Cloud or self-hosted? Choosing the right architecture for your intercom system
Only a few years ago, intercoms and access control lived in separate worlds. One was installed “for residents”, the other “for security”. Today the entry panel sits on the same door as the reader, releases the same lock and writes events to the same log. That means it is held to the same standards as the rest of the access control infrastructure: compatibility, a clear model for storing data, cybersecurity, and the ability to evolve without replacing every piece of hardware.
Recent market data backs this up. Mercury Security (an HID brand) surveyed 561 physical security and cybersecurity professionals for its 2026 Trends in Access Controllers Report. The findings:
- 69% consider interoperability a critical factor when choosing equipment;
- 82% say backward and forward compatibility is important for infrastructure planning;
- cloud connectivity influences purchasing for 56% of respondents (up from 50% a year earlier), yet only 41% actually have cloud-enabled controllers;
- 32% say their current systems lack cybersecurity features (up from 21% in 2025).
The report focuses on controllers, but the trend is broader. When choosing equipment, buyers are looking beyond today’s features to long-term compatibility, cloud connectivity and cybersecurity. For intercoms, all of this comes down to one architectural question: where should the management system run, in the cloud or on your own server, and what difference does it make?
1. Two options: Link Cloud and Link Selfhost
The BAS-IP Link management platform is available in two deployment models: Link Cloud, the cloud-hosted version, and Link Selfhost, which runs on the customer’s own infrastructure. Both are built on the same Link platform, and updates are released for both at the same time, typically around once a week.
Link Cloud is a good fit if:
- the property management company has no in-house IT team or server room;
- you need to go live quickly without buying infrastructure;
- you manage many sites spread across different locations;
- residents need remote access through a mobile app out of the box.
Link Cloud is licensed per apartment. A Basic or Plus plan is assigned to each individual apartment, so a single project can combine apartments on different plans. For more on costs, see our article on cloud subscriptions.
Link Selfhost is a good fit if:
- the customer’s corporate, government or industry requirements do not allow data to be held by a third party;
- the site has its own IT department and information security policies;
- you need to manage data retention periods yourself;
- you need deep integration with the customer’s internal systems.
With Link Selfhost, the main database sits on the customer’s infrastructure. Any exchange with external services depends on the features in use and how the project is configured.
Link Selfhost is available in several licensing packages. Core device and access management features are available without a paid licence. Additional capabilities, including built-in telephony, mobile features and advanced integration tools, depend on the package and the market. It is best to confirm the current package contents for each specific project.
Link Selfhost is delivered as Docker images. Updates can be installed manually or deployed automatically. Minimum server requirements and installation instructions are available in the public documentation. Server sizing depends more on event volume than on the number of apartments: a busy staff entrance generates far more log entries than a residential block with ten doors.
At a glance
| Criterion | Link Cloud | Link Selfhost |
| Where data is stored | One of three server regions: Europe, United States, Asia | Main database on the customer’s infrastructure |
| Who maintains the infrastructure | BAS-IP | Customer’s IT team or the integrator |
| Time to launch | Fast, no servers to buy | Server deployment required |
| Pricing model | Per-apartment subscription (Basic or Plus) | Core features without a paid licence, extended features by package |
| Log retention | One month | Set by the server owner |
| Software updates | Handled by BAS-IP | Docker images, manual or automatic |
| Operation during a temporary loss of internet connection | Local functions continue, see section 2 | Local functions continue, see section 2 |
2. What happens if the connection to the server is lost
This is usually the first question integrators ask, and rightly so.
In the standard configuration, a BAS-IP entry panel works as a standalone device. The Link server distributes credentials and settings to it and collects its logs, but the panel makes the access decision itself. So once credentials and access rules have been synchronised to the devices, the core local functions keep working even if the connection to Link is lost. Functions that need the server or the internet are unavailable until the connection is restored.
| Function | When the server connection is lost |
| Call from entry panel to the apartment monitor | Works |
| Door release from the monitor | Works |
| Entry with already synchronised cards, PIN codes, face recognition and UKEY | Works locally, if the panel makes the decision (standard configuration) |
| Mode in which the server makes the access decision (server-side admission) | Requires a connection to the server |
| Event log | Stored on the device and sent to the server once the connection is restored |
| New credentials | Become active once the connection is restored |
| Credential revocation | Takes effect once the connection is restored. Until synchronisation, a revoked credential may still work at the panel |
| Calls to the mobile app and door release over the internet | Unavailable until the connection is restored |
If a site needs access changes to take effect immediately, for example when an employee leaves an office, a reliable connection between the panels and the server is essential. For projects where centralised decision-making is the priority, server-side admission is an option, bearing in mind that in this mode access depends on the server being available.
