On-Premise Property Management Software: Secure Server Deployment Guide

By Mark Strong on April 14, 2026

on-premise-property-management-server-deployment

Enterprise property operators are increasingly asking a question that cloud-first vendors cannot answer comfortably: where does our maintenance data actually live? For government-managed properties, healthcare facilities, financial sector real estate, and high-security commercial portfolios, the answer to that question is not optional — it is a regulatory and contractual obligation. On-premise deployment of property management software puts the data, the server, and the control back inside your organisation's perimeter. OxMaint supports secure server deployment, private cloud configuration, and self-hosted CMMS environments — giving enterprise property teams the operational power of a modern CMMS without surrendering data sovereignty. Sign up to explore deployment options, or book a demo to discuss your organisation's specific infrastructure requirements.

Your Property Data Belongs to You — Not a Cloud Provider
OxMaint offers on-premise, private cloud, and hybrid deployment options for enterprise property teams that require data sovereignty, local server control, and custom security configurations.

Why Property Operators Choose On-Premise Deployment

The decision to deploy on-premise is rarely about technology preference — it is driven by compliance obligations, insurance requirements, or contractual data handling clauses that cloud SaaS platforms cannot satisfy. Understanding which requirement is driving the decision determines which deployment architecture fits best. Book a demo and OxMaint's solutions team will map your specific compliance requirements to the right deployment model.

Data Sovereignty
Regulatory requirements in some jurisdictions mandate that certain operational data cannot leave the country or region. On-premise deployment guarantees physical data residency without relying on cloud provider regional settings.
Government / Public Sector
Security Perimeter Control
High-security facilities — defence-adjacent properties, financial sector buildings, critical infrastructure — require all software to operate within a controlled network perimeter with no external data transmission.
Critical Infrastructure
Compliance and Audit Requirements
ISO 27001, SOC 2, GDPR, and sector-specific frameworks sometimes impose data handling requirements that are more straightforwardly satisfied by on-premise deployment with direct audit access to the physical infrastructure.
Enterprise / Regulated Industries
Network Reliability Independence
Remote properties, industrial sites, and facilities with unreliable internet connectivity need a CMMS that functions fully without a live cloud connection — with local data sync when connectivity is restored.
Remote and Industrial Properties

Three Deployment Models OxMaint Supports

Model A
Full On-Premise — Your Hardware, Your Network
Data LocationYour physical servers, your data centre
Network AccessInternal LAN only — no external traffic required
UpdatesManual update packages delivered on your schedule
Best ForGovernment, defence-adjacent, and classified facilities
The highest-control deployment option. OxMaint is installed on organisation-owned hardware within your physical network perimeter. No data leaves your infrastructure under any circumstances. Security patching and version updates are applied on your approval timeline.
Model B
Private Cloud — Dedicated Tenant, Your Region
Data LocationDedicated cloud instance in your specified region
Network AccessVPN-gated or IP-restricted access
UpdatesManaged by OxMaint on agreed maintenance windows
Best ForEnterprise portfolios with regional data residency requirements
A dedicated cloud instance — logically and physically separate from OxMaint's shared cloud infrastructure — hosted in your chosen region. Data residency is guaranteed. Infrastructure management is handled by OxMaint, eliminating the internal IT overhead of full on-premise while maintaining sovereignty compliance.
Model C
Hybrid — On-Premise Core, Cloud-Assisted Analytics
Data LocationOperational data on-premise; aggregated analytics in private cloud
Network AccessEncrypted one-way sync to analytics layer
UpdatesCore system on your schedule; analytics layer auto-updated
Best ForLarge portfolios needing on-premise operations with portfolio-wide reporting
Operational data — work orders, technician records, asset history — remains on-premise. Anonymised or aggregated performance metrics are synced to a private analytics layer for portfolio-wide dashboards and benchmarking. Combines data control with enterprise reporting capability.
Not Sure Which Deployment Model Fits Your Requirements?
OxMaint's solutions team will review your compliance obligations, infrastructure, and data handling requirements — and recommend the right deployment architecture before you commit to anything.

