The comparison is usually framed as a technology choice, and it mostly is not. Both arrangements send the same fax to the same machine over the same network. What differs is who operates the thing, where documents come to rest, and which failures land on your desk at eight in the morning.
What is actually being compared
On premise means a fax server, or a set of machines, running in your environment. You own the hardware or the virtual machine, the software licenses, the connection to the telephone network, the configuration, the patching and the backups. Whether that connection is analog lines, a T1, or a SIP trunk changes the details, not the ownership.
A service means the same functions operated by someone else, reached over the internet. You keep the numbers and the workflows. You hand over the operation.
What you keep when you run it yourself
Control is the honest argument for on premise, and it is not a weak one.
- Documents need not leave your network, which simplifies some conversations considerably.
- Integration with internal systems can be direct, without anything crossing a boundary.
- Retention and deletion are configured by you, in a place you already audit.
- There is no third party in the path to assess, contract with or re-assess.
For an organization with an established fax server, staff who understand it and a policy environment that makes external handling awkward, that is a coherent position. The mistake is holding it by default rather than by decision.
What you hand over
The operational load is the real subject, and it is chronically underestimated because most of it is invisible when things are working.
- Keeping the telephony connection alive, and diagnosing it when a carrier changes something.
- Patching the server, and the operating system under it.
- Capacity at peaks, which for many organizations are seasonal and sharp.
- Being the person who understands it, and being available when you are not.
That last point is the one that decides more migrations than any technical factor. Fax servers are frequently maintained by one person who has been there a long time. The arrangement is stable until it is suddenly not, and the knowledge is rarely written down.
Where documents rest
This is the question worth spending time on, because it is the one with obligations attached.
On premise, received documents land somewhere in your environment, and the retention policy is whatever you configured, or whatever the default was. With a service, documents pass through the provider and may rest there for a configurable period.
Neither arrangement is inherently more compliant. What matters is that the answer is known and matches your obligations. The HIPAA Security Rule is instructive here: 45 CFR 164.312 sets standards including audit controls and transmission security, and marks encryption and decryption as addressable rather than required, precisely because the right arrangement depends on the environment. It expects you to have made and recorded a judgment, not to have bought a particular product. Our page on electronic fax and HIPAA compliance works through what that means.
What fails, and who fixes it
Both arrangements fail. The difference is the shape of the failure and who is awake for it.
On premise, failures are usually infrastructure: a line, a disk, a certificate, a patch that did not go as planned. They are yours, they happen on your schedule, and you can go and look.
With a service, failures are usually somebody else's, which is more comfortable until it is less: you are dependent on their status reporting and their timeline. What you get in exchange is that the common failures stop being events at all. A busy destination is retried without anyone noticing.
NIST SP 800-53 is a useful lens here, particularly its Audit and Accountability control family. Whichever arrangement you choose, the question is the same: when something goes wrong, what record exists, who can read it, and how long is it kept.
The hybrid that usually is not one
Organizations frequently describe their arrangement as hybrid, and on inspection it is often a migration that stopped. A service handles most traffic, one department still has a machine because a workflow was never moved, and the analog line for that machine is still being paid for.
There are genuine reasons to keep a local device: a machine attached to equipment that will not talk to anything else, or a location where connectivity is unreliable enough that a phone line is the more dependable path. Those are worth keeping deliberately. What is worth avoiding is a residue that nobody owns, because it carries the full cost of both arrangements and the benefits of neither.
How to decide
Three questions settle it more often than a feature comparison.
- Who currently maintains the fax server, and what happens when they are unavailable? If the honest answer is uncomfortable, that is the finding.
- Is there a policy reason documents must not leave the environment? If yes, it is a real constraint. If it is assumed rather than written, check.
- What does the current arrangement cost, counting the time as well as the lines? The cost discussion sets out what to include.
A note on numbers
Whichever way the decision goes, the fax numbers are the part that constrains the timetable. They are printed on forms in circulation, held in the address books of partner organizations, and written into processes at the other end that you cannot see or change.
Porting them takes as long as it takes, is largely outside your control once submitted, and cannot easily be rushed at the point you have already committed to a date. Start it early, and treat the porting schedule as the project plan rather than as a task within it.
Where to go next
If what you are retiring is a fax server rather than machines, migrating from an on-premise fax server is the harder case and has its own sequence.
If you are leaning towards moving, migrating from fax machines to cloud fax covers the sequence and why number porting sets the pace. For what the LABUSA service provides, see pricing, or tell us what you are working with.
Sources
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. The Audit and Accountability family behind the record questions above.
- 45 CFR 164.312, Technical safeguards, Government Publishing Office. Audit controls, transmission security, and the required or addressable marking on each specification.