3. Where data is stored and how long it is retained
An intercom system may process personal data: access logs, call history, visitor snapshots and resident details. For projects in the UK and EU, this raises compliance considerations under UK GDPR and EU GDPR respectively; elsewhere, local data protection law applies. The choice of architecture directly shapes the answers to the following questions.
Where data is stored. Link Cloud is available in three server regions: Europe, the United States and Asia. A regional server is selected at registration, and BAS-IP recommends choosing the region that matches the project’s location. With Link Selfhost, the main database sits on the customer’s infrastructure.
How long data is kept.
| Data type | Link Cloud | Link Selfhost |
| Access event log | One month, then deleted | Rotation period set by the server owner |
| Call history | One month | Set by the server owner |
| Event snapshots | One month, only if the customer has enabled sending them | Set by the server owner |
| Video recordings | Not stored | Not stored |
Biometrics. Photos used for face recognition are not stored. The image is converted into a hash, which is stored in encrypted form. If the photo is uploaded through the panel’s own web interface, the hash is created and stored on the device. If it is uploaded through the mobile app, the server creates the hashes and sends them to the panels.
Who has access and how to delete data. In the cloud scenario, BAS-IP acts as a data processor under a data processing agreement (DPA) with the customer. The purposes of processing and who has access are set out in the Privacy Policy: personal data is accessible only to staff who need it for their work, for example for technical support or incident investigation. Data subjects may request access to their personal data, rectification or erasure of that data, or data portability, in line with the Privacy Policy and applicable request-handling procedures.
4. Access control compatibility
According to the same report, 82% of respondents say backward and forward compatibility is important to future infrastructure planning. For intercoms, that translates into a practical requirement: the panel should not force replacement of the existing access control system, whether the architecture is cloud-based or on-premises.
Hardware level. A BAS-IP panel can be connected to a third-party controller as a reader, and a third-party reader can be connected to the panel. The available interfaces depend on the model: some panels have both Wiegand input and output, others only an output. The external SH-12 module can be used to connect Wiegand devices to any BAS-IP panel. It connects to the panel via RS485 and provides a Wiegand input for third-party readers and keypads, plus a Wiegand output for third-party controllers.
Network level. The panels use SIP. The built-in SIP server in Link can route calls between devices and mobile apps, connect to the site’s existing IP PBX and support call-forwarding rules.
Software level. The Link API, Mobile SDK and Device API allow the system to integrate with building management platforms, PropTech services and the customer’s own applications:
- Device API. The documentation is open. Developers register at bas-ip.com and can start working straight away, with no NDA and no need to contact BAS-IP.
- [Link API](https://bas-ip.com/articles/bas-ip-link-api/) and Mobile SDK. Available on request. The company describes its use case and, after a call and an NDA, receives a dedicated project with documentation, libraries, code samples and a sample application. There are no partner tiers, participation fees or turnover requirements; a clearly defined use case is required.
There is no separate charge for access to the documentation and integration tools; BAS-IP products are licensed on the usual terms. For more detail, see our article on integration tools.
Ready-made integrations. The level of integration varies by platform. With some systems, BAS-IP supports calls, video and relay control; with others, the integration also covers credentials, events and access levels. Check the relevant integration page for the exact feature set.
| Category | Platforms |
| Access control | Gallagher, Inner Range, Galaxy Control Systems, Napco, Rosslare, ACTpro, U-Prox, Hartmann |
| Video surveillance | Hikvision, Axis |
| Security platforms | Alarm.com, AxxonSoft |
| Lifts | KONE |
| Smart home and automation | Control4, Lumi, Zennio |
| Microsoft Teams | via CyberTwice |
| Residential community apps | Accrete, RahatBina, Condo Control |
| Gated communities | EntranceIQ |
If the platform you need is not listed, integration can be explored through the Device API, Link API or SDK, depending on the scenario and the capabilities of the third-party system.