Minimum Server Requirements for On-Premise Deployment

OxMaint's on-premise instance is containerised for straightforward deployment on standard enterprise server infrastructure. The following specifications cover a typical property portfolio of up to 500 assets and 50 concurrent users. Sign up to receive the full technical specification sheet for your deployment scale.

Processing
8-core CPU
Minimum for 500-asset portfolio. 16-core recommended for enterprise scale above 2,000 assets or 200 concurrent users.
Memory
32 GB RAM
Base deployment. 64 GB recommended for large asset portfolios with active IoT sensor data ingestion.
Storage
2 TB SSD
Covers 5 years of work order, photo evidence, and compliance document storage at typical portfolio density. RAID-1 minimum for redundancy.
Operating System
Linux / Windows Server
Ubuntu 20.04 LTS or RHEL 8+ preferred. Windows Server 2019+ supported. Docker and Kubernetes compatible for containerised deployments.
Database
PostgreSQL 14+
Bundled with deployment package. Compatible with existing enterprise PostgreSQL instances for organisations with centralised database infrastructure.
Network
1 Gbps LAN
Internal LAN for full on-premise. Optional outbound HTTPS on port 443 only for hybrid model analytics sync. All traffic AES-256 encrypted.

Implementation Roadmap: On-Premise Deployment

1
Infrastructure Assessment
Week 1
OxMaint's solutions team reviews your server environment, network topology, security requirements, and compliance obligations — producing a deployment specification document.
2
Server Provisioning
Week 2
Your IT team provisions hardware to specification. OxMaint delivers the containerised installation package, database schema, and configuration files for your environment.
3
Installation and Configuration
Week 3
OxMaint engineers deploy the instance, configure LDAP or SSO integration, set up role-based access controls, and validate encryption settings against your security policy.
4
Data Migration and Go-Live
Week 4
Asset data, historical records, and user accounts migrated from existing systems. Acceptance testing completed. Platform handed over to your engineering team for production use.
On-Premise and Live in 4 Weeks — Enterprise Infrastructure Included
OxMaint's deployment team manages the full installation, configuration, and migration — your IT team provides the hardware and we handle the rest.

Global Data Sovereignty Compliance

On-premise deployment satisfies data residency requirements across every major regulatory framework. OxMaint's deployment team is experienced in configuring environments that meet the following standards. Book a demo to discuss your specific jurisdiction's requirements.

USA
FedRAMP / FISMA / ITAR — On-premise deployment satisfies FedRAMP boundary requirements for government facilities and ITAR data handling obligations for defence-adjacent properties. OxMaint configures audit logging to NIST 800-53 standards.
Canada
PIPEDA / Protected B — Federal government properties requiring Protected B data classification can deploy OxMaint on-premise within Government of Canada IT infrastructure. PIPEDA compliance documented in the data processing agreement.
UK
UK GDPR / Cyber Essentials — Post-Brexit data residency requirements satisfied by on-premise or UK-region private cloud deployment. OxMaint supports Cyber Essentials Plus certification requirements for public sector property operators.
Germany
DSGVO / BSI IT-Grundschutz — German GDPR implementation (DSGVO) data localisation requirements fully satisfied by on-premise deployment. OxMaint's configuration aligns with BSI IT-Grundschutz baseline protection catalogues for facility management systems.
Australia
Privacy Act / ISM / IRAP — Australian Government Information Security Manual (ISM) requirements for PROTECTED classification data satisfied by on-premise deployment within agency-controlled infrastructure. IRAP assessment documentation available on request.
Saudi Arabia
PDPL / NCA ECC — Saudi Arabia's Personal Data Protection Law (PDPL) and NCA Essential Cybersecurity Controls satisfied by on-premise deployment with Arabic-language audit documentation. Data never leaves the Kingdom's infrastructure.

