Cloud-based and networked access control systems have transformed the way organisations manage security, scale operations and maintain visibility across multiple sites. Yet every additional layer of digital connectivity introduces a corresponding dependency. What happens when the network fails, the cloud becomes unreachable or power is interrupted? Salto Systems’ Salto Space and Salto KS illustrate two distinct approaches to a question that is becoming central to physical security: how much autonomy should an access control system retain when its supporting infrastructure is no longer available?
Electronic access control has undergone a profound architectural shift. Systems that were once predominantly local and self-contained are increasingly administered through centralised platforms, synchronised across estates and, in many cases, managed through the cloud. The advantages are considerable: permissions can be altered remotely, multiple locations can be governed through a common interface and security teams gain a far more comprehensive view of access activity.
Yet greater connectivity does not simply create capability. It also creates dependency. Networks, gateways, cloud services and external power supplies become part of the security chain, and therefore part of the organisation’s risk exposure. The pertinent question for security professionals is no longer merely whether an access control platform performs reliably under normal conditions, but what remains operational when those conditions cease to exist.
In access control, this distinction is particularly important. A communications failure cannot simply result in authorised personnel being locked out of critical areas, nor can resilience be achieved by relaxing the security logic governing entry. A robust system must preserve both availability and control. It is in this context that Salto Space and Salto KS offer two notably different architectural responses to the same underlying challenge.
Salto Space: Moving Intelligence to the Door
Salto Space is built around an architecture in which access decisions need not depend upon a permanent connection to a central server. Central to this model is the Salto Virtual Network, or SVN, combined with a data-on-card approach in which relevant access information can be carried by the credential itself and interpreted locally by the electronic lock.
The significance of this architecture lies in where the decision is made. Rather than requiring the door to consult a distant server each time a user presents a credential, sufficient information can remain available locally for the lock to determine whether access should be granted. A disruption to the wider communications infrastructure does not therefore necessarily remove the system’s capacity to make controlled access decisions.
This degree of decentralisation considerably reduces dependence on uninterrupted network availability. Even where sections of the communications infrastructure are temporarily unavailable, locks can continue to assess credentials using information already available within the system. Updated permissions and event information can subsequently be propagated and synchronised through the virtual network as connectivity is restored.
The locks’ battery-powered operation introduces a further layer of independence. Loss of mains power elsewhere in the building does not automatically render the locking devices inoperative. For large estates, remote locations or premises in which continuous wired connectivity would be impractical or disproportionately expensive, such autonomy can become an important element of operational resilience.
From a business-continuity perspective, the principle is straightforward but consequential: central systems provide administration and synchronisation, while the individual access point retains sufficient intelligence to continue performing its primary security function. It is an architectural philosophy familiar from other resilient systems — centralise what benefits from central control, but avoid making every operational decision contingent upon the availability of the centre.
Salto KS: Cloud Management with Local Fallback
Salto KS adopts a different model. As a cloud-based platform, its principal strengths lie in remote administration, scalability and the centralised management of geographically dispersed locations. For organisations operating portfolios of offices, commercial properties or distributed facilities, the attraction is obvious: access rights can be managed across multiple sites without requiring administrators to be physically present at each one.
Cloud dependency, however, makes contingency design particularly important. Salto KS addresses this through a series of local fallback mechanisms. Compatible locks can be configured to retain certain access permissions locally, allowing them to continue assessing authorised credentials when communication with the system’s IQ gateway is interrupted.
The IQ itself can also retain encrypted credential information locally. Provided it continues to receive power, a loss of connectivity to the cloud does not necessarily prevent doors from operating on the basis of information already available within the local environment. Functions that depend upon a live cloud connection — such as immediately propagated permission changes or certain real-time information — will inevitably be constrained until communication has been restored, but the core access process need not disappear with the connection.
