Access-control platform credential

Genetec Synergis & the SAM: How Card Keys Stay in Your Building

Genetec Synergis is reader-agnostic: it is not locked to one card brand, and it has no proprietary credential of its own. It secures a keyed AES-secured 13.56 MHz smart card by keeping the encryption keys in a Secure Access Module (SAM) inside your building, and it can also ride partner credentials such as HID or STid. Because the keys never leave the site, a working Synergis credential cannot be sourced from a third party.

Last updated 2026-07-29

Does Genetec Synergis lock you into one card brand?

No — Genetec Synergis is deliberately reader-agnostic and does not lock you into a single card or reader brand. Genetec's stated posture is open architecture with "support for OSDP and SSCP protocols," which lets a site mix reader hardware and choose its own credential technology rather than being tied to a proprietary Genetec card that does not, in fact, exist.

That openness is the point of difference from closed platforms. With Synergis, a site can standardise on a keyed AES-secured 13.56 MHz smart card, keep existing HID credentials, or run STid transparent readers in the high-assurance configuration — all under one Security Center system. The credential is a choice you make and control, not a lock-in the platform imposes.

What is a SAM, and why does "keys in the building" matter?

A SAM (Secure Access Module) is a tamper-resistant secure element that stores your card's AES keys and carries out the cryptographic authentication, so those keys never sit in a wall-mounted reader or cross the network in the clear. In the Genetec Synergis high-assurance stack, transparent readers relay the encrypted exchange while the SAM — inside your secured premises — does the decryption, which Genetec describes as decryption that "happens securely within your building."

Why it matters: in older designs, a reader on the unsecured side of a door could hold the keys needed to read cards, so stealing or opening that reader could threaten the whole credential population. Moving the keys into a SAM behind the door removes that exposure. It is also the reason a Synergis credential is not reproducible by an outsider — the working secret is locked in hardware you own.

Which credentials can Genetec Synergis use?

Genetec Synergis can use a spectrum of credentials, from legacy formats read only by their serial number up to fully keyed AES smart cards — which is exactly why it can support a gradual migration. The table below shows the common options and which ones a third party can legitimately supply.

Credential typeHow Synergis uses itThird-party compatible?
Legacy 125 kHz proximityRead via multi-technology readers during migrationYes — open format we supply
Card serial number (CSN / UID)Read the unencrypted serial as an identifierYes — passthrough card we supply
AES-secured 13.56 MHz smart cardEncoded with your keys, held in the SAMNo — issued via your integrator
HID iCLASS / SeosRidden as a partner credentialNo — via the HID channel

What do CSPN certification and ANSSI qualification mean for Synergis?

CSPN certification and ANSSI qualification are French national-cybersecurity-agency assessments, and Genetec holds them for Synergis and Synergis Cloud Link. CSPN (Certification de Sécurité de Premier Niveau) is a first-level security certification based on independent evaluation, and ANSSI qualification is the French state's recommendation of a product for use in sensitive environments.

For a buyer, these are third-party evidence that Synergis's encryption and key-handling have been independently reviewed rather than merely claimed. Combined with the in-building SAM and end-to-end encryption, they explain why Genetec positions Synergis for high-assurance deployments — and why the credential's strength depends on the certified system around it, not on any special card.

How do I add or replace Synergis credentials?

To add or replace a keyed Synergis credential, your integrator encodes new cards with your keys through your SAM — there is no off-the-shelf "Genetec compatible card," because the working secret never leaves your building. For the full component-by-component view of the high-assurance stack, see the canonical guide, Genetec Synergis credentials explained.

Security ID Systems supplies the open layer instead: the 125 kHz proximity cards and card-serial-number (CSN) credentials that Synergis multi-technology readers still accept on legacy and transitional doors. Those we encode as fully compatible credentials that read identically on your existing readers.

Compatible formats we do supply

Keyed Synergis credentials are encoded by your integrator using your in-building SAM keys. Where Synergis readers still accept 125 kHz proximity or a plain card serial number, these open formats are ones we supply as fully compatible credentials.

Sources & references

Genetec and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Genetec Synergis — common questions

Is Genetec Synergis locked to one card brand?

No. Synergis is reader-agnostic and open, supporting OSDP and SSCP and running credentials from multiple vendors under one Security Center system. It has no proprietary Genetec card; a site chooses and controls its own credential technology.

What is a SAM in a Genetec Synergis system?

A SAM (Secure Access Module) is a tamper-resistant secure element that stores your card's AES keys and performs authentication inside the building. Transparent readers hold no keys, so decryption happens on your secured premises and a stolen reader yields nothing useful.

What credentials work with Genetec Synergis?

Synergis can read legacy 125 kHz proximity and card serial numbers during migration, keyed AES-secured 13.56 MHz smart cards encoded through your SAM, and partner credentials such as HID iCLASS or Seos. Only the open prox and CSN formats can be supplied by a third party.

What does ANSSI qualification mean for Synergis?

ANSSI qualification is the French national cybersecurity agency's recommendation of a product for sensitive use, and Genetec holds it, plus CSPN certification, for Synergis and Synergis Cloud Link. It is independent evidence that the system's security has been formally evaluated.

Can I get replacement Genetec Synergis cards from a supplier?

Keyed AES Synergis cards must be encoded by your integrator through your SAM, so no supplier can provide a working drop-in. Security ID Systems supplies the 125 kHz proximity and CSN passthrough credentials that Synergis multi-technology readers still accept.