Lock Icon

Secure by Design

As Ubiquiti expands its product offerings and diversifies their applications, we remain committed to refining our processes to safeguard your information and privacy. This document outlines the specific methods and practices we employ to minimize security risks.

Philosophy
NDAA Compliance
Cloud Security
Data Centers and Code Repos
Corporate Security
Bug Bounty Program
Advisory Bulletins
Subprocessors
Edge-First Philosophy

Ubiquiti’s approach places local control and processing at the heart of every deployment. Our UniFi solutions (UniFi Network, UniFi Protect, etc.) are designed to store and process data on-premises by default. This reduces cloud dependencies and allows you to run core applications locally, ensuring better performance, control, and privacy.

Key Principles of Edge-First

Minimal Cloud Dependencies

Most UniFi functions run locally without mandatory cloud services. You can still leverage Ubiquiti’s cloud infrastructure if you choose, but we architect our solutions so that critical features remain operational—even if the cloud is offline.

Local Data Storage

Camera footage, AI analytics, and network device statistics are processed and stored on-site (e.g., on an NVR or local AI appliance). This reduces external exposure and enhances privacy.

Edge Performance Advantage

By processing data closer to where it’s generated, we reduce complexity and give you direct control over how your network and devices operate.

Examples of Local-Centric Operation

UniFi Network

Local Management

Manage your network on a UniFi Cloud Gateway, CloudKey, or self-hosted Network Server.

Local Data Handling

Core network tasks—such as routing, firewall enforcement, and Deep Packet Inspection (DPI)—are performed on your UniFi Cloud Gateway, CloudKey, or self-hosted Network Server. Keeping these functions on-premises enhances performance, reliability, and privacy.

Selective Cloud Integration

While the majority of your data stays local, certain features—like software and threat signature updates, push notifications, or remote alerts—rely on Ubiquiti’s cloud. This ensures you’re always up to date with the latest protections and improvements, without compromising your data sovereignty.

UniFi Protect

Local Video Storage

Camera footage is recorded directly to your NVR or other UniFi OS hardware. Footage is never stored in our cloud.

On-Device AI

Advanced analytics run on local compute (e.g., AI Key or the camera itself), minimizing cloud interaction.

Optional Remote Access

UniFi Site Manager

A web dashboard (unifi.ui.com) provides centralized remote access if enabled. However, none of your detailed network data or video footage is stored in our cloud. The only exception is for optional cloud backups, which are end-to-end encrypted with your own password. These backups never contain any video data.

Disable at Will

Remote access is entirely optional. You can disable it if you prefer offline-only operation, at which point any management access would occur locally or via your own VPN.

Where Cloud Integration Is Required

Certain UniFi features leverage cloud connectivity for setup, management, and notifications. However, core functionality remains local where technically possible:

UniFi Site Manager

Provides centralized remote access and optional encrypted cloud backups. SD-WAN configurations are stored in the cloud, but no traffic flows through Ubiquiti’s infrastructure. If you prefer, you can operate your UniFi deployment entirely offline, using local login access or manual VPN/port forwarding for remote management.

Site Magic SD-WAN

Uses WireGuard to establish direct, peer-to-peer tunnels between sites. Traffic never passes through Ubiquiti’s cloud infrastructure. Even in cases where a site is behind a firewall or double NAT, Site Magic dynamically routes through the public IP address of one of your other sites. Because it is built on WireGuard, all traffic is fully encrypted end-to-end. Cloud connectivity is only used for initial setup and coordination—not for data transmission.

UniFi Teleport VPN

Uses WireGuard for encryption and is designed for seamless, automatic remote access. While Teleport prefers direct device-to-device connections, it may proxy through Ubiquiti’s cloud in cases where a gateway is behind a firewall. However, all traffic remains fully end-to-end encrypted. If you prefer a fully manual VPN setup, you can configure WireGuard, OpenVPN, or L2TP to bypass Ubiquiti’s cloud entirely.

Mobile Push Notifications

Alerts are relayed through the cloud. If an image is included in a notification, it is encrypted, and only the customer can decrypt it. All images are automatically deleted after 24 hours.

Cloud Email Notifications

If a custom SMTP server is not used, emails are sent through Ubiquiti’s SMTP servers. Emails are only stored temporarily in the queue for delivery and are removed from our systems as soon as they are successfully sent.

We focus on minimizing cloud dependencies while ensuring secure, seamless management.

If the Cloud is Unreachable

Even if Ubiquiti’s cloud services were temporarily offline, your local network and security features remain fully functional:

Network Continuity

Devices continue to route traffic, enforce firewall rules, and authenticate users.

Local Administration

You can still log in to your on-prem UniFi Cloud Gateway, CloudKey, or self-hosted Network Server via local IP or a direct connection (e.g., VPN).

Site Magic SD-WAN

Our peer-to-peer “Site Magic” tunnels remain established and do not route data through Ubiquiti’s cloud. You may be unable to reconfigure certain aspects without cloud connectivity, but existing tunnels will stay up.

In rare cases, updates and certain remote diagnostics won’t be available until cloud connectivity is restored. But your core network functionality remains unaffected.

Security and Privacy by Design

Encryption Everywhere

Data in Transit

All data traveling between your devices and Ubiquiti’s services is encrypted (HTTPS, secure tunnels, etc.).

Local Storage

Video footage, logs, and other sensitive files remain on your local server unless you choose to back them up to the cloud.

Cloud Backups

Optional end-to-end encryption means only you have the decryption key (your account password).

Minimizing the Attack Surface

By running critical services on local hardware, Ubiquiti’s edge-first model reduces the potential risks associated with fully cloud-reliant systems. Fewer cloud dependencies = fewer possible external attack vectors.

Rigorous Testing & Bug Bounty Program

Thorough QA and Alpha Testing

Ubiquiti conducts extensive internal testing and leverages an Alpha and Early access testing community of experienced users who deploy firmware in real-world environments before general release. This process helps identify and resolve potential reliability and security concerns ahead of major updates.

Leading Bug Bounty Program

We value the security research community and offer one of the most competitive bug bounty programs in the networking industry. Independent researchers are rewarded for discovering and responsibly reporting vulnerabilities, ensuring that security improvements happen continuously.

Our Commitment to Trust

Ubiquiti is focused on delivering secure, reliable, and privacy-focused products. We continuously evolve our solutions—combining robust local features, optional cloud conveniences, and best-in-class security practices. Whether you’re managing a small home setup or a massive enterprise network, our edge-first design philosophy and transparent security practices ensure that you remain in control of your network and data at all times.

This was last updated on July 13, 2026.