For Law 5651 log retention, the decisive difference between cloud and on-premises is where the data lives and who controls access to it. In the on-prem model, access and traffic records stay on the organization's own servers, while in the cloud model the same records reside on a third-party provider's infrastructure. SignLogger runs fully on-prem: it is installed in the organization's own virtualization environment (VMware/Hyper-V), and the data never leaves the organization's boundaries.
This content is for general information only and is not legal advice. The scope of obligations varies by organization type; consult the legislation and your legal counsel for a binding assessment.
The Core Distinction: Data Residency and Access
Because records under Law 5651 carry evidentiary value, where they are stored is a legal question as much as a technical one. In the on-prem approach, the physical location, backups, and access rights of the records are entirely under the organization's control. In the cloud, part of that control is shared with the provider; which country's data center holds the data, who accesses it, and how the provider handles access requests must each be verified separately.
- Data residency: On-prem keeps data in-house; cloud may place it in a region the provider chooses.
- Access control: On-prem authorization belongs solely to the organization; in the cloud, provider staff may also hold technical access to the infrastructure.
- Privacy: Letting access logs that contain personal data leave the premises adds obligations under data protection law.
- Independence: An on-prem solution is unaffected by internet outages or the termination of a provider contract.
Cloud vs. On-Prem Comparison
| Criterion | On-Prem (SignLogger) | Cloud |
|---|---|---|
| Data location | Organization's own infrastructure | Provider's data center |
| Access rights | Organization only | Organization + provider |
| Internet dependency | None | Constant connection required |
| Log signing | Automatic every day, Kamu SM timestamp + e-signature | Depends on provider |
| Privacy burden | Data never leaves premises | Transfer/contract assessment needed |
| Exit ease | Data already in-house | Migration/format lock-in |
Where Is Record Integrity Established?
Law 5651 compliance requires not only storing records but also being able to prove they were not altered afterward. SignLogger signs the collected logs every day with the timestamp and e-signature of TÜBİTAK Kamu SM, an authorized certificate authority, so that a record's existence on a given date and its integrity can be verified independently. Kamu SM services work on a credit (kontör) basis, so enough credits must be planned for signing. This integrity chain is produced and stored in the organization's own environment in an on-prem deployment; see the Law 5651 log signing solution page for details.
Why Is SignLogger On-Prem?
SignLogger is brand-independent and works with any RADIUS-capable firewall. Because installation happens in the organization's own virtual environment, all data — including hotspot, captive portal, and NAC records — stays on site. This approach preserves data sovereignty and keeps signed records in the organization's hands throughout the retention period. In hotspot scenarios that require authentication, captive portal RADIUS verification is done with PAP; for enterprise wireless, 802.1x/EAP can be preferred.
- Data never leaves the organization; sovereignty is preserved.
- Signed, timestamped records can be presented directly during an audit.
- Works with existing firewall and hotspot management infrastructure.
Frequently Asked Questions
Is storing Law 5651 logs in the cloud prohibited?
The general rule is that records must be retained in a verifiably intact form for the prescribed period; there may be restrictions on storage location that vary by organization type. If the cloud is used, responsibility for data residency, access, and signing must be clarified.
How long must logs be kept in on-prem retention?
The retention period is determined by organization type and is based on the period prescribed in the legislation. SignLogger keeps the records in signed form throughout that period.
How do I prove cloud records were not altered?
Integrity is proven by signing records with a timestamp and e-signature. On-prem, SignLogger produces this every day in the organization's environment with a Kamu SM timestamp and e-signature.
Does SignLogger offer a cloud version?
SignLogger is designed to run on the organization's own infrastructure (VMware/Hyper-V), keeping data on site. This is the preferred model for organizations that prioritize data sovereignty and audit convenience.
Does on-prem logging stop when the internet goes down?
Log collection and storage run locally, so they are unaffected by internet outages. Only the Kamu SM signing step needs online access and is completed once the connection returns.
Can my cloud provider keep my data in another country?
Yes, in the cloud the data may reside in a region the provider selects, which requires additional assessment for privacy and access. The on-prem model removes this risk because the data never leaves the organization.