Some facilities cannot connect to the internet. Defence installations, nuclear and critical-energy sites, secure government buildings, high-value vaults, certain pharmaceutical and research environments — in each, network isolation is a control, not an inconvenience. Attendance still has to work, and in these environments it often matters more than elsewhere, because knowing precisely who is inside the perimeter is a safety and security requirement rather than a payroll one.

This guide covers what air-gapped biometric attendance involves, what changes compared with a normal deployment, and the questions worth asking before assuming a product can do it.

What air-gapped actually means here

An air-gapped deployment has no route to the public internet. Everything the system needs — the server, the database, the matching engine, the administration interface and the check-in devices — lives inside an isolated network segment. There is no licence server to phone home to, no cloud dashboard, no automatic update channel, and no vendor remote support session.

This is a stronger requirement than “offline capable”. Many products advertise offline operation, meaning a device can keep working through a network outage and sync later. That is useful but different: it still assumes connectivity exists most of the time. Air-gapped means it never exists, by design, permanently.

What has to be true of the product

  • Self-hosted server, fully functional without internet. The whole matching and record pipeline must run locally. See on-premise attendance software.
  • Offline licensing. If the licence validates against a remote server, the system will eventually stop working. Ask specifically how licensing is handled with no outbound connection.
  • Local administration. A web control panel served from the local server, reachable from an internal workstation — not a cloud console.
  • On-device matching and liveness. Recognition and anti-spoofing must run without calling out. See presentation attack detection.
  • Manual update path. Updates delivered as files that can be transferred through your approved procedure and verified before installation.
  • Local time source. No public NTP. The deployment needs an internal time source, and timestamps are evidentiary in these environments.

What changes operationally

Updates become a project, not a notification

Each update is transferred deliberately, checked, and applied in a maintenance window. Plan a cadence — many secure sites update once or twice a year rather than continuously — and confirm the vendor supports versions long enough for that rhythm. Ask about the support lifetime of a given release before you deploy it.

Support happens without remote access

No screen sharing into the environment. That makes diagnostics dependent on what your own staff can extract: logs, exports, configuration dumps. Verify these can be produced and sanitised for sharing, and that the vendor can work from them. Train two people internally rather than relying on one.

Enrolment is a controlled process

Enrolment happens inside the perimeter, on managed devices, usually by cleared staff. Build it into onboarding alongside the badge and the induction, because a contractor arriving on Monday morning cannot self-enrol from a phone outside.

Backups stay inside

Backups of a biometric database must remain within the same security boundary, with the same handling rules as the live system. That includes the retention and destruction discipline described in our compliance hub — backups are where deleted templates quietly survive.

Choosing modalities for secure sites

High-security environments often justify stronger assurance than an office. Practical patterns:

  • Iris where assurance must be highest, hands may be gloved or dirty, or faces are partly covered by protective equipment. See iris recognition.
  • Face with robust liveness for throughput at main entrances.
  • Multimodal — requiring two modalities for entry to the most restricted zones, while a single modality suffices at the perimeter.

Tiering by zone is usually better than applying the strictest control everywhere; uniform maximum security produces queues, and queues produce workarounds. Our high security page covers this pattern.

Attendance as a safety instrument

In isolated facilities the attendance record doubles as the live occupancy list. If an alarm sounds, the question is not how many hours someone worked but exactly who is inside and where they last badged. Two capabilities matter for this: a real-time on-site view that does not depend on any external service, and an exportable muster list that works when the network — and possibly the power — is degraded. Ask how the system behaves during a partial failure, and test it during commissioning rather than during an incident.

Procurement questions specific to air-gapped deployments

  1. Can the system be installed and operated with no outbound connectivity, permanently?
  2. How is licensing validated offline, and what happens at renewal?
  3. How are updates delivered and verified, and how long is a release supported?
  4. What can your support team do without remote access, and what do you need from us?
  5. Which databases are supported on-premise, and what are the hardware requirements?
  6. Does the control panel run locally, and what are its authentication options?
  7. Can we export a live occupancy list from a workstation inside the segment?
  8. Is the API identical to the cloud product, so internal integrations are portable?

Our RFP checklist covers the broader set, and how it works shows the server-and-clients architecture these questions probe.

Frequently asked questions

Is air-gapped the same as on-premise?

No. On-premise means you host it; air-gapped means it also has no internet path at all. Every air-gapped deployment is on-premise, but not every on-premise deployment is air-gapped.

Can we pilot in the cloud and then deploy air-gapped?

Only if the vendor runs the same server software in both modes. Where they do, piloting in the cloud is a low-risk way to validate accuracy before building the isolated environment.

How do mobile check-ins work with no internet?

Devices connect to the local server over the internal network. Public mobile data is not involved, and typically not permitted.

What about visitors and contractors?

They need enrolment inside the perimeter and short retention afterwards. See visitor management.

Commissioning an isolated deployment

Commissioning takes longer in an air-gapped environment than teams expect, mostly because every transfer into the segment follows a procedure. Planning for that up front avoids a project that stalls at the boundary.

Stage the software transfer early. Installation media, dependencies, database, licence files and documentation all have to cross the gap through your approved process, with checksums verified on both sides. Establish exactly what will be needed before the installation window rather than discovering a missing dependency inside it.

Validate the licence mechanism first. Before configuring anything else, confirm the system runs and will keep running with no outbound connectivity, and establish what renewal will involve. Discovering a phone-home requirement after enrolment is the worst possible sequencing.

Set the time source before enrolling. Timestamps in these environments are often evidentiary. Point the server and every device at the internal time source and verify they agree.

Document the whole configuration. With no remote support, your own runbook is the support resource. Record server configuration, device registration steps, network segments, account roles and the recovery procedure — and store it somewhere accessible during an outage, which means not solely on the system it documents.

Rehearse the failure cases. Server restart, device replacement, database restore from backup, and enrolling a new starter when the usual administrator is absent. Rehearse them during commissioning while the vendor is still engaged.

Governance in isolated environments

Isolation removes some risks and concentrates others. Everyone with physical access to the segment is inside the trust boundary, which makes internal controls carry more weight.

  • Separate duties. The person who enrols should not be the person who can delete audit logs.
  • Review access quarterly. Cleared staff change roles; administrator accounts outlive the reason they were created.
  • Log and review. An audit trail nobody reads is a record, not a control. Set a review cadence.
  • Keep two trained administrators. With no remote support, a single point of knowledge is an operational risk rather than an inconvenience.

NCheck is a biometric attendance system by Neurotechnology that runs on-premises or in the cloud, supports face, fingerprint and iris recognition, and works on phones, tablets, IP cameras and biometric terminals. Free forever for up to 5 employees.