
Secure by Design
As Ubiquiti expands its product offerings and diversifies their applications, we remain committed to refining our processes to safeguard your information and privacy. This document outlines the specific methods and practices we employ to minimize security risks.
Edge-First Philosophy
Ubiquiti’s approach places local control and processing at the heart of every deployment. Our UniFi solutions (UniFi Network, UniFi Protect, etc.) are designed to store and process data on-premises by default. This reduces cloud dependencies and allows you to run core applications locally, ensuring better performance, control, and privacy.
Key Principles of Edge-First
Minimal Cloud Dependencies
Most UniFi functions run locally without mandatory cloud services. You can still leverage Ubiquiti’s cloud infrastructure if you choose, but we architect our solutions so that critical features remain operational—even if the cloud is offline.
Local Data Storage
Camera footage, AI analytics, and network device statistics are processed and stored on-site (e.g., on an NVR or local AI appliance). This reduces external exposure and enhances privacy.
Edge Performance Advantage
By processing data closer to where it’s generated, we reduce complexity and give you direct control over how your network and devices operate.
Examples of Local-Centric Operation
UniFi Network
Local Management
Manage your network on a UniFi Cloud Gateway, CloudKey, or self-hosted Network Server.
Local Data Handling
Core network tasks—such as routing, firewall enforcement, and Deep Packet Inspection (DPI)—are performed on your UniFi Cloud Gateway, CloudKey, or self-hosted Network Server. Keeping these functions on-premises enhances performance, reliability, and privacy.
Selective Cloud Integration
While the majority of your data stays local, certain features—like software and threat signature updates, push notifications, or remote alerts—rely on Ubiquiti’s cloud. This ensures you’re always up to date with the latest protections and improvements, without compromising your data sovereignty.
UniFi Protect
Local Video Storage
Camera footage is recorded directly to your NVR or other UniFi OS hardware. Footage is never stored in our cloud.
On-Device AI
Advanced analytics run on local compute (e.g., AI Key or the camera itself), minimizing cloud interaction.
Optional Remote Access
UniFi Site Manager
A web dashboard (unifi.ui.com) provides centralized remote access if enabled. However, none of your detailed network data or video footage is stored in our cloud. The only exception is for optional cloud backups, which are end-to-end encrypted with your own password. These backups never contain any video data.
Disable at Will
Remote access is entirely optional. You can disable it if you prefer offline-only operation, at which point any management access would occur locally or via your own VPN.
Where Cloud Integration Is Required
Certain UniFi features leverage cloud connectivity for setup, management, and notifications. However, core functionality remains local where technically possible:
UniFi Site Manager
Provides centralized remote access and optional encrypted cloud backups. SD-WAN configurations are stored in the cloud, but no traffic flows through Ubiquiti’s infrastructure. If you prefer, you can operate your UniFi deployment entirely offline, using local login access or manual VPN/port forwarding for remote management.
Site Magic SD-WAN
Uses WireGuard to establish direct, peer-to-peer tunnels between sites. Traffic never passes through Ubiquiti’s cloud infrastructure. Even in cases where a site is behind a firewall or double NAT, Site Magic dynamically routes through the public IP address of one of your other sites. Because it is built on WireGuard, all traffic is fully encrypted end-to-end. Cloud connectivity is only used for initial setup and coordination—not for data transmission.
UniFi Teleport VPN
Uses WireGuard for encryption and is designed for seamless, automatic remote access. While Teleport prefers direct device-to-device connections, it may proxy through Ubiquiti’s cloud in cases where a gateway is behind a firewall. However, all traffic remains fully end-to-end encrypted. If you prefer a fully manual VPN setup, you can configure WireGuard, OpenVPN, or L2TP to bypass Ubiquiti’s cloud entirely.
Mobile Push Notifications
Alerts are relayed through the cloud. If an image is included in a notification, it is encrypted, and only the customer can decrypt it. All images are automatically deleted after 24 hours.
Cloud Email Notifications
If a custom SMTP server is not used, emails are sent through Ubiquiti’s SMTP servers. Emails are only stored temporarily in the queue for delivery and are removed from our systems as soon as they are successfully sent.
We focus on minimizing cloud dependencies while ensuring secure, seamless management.
If the Cloud is Unreachable
Even if Ubiquiti’s cloud services were temporarily offline, your local network and security features remain fully functional:
Network Continuity
Devices continue to route traffic, enforce firewall rules, and authenticate users.
Local Administration
You can still log in to your on-prem UniFi Cloud Gateway, CloudKey, or self-hosted Network Server via local IP or a direct connection (e.g., VPN).
Site Magic SD-WAN
Our peer-to-peer “Site Magic” tunnels remain established and do not route data through Ubiquiti’s cloud. You may be unable to reconfigure certain aspects without cloud connectivity, but existing tunnels will stay up.
In rare cases, updates and certain remote diagnostics won’t be available until cloud connectivity is restored. But your core network functionality remains unaffected.
Security and Privacy by Design
Encryption Everywhere
Data in Transit
All data traveling between your devices and Ubiquiti’s services is encrypted (HTTPS, secure tunnels, etc.).
Local Storage
Video footage, logs, and other sensitive files remain on your local server unless you choose to back them up to the cloud.
Cloud Backups
Optional end-to-end encryption means only you have the decryption key (your account password).
Minimizing the Attack Surface
By running critical services on local hardware, Ubiquiti’s edge-first model reduces the potential risks associated with fully cloud-reliant systems. Fewer cloud dependencies = fewer possible external attack vectors.
Rigorous Testing & Bug Bounty Program
Thorough QA and Alpha Testing
Ubiquiti conducts extensive internal testing and leverages an Alpha and Early access testing community of experienced users who deploy firmware in real-world environments before general release. This process helps identify and resolve potential reliability and security concerns ahead of major updates.
Leading Bug Bounty Program
We value the security research community and offer one of the most competitive bug bounty programs in the networking industry. Independent researchers are rewarded for discovering and responsibly reporting vulnerabilities, ensuring that security improvements happen continuously.
Our Commitment to Trust
Ubiquiti is focused on delivering secure, reliable, and privacy-focused products. We continuously evolve our solutions—combining robust local features, optional cloud conveniences, and best-in-class security practices. Whether you’re managing a small home setup or a massive enterprise network, our edge-first design philosophy and transparent security practices ensure that you remain in control of your network and data at all times.
This was last updated on July 13, 2026.