This produces a more hybrid model of resilience. The cloud remains the central management layer, but local caching and decision-making prevent a temporary communications failure from becoming an immediate operational failure. In higher-risk environments, additional connectivity such as cellular backup can further reduce the likelihood that a single communications route becomes a point of failure.
The important qualification is that resilience is not an abstract characteristic of the platform alone. It depends on the precise configuration of locks, gateways, firmware, power arrangements and communications infrastructure. A system may be capable of offline operation in principle while still being inadequately prepared for the particular failure modes of a given site.
A Network Failure Is Not a Power Failure
One of the more important distinctions in assessing access-control resilience is also among the most easily overlooked: loss of communications and loss of power are not the same event.
A lock may remain perfectly capable of making access decisions when an internet connection disappears, yet cease to function if an essential gateway loses power. Conversely, battery-powered locking devices may continue to operate while central communications infrastructure has been disabled. Treating all such scenarios simply as “offline operation” obscures important differences in system behaviour.
In the case of Salto KS, for example, the IQ requires an external power supply. If that supply is interrupted and no uninterruptible power source is available, the IQ can no longer perform its role. At that point, continued operation depends more heavily on the information retained directly by the locks and on how offline access has been configured.
The practical implication is that security planners should be wary of broad claims about offline capability. The more useful questions are considerably more precise: which components remain functional in each failure scenario, what data remain locally available, how long can the system continue to operate in a degraded state, and where do genuine single points of failure remain?
Only when these questions have been answered can organisations make informed decisions about additional measures such as UPS provision, redundant network routes, secondary communications channels or alternative operating procedures.
Resilience Is an Architectural Question
The comparison between Salto Space and Salto KS is therefore less a contest between two technologies than an illustration of two different philosophies of resilience. Salto Space places greater emphasis on decentralised decision-making and operational independence at the access point itself. Salto KS, by contrast, combines the advantages of cloud-based administration with local mechanisms intended to sustain operations during temporary communications disruptions.
Neither architecture can be judged in isolation from the environment in which it is deployed. A company operating hundreds of small, geographically dispersed sites may place considerable value on central cloud administration. A hospital, data centre or industrial site, meanwhile, may attach greater importance to the ability of individual access points to continue functioning during prolonged infrastructure disruption.
Risk tolerance also varies by location. The consequences of temporarily degraded access in a conventional office environment are not equivalent to those in a pharmaceutical laboratory, critical production facility or secure technical area. Resilience must therefore be designed around operational consequence rather than treated as a generic product feature.
That requires organisations to define failure behaviour before systems are deployed. Which doors must remain operable during a complete communications outage? For how long should locally held permissions remain valid? Which infrastructure components require redundant power? Which gateways or network paths justify duplication? How are transactions recorded during disruption, and how are those records reconciled once normal service resumes?
These are not secondary technical questions. They form part of the security architecture itself.
Cloud Convenience Requires Local Resilience
The broader significance extends well beyond the two Salto platforms. As physical security becomes increasingly digital, the distinction between cyber resilience and physical resilience becomes more difficult to sustain. A door controller may be a physical-security component, but its effectiveness can depend upon software services, networks, identity data, communications gateways and power infrastructure.
Cloud services and centralised management undoubtedly provide efficiency, scalability and visibility. Yet systems designed around continuous connectivity must also account for the possibility that continuity will fail. Otherwise, a platform intended to improve security can inadvertently introduce new operational dependencies into the very environment it is meant to protect.
For security leaders, the relevant measure of maturity is therefore not whether an access control system can simply be described as “offline capable”. It is whether the organisation understands precisely how the system behaves under different forms of disruption: what decisions remain local, which functions degrade, what information becomes stale, and how quickly full operational integrity can be restored afterwards.
Resilience is ultimately a property of architecture rather than marketing terminology. An access control system proves its quality not merely when networks, cloud services and power supplies behave as expected, but when they do not — and the system continues to make secure, predictable decisions nonetheless.


