WHERE UNIFI PROTECT CONSTRAINS

Hardware-locked. No native cloud. No MSP console.

The deployment surface narrowed on purpose

UniFi Video installed on a Windows or Linux PC until Ubiquiti retired it in January 2021. Protect will not: no Docker, no NUC, no commodity Linux. Buying the software means buying the console, and every future camera decision is made inside that choice.

Off-LAN, an operator watches the preview, not the recording

Ubiquiti's own banner says it in writing: "A local connection helps reduce latency and maximize resolution during your viewing sessions." Off-LAN traffic reaches the ui.com relay unless the site has a public IP and a free inbound TCP 443, which rules out CGNAT, Starlink, most 4G and 5G WANs and nearly every PCI or ISO 27001 LAN. An r/Ubiquiti operator, verbatim: "If I go to unifi.ui.com and look at the camera in the Protect screen, the resolution is terrible. Like, 1080P terrible. Very blurry... However, if I connect directly to the UNVR via the local IP address, it looks fine." The FAQ below traces who pays for that relay and why the cap exists.

Building the off-site copy is your job

Continuous Archive to OneDrive, Google Drive, Dropbox or a NAS writes proprietary .ubv files, so the archive is only readable back through UniFi software. An integrator who wants a second copy of a customer's evidence assembles the storage, the schedule and the restore path themselves, then owns them at every site.

One sign-in per customer, not one per integrator

Protect 7.0 Site Manager and Fabrics landed end-customer federation in March 2026, so one customer with several buildings finally works. The installer still signs in to a separate ui.com account for every customer they look after. HostiFi and UniHosted sell a multi-tenant layer on top, and both add a vendor and a bill Ubiquiti did not ask you to carry.

Nobody has published a control room running on it

No IPVM coverage of a named Protect SOC deployment, no Ubiquiti case study of a named monitoring-station customer, no public latency or dropout telemetry. Anonymous defenders on r/Ubiquiti report 50-plus sites running fine. On the same thread, u/corsalove, a Ubiquiti installer with a 1,000-plus camera control room, calls Protect the wrong tool for that job. Their team runs a different VMS for the monitoring layer. A second operator running 42 monitors asks plainly how anyone would feed a wall of screens from Protect at scale.

MP4 out, and nothing to prove it is the original

Export downloads MP4 files. No standalone player, no integrity verification, no chain-of-custody workflow. An operator handing footage to police or an insurer hands over a file anyone could have edited, and has no way to show otherwise.

AT A GLANCE

UniFi Protect and TetherX, question by question

The 11 questions an integrator asks on a site walk, answered for both platforms.

Question UniFi Protect TetherX
What you do with the recorders already on site A UniFi OS console becomes the recorder. Protect will not run in Docker, on a NUC, on Windows or on commodity Linux, so an existing recorder has no part to play. They stay. The TetherBox sits alongside the existing NVRs, DVRs and panels and pulls from them. It runs as software on a server the site already owns, so nobody rips out working kit to start.
Which devices you can connect UniFi cameras get the full product. Third-party ONVIF cameras record only, unless the site buys a $199 AI Port per camera, and an integrator running 30 sites reports ONVIF reliability as hit and miss at scale. 1,000+ integrations across 17,000+ device models, plus any ONVIF camera with full features - not a bridged, feature-reduced tier.
What your operators see on one timeline Cameras, Wi-Fi, switching and UniFi Access under one app - strong inside the Ubiquiti range. Third-party intruder panels and door controllers are not part of it. Video, access control, intruder and automation. One operator, one timeline, one dashboard across all four.
Who monitors your alarms No monitoring-station workflow, and no published alarm-receiving-centre case studies. A monitored site keeps a separate signalling path to the centre. It stays. TetherX signals Immix, Sentinel, CONXTD, MASterMind, Bold Patriot Manitou, Stages, CHeKT and others directly, so the existing ARC, SOC contacts and alarm SLAs carry on.
What you can still do when the Internet drops Recording is local on the console, so an outage does not stop it. Off-site redundancy is the customer's problem to assemble. Keeps recording and keeps working. Recording, doors and alarms run on the TetherBox on the local network, and the console picks up where it left off when the link returns.
What your uplink has to carry Off-LAN viewing goes through the ui.com relay on the low-bitrate substream, around 500Kbps to 1Mbps per camera against 4-8Mbps on the archive stream. Remote operators watch the preview, not the recording. Thumbnails, metadata, and the clips an operator opens or chooses to sync. A thin rural line still records every camera, because recording never leaves the local network.
Where the AI runs Person and vehicle analytics, smart events and search need either a UniFi camera or that $199 AI Port on each third-party camera. At the edge on the TetherBox: person, vehicle and animal detection plus 63-class audio analytics, searchable across multi-site footage in seconds. The platform keeps evolving with additional analytics through the year.
Who you buy it from Distribution and direct. No first-party multi-tenant console for an integrator managing several end customers - HostiFi and UniHosted fill that gap as third parties, with another vendor and another bill. Your installer, always. TetherX sells through the channel only and does not quote end customers direct, so the integrator keeps the account.
What you actually pay for No software subscription at all. The cost sits entirely in Ubiquiti hardware, which is dearer than Hikvision or Dahua equivalents and cheaper than Verkada or Rhombus. An annual subscription by channel count, from £100/site/year. Not per operator seat, not per analytic, and no concurrent-user cap.
Where your recordings are stored On the local console. There is no vendor-stored cloud retention - Continuous Archive writes proprietary .ubv files to OneDrive, Google Drive, Dropbox or a NAS, and they need UniFi software to play back. On the TetherBox at site by default. Cloud recording is optional per camera, into a UK, EU, US, Canadian, Indian or Australian region the customer picks.
What you keep if you stop paying Nothing changes, because there was no subscription. This is the genuine strength of the model. The TetherBox keeps a local interface for live view and recent footage with no Internet and no subscription, so the site is never dark.

