Yes. In most cases we can take over an existing system without replacing the door hardware. We start with a site survey that documents every opening and tells you exactly what stays and what has to change.
The evaluation covers the parts that actually determine cost: door hardware and frame condition, electric strikes and maglocks, power supplies and fire alarm release, controller panels, reader type and wiring, and whether the current software license or hosting can be transferred. Where the head-end is proprietary or abandoned by the manufacturer, we usually reuse the wiring and hardware and swap only controllers and readers.
- Door hardware, strikes, maglocks, request-to-exit devices, and door position switches tested opening by opening
- Controller panels and power supplies checked for capacity, battery condition, and firmware support
- Reader technology identified (125 kHz prox, iCLASS, Seos, OSDP) so credentials can be migrated or reissued
- Existing cabling tested and reused where it passes — we do not quote a rip-and-replace by default
- Cardholder database exported and re-imported so staff keep working through the cutover
For most commercial sites, cloud access control is the better choice. There is no on-site server to patch, back up, or replace, firmware and software updates are applied automatically, and administrators manage doors and users from a browser or phone from anywhere.
On-premise still makes sense in specific cases: facilities with strict no-outbound-connection policies, sites that must keep credential data physically in-building, or large campuses already running a licensed enterprise platform. Both architectures use the same field hardware, so a site can start on-premise and move to cloud later without repulling wire.
- Cloud: no server maintenance, automatic updates, remote lockdown, multi-site management under one login
- On-premise: local database, works through internet outages, fits restricted-network and campus environments
- Either way, controllers keep enforcing schedules and credentials locally if the network drops
A mobile credential is a secure token issued to a phone's wallet or app instead of a plastic card. The phone presents it to a Bluetooth or NFC reader, the reader passes it to the controller, and the door unlocks in the same fraction of a second a card would take.
Practical advantages: credentials are issued and revoked instantly from the admin portal, there is no card stock to buy or badge printer to maintain, and a lost phone is deactivated remotely. Smart readers also support OSDP encrypted communication back to the controller, which closes the cloning and wire-tap gaps that legacy Wiegand prox readers leave open. Most deployments run mobile and cards side by side so contractors and visitors still get a physical badge.
Yes. Access events and video are tied together so every badge read, forced door, and door-held-open alarm is linked to the camera clip that shows what happened.
That linkage is what makes investigations fast: search by cardholder or door instead of scrubbing hours of recorded video. It also supports live verification — when a door is forced at 2 a.m., the monitoring center or your on-call manager sees the associated camera view with the alarm instead of guessing. We integrate access platforms with Digital Watchdog, Hanwha, Turing AI, and UniFi Protect video systems.
Legacy 125 kHz prox systems are upgraded in phases: replace readers and controllers with modern IP equipment first, run both credential types during the transition, then retire the old cards once every user is reissued.
Old prox cards can be copied with an inexpensive cloner, so the security gain from moving to encrypted smart credentials or mobile is immediate. Most existing reader wiring supports the swap, which keeps the cost in hardware and labor rather than in cable pulls and patching. We stage the work door by door so no opening is left unsecured overnight.
- Phase 1: replace controllers and readers, keep existing door hardware and wiring where it tests clean
- Phase 2: issue encrypted smart cards and mobile credentials, run dual credential support
- Phase 3: deactivate legacy prox numbers and hand over documented as-builts and admin training