Skip to content
Guides

Buyer guide · Document management

On-premises document management: who needs it and what to look for

Who still keeps documents on their own servers and why, what you take on when you do, what a good on-premises system should give you, the hybrid patterns that work, and a typical setup drawn out.

For IT managers, records managers and operations leads deciding whether documents should live on their own servers, and what to ask before they buy.

Most new software is sold as a cloud service, and for many teams that is the right choice. But a good number of organizations still keep their documents on servers they own, and for sound reasons. This guide is for them, and for anyone deciding which side of that line they are on.

Ademero sells both models: Content Central for your own servers and Nucleus One in the cloud. If you want the two compared side by side, read our cloud vs on-premises comparison. This guide goes deeper on the on-premises side.

Who still needs documents on their own servers

Regulated or sensitive data with strict policies

Medical records, personnel files, legal matters, financial records and government files. Regulations rarely name a location, but internal policy, contracts or customers often do. When the rule is "these documents do not leave our network", on-premises is the simplest way to prove it.

Data residency

Some organizations must keep data in a particular country or a particular facility. On your own servers, the answer to "where is it?" is a room you can walk into.

Offline, remote or isolated sites

Plants, ships, field offices and secure facilities with poor, metered or no internet still need to file and find documents. A system on the local network keeps working at network speed. For a fully isolated site, ask every vendor (us included) exactly which features need an internet connection: licensing, updates, email capture and cloud integrations are the usual ones.

Integration with on-site ERP and databases

If your ERP, accounting system or line-of-business databases run on your own network, a document system next to them can look up values and hand off data directly, without opening those systems to the internet.

Predictable ownership

You decide when to upgrade, how long to keep a version running, and how data is backed up. Some organizations simply prefer to own the servers they depend on.

The honest trade-offs

On-premises gives you control by making you responsible. Both columns are real:

Location

What you gain:
Documents stay on servers you control
What you take on:
Servers, storage and the room they sit in

Data safety

What you gain:
Your own backup policy and copies
What you take on:
Running backups and testing restores

Updates

What you gain:
Upgrades on your schedule, after your own testing
What you take on:
Applying operating system, database and product updates

Speed

What you gain:
Scanning and large files move at local network speed
What you take on:
Capacity planning as volume grows

Integration

What you gain:
Direct lookups into on-site databases
What you take on:
Keeping those connections working through upgrades

Access

What you gain:
Nothing reachable from outside unless you allow it
What you take on:
Remote access and outside sharing need network setup

If the right-hand column reads like a list of things your team already does well, on-premises will feel natural. If it reads like a new job nobody has time for, look hard at the cloud.

What to look for in an on-premises system

  • A platform your team already supports

    Operating system, web server and database your IT staff know, so it fits your patching and backup routines.
  • Browser access

    No desktop client to install and update on every computer.
  • Your directory for sign-in

    Active Directory or SAML single sign-on, plus multi-factor authentication an admin can require for everyone.
  • Permissions below the folder level

    By document type, by field, and by field value (one branch sees only its own documents).
  • An audit trail that stays on

    Sign-ins, searches, views, downloads, changes, deletions and approvals, with who and when.
  • Retention and legal holds

    Schedules per document type, scheduled destruction, and a recorded override to keep documents indefinitely.
  • Database lookups and ERP exports

    Fill fields from your own databases and send approved data to accounting without custom code.
  • Alerts for the people who run it

    Warnings when a capture backlog grows or a scanner or folder goes quiet.
  • A clean exit

    A full export of documents and index data, in a documented format.
  • Help to get live

    A vendor who does the setup with you and commits to a go-live date.

What a typical on-premises setup looks like

Here is a common Content Central layout. The shape is similar for most on-premises systems: capture points feed a central server, the server keeps its data in a database, staff use a browser, and a few controlled paths cross the network edge.

A typical on-premises document management setup with Content Central. Inside your network: CapturePoint 6 scanning PCs, which read and split pages on the PC, and browser scanning, QCard separator sheets and watched folders all deliver documents to the Content Central server. The server runs on Windows Server with IIS and handles capture and OCR, full-text and field search, workflow and approvals, and permissions, audit and retention. It stores its data in a SQL Server database, which your IT team backs up. Staff use a web browser and sign in with Active Directory, SAML single sign-on and multi-factor authentication. Content Central exports approved data to your ERP or accounting system and looks up values from its database over ODBC. Outside the network: a monitored mailbox (Microsoft 365, Gmail or IMAP) feeds email capture in, and outside people receive only what is shared with them: share links with an expiry, signature requests and forms sent by email.OUTSIDEMailboxMicrosoft 365, Gmail or IMAPYOUR NETWORKCapturePoint 6PCs read pageslocallyBrowser scanningQCards, watchedfoldersContent CentralWindows Server, IISCapture and OCRSearch: words and fieldsWorkflow and approvalsPermissions, audit, retentionDatabaseSQL Server, backedup by your IT teamERP, accountingexports out,ODBC lookups inStaff in a web browsersign in: Active Directory, SAML, MFAOutside peopleexpiring share links, signaturerequests, forms by email link
A typical on-premises Content Central setup. Documents, data and the audit trail stay on servers you control; blue arrows are the only paths that cross the network edge. Outside people reach only what you share with them, so the Content Central web address must be reachable over HTTPS for those links; your IT team decides how.