UniFi Protect column built from: Ubiquiti UniFi Protect, Ubiquiti help: NDAA compliance statement, r/Ubiquiti integrator threads.

UNIFI PROTECT vs TETHERX

Hardware-locked bundle vs open multi-brand platform.

Both unify cameras into a single app. The honest read on where each one wins and where each one costs you something.

UniFi Protect

Strengths

No software subscription - "no fees, ever" on Protect itself, costs shift entirely into Ubiquiti hardware (which is pricier than Hikvision / Dahua / Uniview equivalents but cheaper than Verkada / Rhombus closed-cloud kit)

Strong user-experience polish - one mobile app across cameras / switches / Wi-Fi / access, consumer-grade onboarding, the standout UX in the prosumer / sub-enterprise tier

Strong consumer mobile apps - 4.6 / 5 Apple App Store (around 17K ratings), 4.7 / 5 Google Play (around 19K ratings)

Site Manager + Fabrics (Protect 7.0, March 2026) finally added end-customer multi-site federation

Trade-offs

Hardware-locked - Protect runs only on UniFi OS consoles, ONVIF cameras are record-only without $199 AI Port, no first-party MSP console for integrators, no native cloud retention, NDAA per-SKU

Russia / Ukraine reputational overhang (Hunterbrook January 2026, Pussy Riot March 2026, DOJ Fancy Bear EdgeOS February 2024) sits outside the software-and-recording conversation but is now part of procurement diligence

TetherX

Strengths

Open to 1,000+ integrations including ONVIF support for existing Ubiquiti cameras

First-party integrator / MSP console with per-tenant billing, role-based access across multiple end customers, central health monitoring

cloud recording optional per camera - local-only, cloud-only or both, all in one platform; TetherBox for hybrid edge-plus-cloud retention

ARC integration a la carte (Immix, Sentinel, CONXTD, MASterMind, Bold Patriot Manitou, Stages, CHeKT and others) - the customer picks the monitoring partner, the installer guides the choice

Trade-offs

You are all-Ubiquiti on one site, the hardware is bought, and you never manage another customer's estate. No fees, ever, is the simpler buy.

Pricing figures, ownership, acquisition dates and product behaviour cited on this page are point-in-time and drawn from public sources - see the disclaimer at the bottom of this page for sourcing, "as of" date, and how to flag corrections.

WHICH ONE FITS

Pick the one your site points at

Find the column that describes the job in front of you.

