WestPoint · Access · HID
This isn't a platform. It sits underneath them.
HID is not the software you see: it is the controller in the cabinet, the reader on the wall and the card in your pocket. Knowing which board you have fitted changes what it costs to change system, and it is the first thing we ask.
What it is, and why it is not like the others.
In this list almost everything is a platform: software with its screen, its users and its log. HID is the layer underneath, and it does three things: controllers —the device in the cabinet that decides whether that door opens—, readers and credentials. It belongs to the ASSA ABLOY group, the same one Aperio comes from.
And here is the fact that changes whole conversations: Mercury is the controller that several of the platforms on this same list use underneath. Different software manufacturers fit the same family of boards, with their own firmware and their own label. What is in your cabinet may be the same as what is in someone else's with a different system.
That is not trivia. It means that changing platform is not always throwing away the hardware: sometimes it is changing the firmware and the licence of the board already fitted, and carrying on with the same cabling, readers and cabinets. Sometimes. But the difference can be half the budget.
What that means in your cabinet.
With the caveats, which are what make the advice worth anything.
The route exists because the board is the same, but the firmware and the licence are tied to the manufacturer who sold it to you: going from one to another usually means reprogramming the board and licensing it again. It is done. It is not improvised.
There are generations, and that is where the filter is. The oldest ones have no route left: out of support, without the modern encrypted reader protocol, and the honest thing is to change them. The way to know is to open the cabinet and read what is printed on the board. We do that on the first visit, with a photo.
There are also door modules hanging off the controller, which are reused more easily. And there is Aero, the manufacturer's own line: for installations that do not need the structure of the big ones, and for anyone who wants the open reader protocol from day one.
The conclusion is awkward for whoever is selling: before you choose a platform, find out what hardware you have.
The card, the cable and who holds the keys.
Three things almost nobody looks at, and they decide whether the system protects anything.
The first is the card. A good part of the installed base in Spain uses old technologies that are copied with a device costing less than a day's food: you hold it near a card in a pocket, it is cloned and it opens. And the most widespread format is short —255 site codes and a little over sixty thousand numbers— so overlaps between neighbouring installations are not a hypothesis.
The second is the reader cable. The classic protocol joining reader and controller runs in the clear and unauthenticated: a device hidden behind the reader captures credentials and then replays them. The replacement —the open protocol with an encrypted channel— is spoken by modern readers, but you have to ask for it to be switched on: it can be installed without it.
And the third, the important one: whose the encryption keys for your cards are. A modern card is only secure if the key that opens it is yours and nobody else's. If the installer uses the same set for all their clients, your cards open somebody else's door and theirs open yours. Ask for your own set and for it to be in your hands: whoever holds the keys is in charge of the installation.
Origo: the credential on the phone.
It solves a real problem and opens another conversation.
Origo is the credential-on-the-phone part: a cloud service from which a phone's credential is issued and withdrawn, and which can be carried in the company's own app or in the phone's wallet. It changes the gesture: giving access goes from handing over a card to sending an invitation, and removing it goes from chasing the card to withdrawing it remotely.
What you gain: a phone is not lent out so cheerfully, it does not stay in a drawer at home, and when somebody leaves there is nothing to get back. It shows most with people who visit several sites, and with contractors.
What to look at first: it is paid for per credential and per period, so it goes into every year's budget and not into the works budget, and you need readers that accept it. And there is a personal-phone conversation to have with HR: what gets installed on somebody's phone, and what alternative there is for anyone who does not want to use their own to get in to work. You have to have that alternative, and it is usually a card — also because a phone runs out of battery.
Who it fits, and who it doesn't.
- It fits if you want the controller and the credential not to tie you to one software manufacturer. That is the reason to choose this layer on purpose.
- It fits if you have several sites with different platforms and you want a single credential for whoever moves between them.
- It fits if the project is long and phased: hardware and credential today, software later. That is the right order and almost nobody follows it.
- It fits if you have to migrate from an insecure card without stopping work: readers that read the old and the new are the way through.
- It does not fit if you are expecting a screen: there is no system to administer here, and you still have to choose the platform on top.
- Origo does not fit if there are no company phones and there is resistance to using personal ones: you can mix, but then you are managing two credentials.
What we do with it.
- The inventory with the cabinet open: which controller, which generation, which modules, which readers and which card. With photos and in writing, on the first visit.
- The honest verdict on what can be reused and what cannot, with the reason. Saying everything gets changed is easier to quote and more expensive for you.
- The credential plan: which card you move to, how it lives alongside the old one and with what cut-off date. Coexistence with no end date is not a plan.
- Key management as a named deliverable: the client's own key set, who holds it and where the copy is. This gets signed.
- If Origo is in: a trial with a small group, an issuing and withdrawal procedure, and the alternative for anyone not using a phone sorted out before it is announced to the workforce.
- The maintenance with controller and reader firmware inside it: the first thing to be dropped and the thing that matters most here.
Who configures it after us.
Here the answer is different, because what gets administered is in two places.
Adding and removing people, the schedules and the permissions by zone are not run from here, but from the platform on top. There the answer is that platform's answer, and in almost all of them it is yes: the security team or the IT team runs it, with the right training.
What is the client's in this layer, from day one, is issuing credentials on the phone. Inviting, reissuing and withdrawing is done from a browser: there is no sense in calling an installer to give access to somebody who starts tomorrow. The same goes for encoding cards.
What they should not touch: the controller firmware, the reader configuration, switching on the encrypted channel and, above all, the card keys. The keys being theirs does not mean handling them every day: it means any future supplier can work with them without asking us for anything.
For them to really be able to, you need: training on the credential console for whoever is going to issue, an onboarding and offboarding procedure that fits the one HR uses, the hardware inventory with its generations, and the key custody certificate. Those four things, and not a three-hundred-page manual.
Migrating: here it is almost all the work.
The migrations in this layer are three, and they usually go together. From insecure card to encrypted, with readers that read both while the reissue lasts. From cable in the clear to an encrypted channel, which is sometimes configuration and sometimes changing the reader. And from platform, reusing the controller where you can.
The order matters. The inventory first. Then the credential, which affects the whole workforce and sets the calendar. The software last. Doing it the other way round is what produces those projects where the whole system is changed and the clonable cards from fifteen years ago are still in use.
And one thing we say even when it is uncomfortable: if the inventory comes out badly —generations out of support, old cards, cable in the clear— the project is bigger than you have been told. Better to know that on the first visit.
Other platforms we work with.
This layer sits underneath a platform, and you still have to choose the platform. These are some of the ones we work with.
Get started
Do you know what's in your cabinet?
If you don't, it is the most profitable question you can ask before asking for a quotation. Tell us what system you have and what card you use, and we will tell you what can be reused and what cannot.