Capture. CapturePoint 6 scanning stations split stacks and read pages on the PC itself, then deliver finished searchable PDFs with their field values to Content Central over a dedicated API connection you can revoke. Staff can also scan from the browser, use QCard barcode separator sheets, and drop files into watched folders. A monitored mailbox (Microsoft 365, Gmail or any IMAP mailbox) brings email attachments in.

Server and database. Content Central runs on Windows Server with IIS and stores its data in SQL Server. It handles OCR, full-text and field search, workflow, approvals, signatures, permissions, audit and retention.

Systems around it. Fields can be looked up from any ODBC database, such as vendor details from your ERP, and approved data is exported to the accounting system. Sign-in uses Active Directory or SAML single sign-on, with multi-factor authentication.

What your IT team owns

Plan for these before go-live, and write down who does each one:

  • Backups and restore tests

    The database and the stored documents, on a schedule, with a restore tested before you need one.
  • Updates

    Windows Server, SQL Server and product updates, tested and applied on your schedule.
  • Certificates and access

    HTTPS, and how (or whether) the system is reachable from outside the network.
  • Monitoring

    Disk space and capture services. In Content Central, workflow rules can alert IT when the capture backlog grows or a scanner or folder goes quiet.
  • Accounts

    Linking users to Active Directory or your identity provider, and removing access when people leave.

Hybrid patterns that work

On-premises does not have to mean everything stays inside. These patterns keep the records on your servers and open only what is needed:

Capture locally, file on-premises

Scanning stations read documents on the PC and file them straight to the server on your network. With CapturePoint 6 the reading and extraction happen on the PC, so pages are not sent to a cloud service to be read.

File on-premises, share selectively

Records stay on your servers; outside people get only what they need. In Content Central you can share a document or packet with an outside email address, with an expiration; request signatures from anyone with an email address; and email a form that is submitted through an expiring link.

Two systems, split by job

Some organizations keep records and accounting-linked work on their own servers and give client-facing teams a cloud system with client portals. Treat them as two separate systems with clear rules about what goes where; they do not sync.

On-premises now, cloud later

If a move to the cloud is likely in a few years, ask how documents and index data would move. Content Central includes migration actions that move documents to Nucleus One and verify each one.

Where Content Central fits

Content Central is Ademero's document management system for your own servers. It is trusted by Fortune 500 companies and government agencies whose security and IT teams review Ademero every year. What it gives an on-premises buyer:

  • Your servers, a web browser. Windows Server, IIS and SQL Server; staff work in a browser.
  • Sign-in your way. Active Directory, SAML 2.0 single sign-on (for example Okta, Microsoft Entra ID or ADFS) and authenticator-app MFA that admins can require for everyone.
  • Permissions down to the field. Rights per document type, field permissions, access limited by field value, and an option to make users state a reason before opening a document.
  • Audit and records. An audit trail of sign-ins, searches, views, downloads, changes, deletions and approvals; version history; retention schedules per document type; and legal holds by keeping documents indefinitely, with each override recorded.
  • Workflow. No-code rules, multi-step approvals with deadlines and escalation, e-signatures, forms and packets.
  • Your other systems. ODBC lookups from your own databases; exports to QuickBooks, Sage 50, Sage X3, Workday and Epicor; and API connections for document delivery and lookup.
  • A clean exit. Full exports of documents and their index data.
Content Central account security: each user can turn on authenticator-app multi-factor sign-in, and admins can require it for everyone.

We do the setup with you, and going live in 30 days is a commitment, not a slogan. See Content Central implementation.

When Nucleus One in the cloud is the better fit

Choose the cloud, and Nucleus One, when these sound more like you:

  • No servers or IT time to spare

    Nothing to install, patch or back up yourself.
  • People work everywhere

    Nucleus One has iOS and Android apps as well as the web.
  • Clients are part of the work

    Nucleus One includes client portals for the people outside your organization you work with.
  • Your other apps are in the cloud

    Zapier and a REST API connect it to the tools you already use.

Questions

Do regulations like HIPAA require on-premises document management?

Generally not. Most regulations describe safeguards (access control, audit, retention, protection of data) rather than a location. Your own policies, contracts or customers may still require documents to stay on your servers. Your compliance team or counsel should make that call.

Can people reach an on-premises system from outside the office?

Yes, if your IT team makes it reachable, for example over a VPN or by publishing the web address over HTTPS. Content Central runs in a web browser, so there is no desktop software to install on each computer, and on a phone the approval queue switches to cards with approve and reject buttons.

If we start on-premises, can we move to the cloud later?

With Ademero, yes. Content Central includes migration actions that move documents to Nucleus One, Ademero’s cloud system, and verify each one. It is a one-way move, not a live sync between the two.

What does Content Central cost?

Content Central is quoted for your users and setup. Tell us about your setup on the pricing page and we will send pricing that fits, or book a free live demo and we will walk you through it.

See it on your own documents

See Content Central running the way it would on your servers.

In a free demo we walk through sign-in with your directory, permissions, the audit trail, retention and one of your own processes, and answer your IT team's questions about the setup.

Runs on your own Windows servers; people work in a web browser. Quoted for your users and setup. Get pricing

No servers to spare, or people mostly outside the office? Nucleus One is Ademero's cloud document system, with client portals and mobile apps.

Content Central Workflow administration: triggers, actions, rules, export templates, message templates, export queue and export history