Choose UniFi Protect if

  • One site, already inside the Ubiquiti range, with the hardware bought and no need for an integrator console
  • The customer will not pay a recurring software fee under any circumstances
  • Everyone who views the cameras is usually on the local network, so the relay substream never becomes the experience
  • Nobody needs to hand verified footage to police or insurers

Choose TetherX if

  • You manage several end customers and need one console, per-tenant billing and role-based access across all of them
  • The site runs third-party ONVIF cameras that should keep their analytics rather than becoming record-only
  • Operators review incidents remotely and need archive-quality video, not a capped preview stream
  • The customer's monitoring station, alarm panels and doors have to be part of the same platform
FAQ

Questions before you switch from UniFi Protect

UniFi Protect ships pre-loaded on every UniFi OS console and the pitch is "no fees, ever". For a single-site prosumer or a smaller commercial build that values the app over the cost per channel, that trade lands cleanly, and the polish is real: one mobile app across cameras, switches, Wi-Fi and access, with consumer-grade onboarding nobody else in the tier matches.

The cracks appear the moment a buyer needs more than one site, one user group or one customer. The table above sets out where each of those runs into the design. TetherX answers them differently, and the buyer-fit block says which reader that actually helps.

Ubiquiti cameras that expose an ONVIF profile (most current G-series models do) can be brought into TetherX alongside any other ONVIF / RTSP brand on the site. The constraint is on Ubiquiti's side, not TetherX's: UniFi Protect treats third-party ONVIF cameras as "recording only" - no person / vehicle analytics, no smart events - unless you also buy a $199-per-camera AI Port. TetherX runs analytics in the cloud or on TetherBox, so the camera does not need to ship AI inference to qualify. Net result: existing Ubiquiti cameras keep recording, and you gain the option to mix in Axis / Hanwha / Hikvision / Bosch / Dahua / i-PRO / Mobotix / VIVOTEK without paying a per-camera AI surcharge for the cross-brand integration.

It is true, and it is worth reading as a hardware price rather than a software one. A UniFi G6 Bullet is $199 against sub-$100 for a comparable Hikvision, Dahua or Uniview camera; a UNVR Instant is $199, a UNVR $299, an Enterprise NVR Core around $5,000 and an AI Key around $799. The cheapest route to cameras on a wall is still Hikvision or Dahua, and both carry NDAA Section 889 baggage Ubiquiti does not. The premium buys the app polish and the Five-Eyes procurement story, and those are things buyers genuinely want.

Where the sums turn is on the second site and the second customer. Drives, off-site storage and the integrator console are all separate purchases on the Protect side. TetherX charges one annual subscription by channel count through the qualified installer, with cloud recording, AI search and ARC integration added per camera where a site needs them. So Protect wins on a single site with the hardware already bought, and TetherX wins once the integrator is running several customers and billing remote monitoring on top.

"MSP multi-tenant console" is the integrator-side dashboard that lets one installer (or one MSP technician) sign in once and manage every end customer they look after - separate, walled-off video estates, separate billing, separate user lists - from a single pane. Compare an accountant opening a different Xero account for every client, one customer per session, against the same accountant opening one firm-level dashboard and pivoting between clients in a click. "Multi-tenant" keeps each end customer's data, users and footage logically separate. "MSP" gives the integrator a layer above all of those tenants.

This is the largest functional gap with UniFi Protect for installers running more than a handful of customer sites. Ubiquiti's March 2026 "Site Manager" + "Fabrics" feature landed end-customer multi-site (one customer with several buildings), but the integrator still has to sign in to a separate ui.com account per customer. Third-party hosting platforms (HostiFi, UniHosted) layer a multi-tenant console over Ubiquiti consoles, but neither is a Ubiquiti product and both add another vendor (and another bill) to the stack.

TetherX ships an integrator-side multi-customer console as a first-party feature - one sign-in for the integrator, every end-customer estate visible inside it, channel-only billing through the installer, and the customer relationship and recurring revenue staying with the installer rather than the platform vendor. For an installer with five or more end customers, the absence of this layer in UniFi Protect is the operational tax.

The honest answer from the field (r/Ubiquiti, May 2026, "Is Ubiquiti Protect viable for large enterprise CCTV deployments?" - 80+ locations, 40-500 cameras per site, evaluating off Genetec + CCURE + Axis):

Connectivity. Per Ubiquiti's own Site Manager documentation a "Direct Connection automatically activates when accessing a site via Site Manager while connected to the same local network." Translation: same LAN gets a direct connection, remote viewing across sites goes through a ui.com brokered relay. No port forwarding required at the integrator end (good), but live-view latency and bandwidth on the cross-site view depend on Ubiquiti's relay path, not on a customer-controlled link.