5. Cybersecurity
The proportion of professionals who say their current systems lack cybersecurity features rose from 21% to 32% in a year. Every networked device at a door should be treated as part of the site’s cybersecurity perimeter. BAS-IP addresses this in several ways:
- Administrator password. On current models, initial setup requires creating an administrator password. The procedure may differ on earlier models, so default credentials must be changed before a device goes into service.
- Brute-force protection. Rate limiting is applied to a number of interfaces and APIs.
- Regular updates. On average, each device category receives around four major and up to 20 minor firmware releases per year.
- Panels support both standard cards and copy-protected cards (MIFARE DESFire).
- Biometrics stored as hashes, not photos (see section 3).
6. Mobile credentials
Half of Mercury’s respondents already use or plan to adopt mobile credentials, while 46% rank mobile credential integration among the trends driving controller purchases. Architecture matters here too: some scenarios work locally, others need the server.
- UKEY (Bluetooth). The smartphone sends an encrypted credential to the reader, which decrypts it and passes it to the panel. Works locally; no internet connection is needed at the moment of entry.
- The same principle, available on Android smartphones.
- Via the app. The resident taps the door release button in the Link app and the command reaches the panel through the server. An internet connection is required.
7. Checklist: 8 questions to ask a vendor before choosing an architecture
- Can the system be deployed either in the cloud or on your own server?
- What keeps working if the server connection or the internet goes down, and how are access revocations applied?
- Where is the data physically stored, and in which jurisdiction?
- How long are logs, calls and snapshots kept, and who sets those periods?
- How does the panel connect to an existing access control system, and what functionality does each ready-made integration support?
- Are APIs and SDKs available, and on what terms are they offered to integrators?
- How is the device protected against attacks, and how often are updates released?
- Which mobile credentials and card formats are supported?
Frequently asked questions
Can BAS-IP be used without the cloud?
Yes. Link Selfhost is deployed on the customer’s own server, and the main database sits on their infrastructure. Core features are available without a paid licence.
Where is data stored in Link Cloud?
In one of three server regions: Europe, the United States or Asia. The region is selected at registration.
How long are logs kept in Link Cloud?
One month, after which they are deleted. Video recordings are not stored. In Link Selfhost, the retention period is set by the server owner.
Can a BAS-IP panel be connected to an existing access control system?
Yes. Ready-made integrations are available for a number of systems, including Gallagher, Inner Range, Rosslare and Napco, and their features vary. At hardware level, the panel connects via Wiegand, either directly or through the SH-12 module.
What happens to the door if the internet goes down?
In the standard configuration, calls from the entry panel to the monitor, door release from the monitor and entry with already synchronised credentials continue to work over the local network. Logs are sent to the server once the connection is restored. Calls to the mobile app and door release over the internet are unavailable, and access changes are applied once the connection is restored.
Does BAS-IP store photos of faces?
No. Face recognition uses a hash rather than a photo, and the hash is stored in encrypted form.
How much does access to BAS-IP APIs and SDKs cost?
There is no separate charge for access to the documentation and integration tools; BAS-IP products are licensed on the usual terms.
Can apartments on Basic and Plus plans be combined in one building?
Yes. Link Cloud plans are assigned per apartment, so a single project can include apartments on different plans.
Conclusion
The choice between a cloud deployment and a self-hosted deployment determines where data is stored, who manages the underlying infrastructure, what happens if connectivity is lost and how the system fits with the rest of the building’s infrastructure. A cloud deployment removes the need for the customer to maintain server infrastructure, while a self-hosted deployment gives greater control over where data is held and how long it is retained.
At BAS-IP, both options are built on the same Link platform. In the standard configuration, the panels’ core local functions keep working if the connection to the server is lost, and for integration with access control, lifts and other building platforms, BAS-IP offers ready-made integrations, APIs and SDKs.