Software-Defined Access, Local Control Guaranteed.
Most access control architectures still depend on dedicated hardware controllers at every site. Primion Virtual Controllers remove that dependency by delivering controller functionality as software, deployable across cloud, on-premises, or edge environments from a single codebase. Every site retains local decision-making and policy enforcement, ensuring operation even when cloud connectivity is unavailable.

In a Nutshell
- Hardware-Free Controllers: Replaces dedicated on-site controller boxes with software that runs from a single codebase across cloud, data centre, or edge deployments.
- Guaranteed Local Autonomy: Each site keeps an active/standby edge cluster, so access decisions keep working through WAN or cloud outages and resync automatically once connectivity returns.
- Faster, Cheaper Rollout: New sites are provisioned straight from the cloud platform rather than a hardware procurement cycle, cutting deployment time and lifecycle costs.
The Catalyst
At most enterprises, adding a new site means starting a controller procurement cycle. The controller has to be specified, ordered, shipped, and installed by an engineer on-site before the doors it’s wired to can be managed. Readers, locks, and cabling go in regardless of architecture. What the traditional model adds on top is a dedicated box that has to be sized, configured, and maintained for the life of the site, and replaced again once it reaches end of support.
Most organisations have stopped questioning this rhythm. But the broader IT estate already moved through an equivalent shift: physical servers gave way to virtual machines, and virtual machines gave way to cloud workloads. The underlying logic did not change, only where it ran. Physical security infrastructure is following the same trajectory, and the organisations driving it are the ones that feel the controller burden most acutely: large enterprises and telecommunications operators managing access control across dozens or hundreds of sites.
The obvious question this shift raises is the one every security lead asks first: if the controller logic now lives in the cloud, what happens to the site when the connection drops? It’s a fair challenge, and one most virtualisation pitches don’t answer well. Losing local autonomy in exchange for centralised convenience isn’t a trade organisations running critical infrastructure are willing to make.
The Method

Primion Virtual Controllers separate controller functionality from dedicated hardware. What was previously embedded firmware now runs as software while retaining the full capabilities of a traditional controller.
That software can run in the Primion cloud, in a customer’s data centre, on dedicated edge hardware at the site, or in a hybrid of all three, from the same codebase. Readers, doors, turnstiles, elevators, and OT equipment stay exactly where they are, connected through an on-site device that serves as a connectivity endpoint rather than the seat of controller logic.
Virtualised does not mean cloud-dependent. Each site runs its own edge cluster of virtual controller nodes in an active/standby configuration, maintaining local access capabilities even if cloud or WAN connectivity is lost. The architecture that removes the hardware controller is designed to be at least as resilient as the controller it replaces.
Above the site layer, a global control plane manages identity, access policy, monitoring, and compliance, with integrations into IAM, HR, workforce management, visitor management, SIEM, and Critical Event Platform systems. A regional layer handles data synchronisation and disaster recovery between primary and standby nodes. None of this changes what happens at the door. It changes how consistently policy reaches every door, and how quickly a new one can be added.
Consider a logistics company opening a new distribution hub. In the old model, a controller is specified, purchased, shipped, and installed by an engineer, and the site builds its own local configuration from scratch. Months pass before the site becomes fully operational, and every future firmware update means another scheduled visit.
In the new model, the site is provisioned from the cloud platform. Edge nodes are deployed with a minimal hardware footprint and seeded with credentials and policy from the regional layer. The site comes online with active/standby resilience built in from day one, and most future capabilities can be delivered through software updates rather than controller replacement.
The challenge Primion is taking seriously is the installed base. Organisations with existing hardware estates face a transition, not a clean start. Virtual Controllers are being designed to support phased deployment alongside existing infrastructure, allowing new sites and pilot clusters to run virtual controllers without requiring an immediate estate-wide migration. That is where first pilot conversations become most valuable.
The Components
- Highest security and compliance standards
Local access decisions remain available during WAN outages, secured by end-to-end encryption. Centralised policy governance, audit trails, compliance reporting, and IAM/HR integration support secure, compliant operations. - High connectivity and integration
Open APIs connect HR, IAM, workforce management, visitor management, field devices, and OT systems. Supports cloud, on-premises, and hybrid deployments with future-ready integration capabilities. - Modular and scalable architecture
One architecture scales from a single site to global estates. New sites join the existing platform, while software, infrastructure, and hardware scale independently. - Operational efficiency and lower cost
Reduce reliance on dedicated controllers, accelerate deployments, and reuse existing infrastructure. Software-based updates lower maintenance effort and lifecycle costs. - Local autonomy and business continuity
Sites continue operating during WAN or cloud outages with built-in resilience and automatic resynchronisation when connectivity is restored.
Virtualised Does Not Mean Cloud-Dependent
The instinct to distrust cloud-based control is a reasonable one. Centralising the logic that governs physical access raises an obvious question: what happens to a site when its connection to that logic goes down? Many architectures that move control to the cloud answer that question by asking the customer to accept the risk. Virtual Controllers answer it differently by preserving full local autonomy at every site, regardless of where the controller logic runs.
For large enterprises operating critical sites, deployment flexibility has become a requirement rather than a preference. The organisations pushing hardest for virtualised access control are also the least willing to compromise on local resilience.
Virtual Controllers are designed for that requirement. Active/standby clusters at every site ensure operations continue uninterrupted during connectivity outages and automatically synchronise once connections are restored. The centralisation that makes the platform easier to govern, update, and scale sits above a layer that was never designed to depend on it.
The result is an architecture that delivers the operational simplicity of software-defined access control without sacrificing the one thing traditional controller-based systems have always guaranteed: the door continues to function and stay secure when the network doesn’t.
The POC

Primion has built and demonstrated the core architecture: controller functionality running as software with full firmware capability intact, edge clusters delivering local resilience with automatic failover, and the three-layer topology operating as designed. The next step is deployment in a live customer environment with the multi-site complexity and integration requirements needed to test it at scale.
A pilot is not simply early access. The operational realities of the first deployments, including site topology, existing infrastructure, and resilience and compliance requirements, will directly influence which integration connectors are prioritised, how migration paths from existing hardware estates are designed, and which configurations are hardened for production use. Pilot partners help shape what the platform becomes.
If your organisation manages access control across multiple sites and is looking to reduce controller dependency without sacrificing local resilience, speak with your Primion account manager about joining the pilot programme. We will work with you to assess whether your environment is a good fit and what a first deployment could look like in practice.
Let’s talk possibilities!
Every project on this page started with a conversation about a real operational challenge. Bring us yours, and let’s explore what a working prototype could look like.