"Show me every front door across every site" workflow. Not really. Site Manager + Fabrics federates sites at the navigation level, but there is no tag-based cross-site search ("show all cameras tagged front_door across all 80 sites in one grid"). Field report on the live view at scale, JamesAtWork85 verbatim: "Finding and organizing cameras in the live view grid is somewhat annoying at the 60 or so feeds we're at. Would be nice to be able to add a bit of structure to it." For a video wall feeding many cameras, slynas verbatim: "I'd be interested to see how you'd feed an entire wall of screens with protect, on a scalable level." The dedicated video-wall renderer at SOC scale is the gap, not the viewing surface.

ONVIF cameras (i.e. anything not Ubiquiti). Leading-Call9686, 30 large sites with 100-200+ cameras per site, verbatim: "if you are using Unifi cameras primarily, then it works great. But if you are trying to use ONVIF cameras, then you will run into issues... At this point I can't recommend any deployment that uses a majority of ONVIF cameras if you want minimal issues over time." Sala91: "ONVIF support is very hit and miss. Some cameras will just go to reboot hell with unify onvif protocol. Unifi own cameras however have been nothing but perfection in terms of reliability." Changing resolution / frame rate on an ONVIF camera requires fully removing and re-adding it; zero intelligent error reporting on ONVIF failures.

Footage export and chain of custody. Artentus: "If you export footage you are downloading MP4 files to your computer... if you have any special legal requirements it's not happening on Protect." No standalone-player export with integrity verification.

Field verdict on enterprise readiness. Sala91, after running an enterprise eval: "current trend shows them competent in about 5 years for big enterprise. Today it's probably perfect for SOHO, fits most SIMPLE deployments of enterprise and some more complex with help of MSP." Same thread, multiple commenters: future features (LTS branches, expanded continuous archiving, multi-site video wall) "with Ubi this could mean in two months or in five years." Translation: Site Manager / Fabrics is a real improvement on per-console isolation, but it is not the Genetec-class multi-site experience a 30+ site enterprise will recognise as "production-ready" today.

Ubiquiti now publishes an official NDAA page (help.ui.com) that states verbatim: "Most UniFi products comply with NDAA standards, but it is important to verify each product's specific specifications." Translation: NDAA compliance is per-SKU, not brand-wide. There is no consolidated compliance matrix - integrators have to walk every techspecs.ui.com product page to confirm. Compare to Axis (per-SKU NDAA badges) or Avigilon / Verkada (brand-wide attestation), and the procurement workload is heavier on UniFi. See NDAA Section 889 for ring-fencing patterns and migration paths. TetherX itself is software-only and Five-Eyes-jurisdictional (UK-registered, AU operations), with no Section 889 covered-entity exposure - and supports an NDAA-compliant mix of Axis, Hanwha, i-PRO, Bosch and Avigilon cameras at full feature.

The honest comparison set is not just UniFi Protect. The decision typically lands between (a) staying on Protect, (b) moving to a closed-ecosystem cloud like Verkada or Rhombus, (c) moving to an open cloud like Eagle Eye / Brivo or TetherX. Closed ecosystems lock the customer into the vendor's cameras with a rip-and-replace cost on lapse. TetherX keeps the existing fleet (Ubiquiti and otherwise) and gives the integrator the channel margin instead of selling around them. See the best VSaaS providers shortlist for the full open-vs-closed split.

Ubiquiti pays the relay POP egress out of their AWS bill - and they keep it survivable by silently capping every off-LAN stream to the substream, not by capping you in writing.

The relay infrastructure is Ubiquiti-operated. cloudaccess.svc.ubnt.com resolves to around 2,970 IPs on Amazon CloudFront, UDM Pro debug logs put the control plane in AWS us-west-2 on AWS IoT topics, and the data plane is whatever CloudFront POP is closest to the viewer. CloudFront egress lists at roughly USD $80-$120 per TB at retail tiers. Naively, "10 sites x 8 cameras x 4 Mbps x 24/7" works out to around 10 TB per day of relay egress per customer, which would run a low-five-figures USD monthly AWS bill per heavy user. That is not what's happening - and there are three reasons why.

