ten year view for a building with a few dozen doors the two often land in a similar range, and which one wins turns on whether the server, the patching and the staff hours are costed honestly. At several hundred doors with an existing IT operations team, on-premise can be clearly cheaper.

Link to this answer
Can I keep my existing card readers and cards when moving to a cloud platform?

Often yes for the readers, if they use Wiegand or OSDP and the new controller supports that interface. Whether the cards carry over depends on the credential technology. Older 125 kHz prox cards can usually be read but are easily cloned, so a migration is a good time to move to 13.56 MHz smart cards or mobile credentials.

Link to this answer
Who owns the data on a cloud access control platform?

The contract decides it, and contracts differ. Most vendors treat cardholder records and door events as the customer's data and their own role as hosting it, but the terms that matter are the ones that apply on the day you leave: what export format you get, how long the data survives cancellation, and whether any of it can be loaded into a competing platform. Settle those in writing before a portfolio is standardized on one vendor.

Link to this answer
Does access control count as an alarm system in California?

Cameras and access control are installed under the C-7 classification. Burglar and intrusion alarm systems are a separate scope, and alarm monitoring requires a BSIS Alarm Company Operator license, which is not offered and is referred to a licensed alarm company.

Link to this answer

Question not answered here? Ask a person who does this work.

Call (916) 340-7503Email usOr send drawings to bid
TELELINKBusiness Services

Ready to put this on a real building?

Send over the drawings or describe the scope. We will tell you what we would take on, what we would coordinate out, and what it will take to do it right.