OxMaint vs. Competitors — On-Premise and Private Deployment

Scroll
CapabilityOxMaintMaintainXUpKeepFiixLimbleIBM MaximoHippo (Eptura)
Full on-premise deployment YesNoNoNoNoYesNo
Private cloud (dedicated tenant) YesNoNoLimitedNoYesNo
Hybrid on-prem / cloud model YesNoNoNoNoYesNo
Air-gapped (no internet) operation YesNoNoNoNoYesNo
LDAP / Active Directory integration YesLimitedLimitedYesNoYesLimited
Custom data retention policies YesNoNoLimitedNoYesNo
Data sovereignty documentation YesNoNoNoNoYesNo
Deployment time 4 weeksCloud onlyCloud onlyMonthsCloud only6–12 monthsCloud only

Security Architecture: What On-Premise OxMaint Includes

Encryption at Rest and in Transit
AES-256 database encryption. TLS 1.3 for all internal API calls. Encryption keys held by your organisation — never by OxMaint.
LDAP and SSO Integration
Integrates with Active Directory, LDAP, SAML 2.0, and OpenID Connect — enforcing your organisation's existing identity and access management policies.
Immutable Audit Logging
Every user action, data access event, and system change logged to a tamper-evident audit trail — exportable in SIEM-compatible formats for integration with your security operations centre.
Role-Based Access Control
Granular permissions at property, building, floor, and asset level. Technicians see only their assigned work orders. Managers see only their managed properties. Executives see the portfolio view.

Results Enterprise Property Teams Achieve

4 wks
Average time from infrastructure assessment to production go-live
100%
Data sovereignty compliance maintained across all on-premise deployments
Zero
External data exposure events across all OxMaint on-premise installations
68x
Average ROI on on-premise CMMS deployment versus reactive maintenance baseline
Enterprise Deployment — On Your Infrastructure
Full CMMS Power. Complete Data Control. Your Server. Your Rules.
OxMaint delivers the same operational intelligence as our cloud platform — work order management, PM scheduling, compliance documentation, and technician analytics — deployed entirely within your organisation's controlled infrastructure.

Frequently Asked Questions

Does OxMaint function without any internet connectivity in full on-premise mode?

Yes. Full on-premise deployment operates entirely within your internal network. Mobile technician apps sync via your internal Wi-Fi or wired LAN. No outbound internet connectivity is required for core CMMS functionality — including work order creation, PM scheduling, and compliance documentation. Sign up to review the full air-gapped deployment specification.

Who manages software updates in an on-premise deployment?

Your organisation controls the update schedule. OxMaint delivers versioned update packages through a secure delivery channel — your IT team applies updates at a time and pace that suits your change management process. Critical security patches are flagged separately with recommended implementation timelines. Book a demo to walk through the update management workflow.

Can OxMaint on-premise integrate with our existing IT systems?

Yes. OxMaint's on-premise instance supports REST API integration with ERP systems, BMS platforms, DCS historians, and HR systems for technician data sync. LDAP and Active Directory integration means your existing identity management system controls OxMaint access without a separate user management process.

What support does OxMaint provide for on-premise deployments?

On-premise customers receive a dedicated technical account manager, priority support SLA, and access to OxMaint's engineering team for integration queries. Support is delivered via your chosen channel — email, ticket, or scheduled video call — without requiring remote access to your infrastructure unless specifically granted for a support session.

How is the on-premise deployment priced compared to cloud?

On-premise and private cloud deployments are priced on a per-asset or per-user basis with an annual software licence. Infrastructure costs are separate and borne by your organisation. For most enterprise property portfolios, the total cost of on-premise deployment is comparable to or below cloud SaaS pricing when factoring in the elimination of cloud data transfer and storage fees. Book a demo and our solutions team will provide a specific commercial proposal for your deployment scale.


Share This Story, Choose Your Platform!