1. STUN-brokered P2P first, relay only as a fallback. The NVR holds an outbound socket to AWS; when a viewer opens a camera, AWS introduces the two endpoints and the media flows peer-to-peer over a UDP hole-punch. Ubiquiti pays the signalling cost (cheap) but not the media bytes (expensive). Users posting their firewall logs on r/Ubiquiti regularly see the NVR start uploading to a residential IP the instant they open the Protect app - that's the hole-punch in action. The relay only carries the media bytes when symmetric NAT or strict outbound firewalls defeat STUN, which is most enterprise networks but very few homes.

2. The substream cap is the bandwidth ceiling. When the path does fall back to the relay, Ubiquiti forces the off-LAN viewer onto the camera's H.264 "preview" substream rather than the main archive bitstream. The in-product banner says it in plain English: "A local connection helps reduce latency and maximize resolution during your viewing sessions." A substream is typically 480p-720p at 500 Kbps - 1 Mbps; the archive stream is 4-8 Mbps. So the "10 sites x 24/7" workload is closer to 10 x 8 x 0.5 Mbps = around 40 Mbps of relay throughput, not the headline 320 Mbps. At sub-$1 per camera per month in CloudFront egress, that's economically sustainable. Ubiquiti never has to publish a byte quota because the codec choice does the rationing for them.

3. The ToS catch-all backstops the maths. Ubiquiti's May 2024 Terms of Service reserve the right to "terminate or suspend your access to or right to use all or part of the services without notice... if Ubiquiti determines, in its sole and absolute discretion, that you... have engaged in any conduct otherwise harmful to the interests of Ubiquiti." There is no published "fair use" byte ceiling, no MB/GB language, no per-account quota - just a unilateral kill option for any account whose relay traffic becomes unprofitable. No public IPVM, Reddit, or community.ui.com thread surfaces a confirmed throttling or cut-off event, which suggests the substream cap is effective enough that few consumers ever hit the wall.

4. Client-side caps further bound the relay. Vantage Point (the only first-party multi-NVR SOC tool) caps at 5 NVRs per workspace. Multi-view caps at 16 streams in the iOS app and 26 streams on web/Android. So even a 7,000-site bank with 100 SOC operators is structurally limited to 100 x around 20 active streams x around 500 Kbps = around 1 Gbps of relay throughput, not the headline 7,000 x 24/7 number. And that customer would not be on Cloud Access anyway - the named integrator population running Protect at >1,000-camera control-room scale has publicly moved to a different VMS for exactly this workload - u/corsalove, a Ubiquiti installer himself, says outright on r/UnifiProtect that Protect is not the correct software for a 1,000+ camera control room and his team runs a different VMS for the monitoring layer.

Where this leaves the SOC / multi-site buyer. The "no fees, ever" claim is technically true: Ubiquiti is not invoicing the customer for the relay. But the off-LAN viewing experience that comes with it is fundamentally a low-bitrate preview, not the recording; the only documented multi-NVR SOC tool caps at 5 NVRs; and the service is governed by a unilateral kill clause rather than a contracted bandwidth commitment. There is zero published IPVM coverage of a named Protect SOC deployment and zero Ubiquiti case study of a named ARC customer - the absence is itself the answer. Verkada, Rhombus and Eagle Eye take the opposite shape: camera or bridge uploads continuously to the vendor cloud, cloud is the canonical source for every viewer, multi-viewer fan-out is paid for once on the site-to-cloud upload, archive-quality is the only quality, and the bandwidth cost is explicit on the camera licence. TetherX sits in between: a TetherBox at the site brokers, and the customer chooses per camera which streams stay LAN-only (zero ongoing cost), which become cloud-resident at archive quality (priced explicitly per camera), and which use the cloud only as failover. No silent quality cap, no client-side keep-alive cliff, no sole-discretion suspension. Choosing the architecture is the point.

Yes. 30-day free trial through an integrator partner with a TetherBox, full platform access, can run alongside an existing UniFi Protect install for direct comparison. Extensions on request.
COMPANY HISTORY

Ubiquiti: prosumer networking giant, security VMS as an OS app

Ubiquiti Inc. was founded in October 2003 in San Jose, California by Robert J. Pera (ex-Apple Wi-Fi engineer). Headquartered today in New York City. Listed on the NYSE under ticker UI (legally renamed from Ubiquiti Networks Inc. and transitioned from NASDAQ: UBNT on 19 August 2019). FY2025 (year ended 30 June 2025): revenue US$2.57B, net income US$712M, 1,667 employees (SEC 10-K, mirrored on Wikipedia).

