Does Genetec Synergis lock you into one card brand?
No — Genetec Synergis is deliberately reader-agnostic and does not lock you into a single card or reader brand. Genetec's stated posture is open architecture with "support for OSDP and SSCP protocols," which lets a site mix reader hardware and choose its own credential technology rather than being tied to a proprietary Genetec card that does not, in fact, exist.
That openness is the point of difference from closed platforms. With Synergis, a site can standardise on a keyed AES-secured 13.56 MHz smart card, keep existing HID credentials, or run STid transparent readers in the high-assurance configuration — all under one Security Center system. The credential is a choice you make and control, not a lock-in the platform imposes.
What is a SAM, and why does "keys in the building" matter?
A SAM (Secure Access Module) is a tamper-resistant secure element that stores your card's AES keys and carries out the cryptographic authentication, so those keys never sit in a wall-mounted reader or cross the network in the clear. In the Genetec Synergis high-assurance stack, transparent readers relay the encrypted exchange while the SAM — inside your secured premises — does the decryption, which Genetec describes as decryption that "happens securely within your building."
Why it matters: in older designs, a reader on the unsecured side of a door could hold the keys needed to read cards, so stealing or opening that reader could threaten the whole credential population. Moving the keys into a SAM behind the door removes that exposure. It is also the reason a Synergis credential is not reproducible by an outsider — the working secret is locked in hardware you own.
Which credentials can Genetec Synergis use?
Genetec Synergis can use a spectrum of credentials, from legacy formats read only by their serial number up to fully keyed AES smart cards — which is exactly why it can support a gradual migration. The table below shows the common options and which ones a third party can legitimately supply.
| Credential type | How Synergis uses it | Third-party compatible? |
|---|---|---|
| Legacy 125 kHz proximity | Read via multi-technology readers during migration | Yes — open format we supply |
| Card serial number (CSN / UID) | Read the unencrypted serial as an identifier | Yes — passthrough card we supply |
| AES-secured 13.56 MHz smart card | Encoded with your keys, held in the SAM | No — issued via your integrator |
| HID iCLASS / Seos | Ridden as a partner credential | No — via the HID channel |
What do CSPN certification and ANSSI qualification mean for Synergis?
CSPN certification and ANSSI qualification are French national-cybersecurity-agency assessments, and Genetec holds them for Synergis and Synergis Cloud Link. CSPN (Certification de Sécurité de Premier Niveau) is a first-level security certification based on independent evaluation, and ANSSI qualification is the French state's recommendation of a product for use in sensitive environments.
For a buyer, these are third-party evidence that Synergis's encryption and key-handling have been independently reviewed rather than merely claimed. Combined with the in-building SAM and end-to-end encryption, they explain why Genetec positions Synergis for high-assurance deployments — and why the credential's strength depends on the certified system around it, not on any special card.
How do I add or replace Synergis credentials?
To add or replace a keyed Synergis credential, your integrator encodes new cards with your keys through your SAM — there is no off-the-shelf "Genetec compatible card," because the working secret never leaves your building. For the full component-by-component view of the high-assurance stack, see the canonical guide, Genetec Synergis credentials explained.
Security ID Systems supplies the open layer instead: the 125 kHz proximity cards and card-serial-number (CSN) credentials that Synergis multi-technology readers still accept on legacy and transitional doors. Those we encode as fully compatible credentials that read identically on your existing readers.
Compatible formats we do supply
Keyed Synergis credentials are encoded by your integrator using your in-building SAM keys. Where Synergis readers still accept 125 kHz proximity or a plain card serial number, these open formats are ones we supply as fully compatible credentials.
Sources & references
- Genetec — Synergis (open architecture, OSDP & SSCP, end-to-end encryption, CSPN/ANSSI)
- Genetec — Synergis high-assurance access control (SAM, transparent readers, keys in the building)
- Genetec — Cyber risks of a legacy access-control system (OSDP default-key and cloning warnings)
- STid — transparent reader hardware used in the Synergis high-assurance stack
Genetec and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.