UniFi Protect is one of seven apps inside the UniFi suite (Network, Protect, Access, Talk, Drive, InnerSpace, Identity), all running on UniFi OS. It is not sold as standalone software - it ships pre-loaded on every Protect-capable console and is activated by adopting a UniFi camera. The product replaced UniFi Video (Windows / Linux installable, EOL January 2021) and intentionally narrowed the deployment surface to Ubiquiti hardware.

Manufacturing is split across Vietnam, Taiwan and China (community-confirmed across multiple r/Ubiquiti and r/UnifiProtect threads). Vietnam and Taiwan are the structural NDAA-compliance anchors; the China share is why Section 889 status must be checked per-SKU.

Public-record events relevant to procurement diligence: a 2014 OFAC US$504,225 Iran sanctions fine, and a 2015 US$46.7M BEC loss disclosure. The DOJ indicted insider Nickolas Sharp in December 2021, and he was convicted of extortion in February 2023. Ubiquiti filed a defamation suit against Krebs in March 2022, resolved outside court that September.

More recently: in February 2024 the DOJ disrupted Russian Military Unit 26165 (Fancy Bear) running on compromised Ubiquiti EdgeOS routers. A January 2026 Hunterbrook investigation documented Ubiquiti products in Russian military supply chains, and Pussy Riot protested at the NYC HQ in March 2026. None are operational defects in Protect itself, but together they shape the procurement conversation.

Glassdoor 3.5 / 5 (303 reviews, May 2026): CEO Robert J. Pera 71% approval, work / life balance 3.0, culture 3.2 - below the IT industry 3.9 average, with recurring themes "fast-paced", "chaotic", "lack of transparency", "shunning culture" balanced against "good compensation", "interesting projects", "startup mentality". The manufacturer's site is the authoritative source for current product status.

Free comparison PDF

Not ready to talk? Take the comparison with you.

A one-page open cloud VMS versus locked-platform breakdown: what you keep, what you cut, what it costs. We will email it over, usually the same working day.

Please complete the verification.

No sales call; your details stay with us. We route serious enquiries through accredited local TetherX installers.

Want this at your site?

Get a quote from a certified TetherX installer. We will match you with a local partner who knows your area and your needs.

Certified Installers
Local to You
No Obligation
Prefer to browse partners first? See our partner directory →

Still have questions about multi-site, MSP console or NDAA compliance?

Try TetherX free for 30 days

Run TetherX alongside an existing UniFi Protect install. Trial extensions on request.

Start Free Trial

Across the partner network

TetherX partners hold the accreditations security-procurement buyers and insurers filter on. Coverage varies by partner.

NSI 9 ISO 9001 7 SSAIB 5 SafeContractor 5 BAFE 4 CHAS 4 ConstructionLine 4 Cyber Essentials 3 NICEIC 2 ISO 14001 2 ISO 27001 1

Counts reflect partners currently in the TetherX directory holding each accreditation.

Anything wrong on the UniFi Protect comparison?

Flag an inaccuracy, an outdated fact, or a missing nuance on the UniFi Protect page. We update the per-vendor pages and the /compare hub from this inbox - real reply, real human.

Please tell us what to call you.
Please enter your email address.
Please tell us what to fix or add.
Please complete the verification.

We reply within 1 business day. No newsletter, no follow-up sequence.

[1] About this comparison. Information about other vendors is drawn from their public product pages, datasheets, integrator forums (Reddit, vendor user groups), public CVE databases (NVD, CISA), publicly-listed LinkedIn company pages (headcount, headquarters, founding year, leadership transitions and corporate ownership signals) and customer conversations - accurate to the best of our knowledge as of Q2 2026. Pricing, features, security posture and policies change. A vendor may have shipped a fix, dropped a price, added a region or changed an architecture since this page was last reviewed.

If you believe anything here is inaccurate or out of date, please contact us and we will review and correct it. Trademarks and product names belong to their respective owners and are referenced here for identification only.

30 days free. No card. Talk to a local installer.