Access-control platform credential

Genetec Synergis Credentials Explained: There Is No "Genetec Card"

Genetec Synergis has no proprietary "Genetec card." Synergis is access-control software that encodes and reads a standards-based AES-secured 13.56 MHz smart card, using a Secure Access Module (SAM) and transparent readers so the encryption keys stay inside your building. Because those keys are yours and never leave the site, no third party can produce a working "compatible" Synergis credential.

Last updated 2026-07-29

Is there a "Genetec Synergis card"?

No. Genetec Synergis is the access-control side of Genetec's Security Center platform, and Genetec does not make a proprietary credential of its own. Instead, Synergis reads and encodes standards-based credentials — most commonly an AES-secured 13.56 MHz smart card — and it is the software, controllers, readers, and keys around that card that make the system secure.

This surprises people searching for a "Genetec compatible card," but it is the correct model: Synergis is deliberately open, so a site chooses its own credential technology and keeps control of it. The security question with Synergis is therefore never "which Genetec card do I buy" but "how are my card keys managed" — and Genetec's answer is to keep them inside the building.

How does Genetec Synergis secure credentials?

Genetec Synergis secures credentials by combining a keyed AES smart card with end-to-end encryption from the card all the way to the software. Genetec describes "advanced end-to-end encryption … from credentials to readers … to controllers and software," layered over TLS. In its high-assurance configuration, the card's secret keys are held in a Secure Access Module (SAM) and read through transparent readers, so — in Genetec's words — "decryption happens securely within your building" rather than in a reader that could be pulled off a wall.

Genetec backs this with third-party certification: Synergis and Synergis Cloud Link carry CSPN certification and ANSSI qualification from the French national cybersecurity agency. The high-assurance stack pairs Synergis with transparent reader hardware from STid — the same key-ownership philosophy covered in the STid Architect & SECard guide.

What is a SAM, and how do keys stay in your building?

A SAM (Secure Access Module) is a tamper-resistant secure element that stores your card's AES keys and performs the authentication, so the secret keys never sit in an exposed reader or travel across the network. In the Synergis high-assurance stack, the transparent reader simply relays the encrypted conversation, and the SAM behind it — inside the secured building — does the decryption and verification.

The benefit is that pulling a reader off the wall yields nothing useful: it holds no keys to extract. This is the mechanism that keeps a Synergis credential clone-resistant, and it is explored in more depth in the companion guide, Genetec Synergis & the SAM: how card keys stay in your building.

Is OSDP automatically secure on Synergis?

No — OSDP is only secure on Synergis if Secure Channel is enabled and default keys are changed. Genetec is explicit about this in its own guidance on legacy access control, warning that "OSDP is still vulnerable if the secure channel isn't enabled or if default keys are used." The same blog details how legacy credentials fall to card cloning, skimming, and relay attacks "similar to those used in car theft," and how unencrypted Wiegand wiring can be tapped.

Synergis supports both OSDP and SSCP for the reader-to-controller link, so a site can run an authenticated, AES-encrypted connection end to end. But the protocol alone is not the protection — Genetec's stated best practice is to enable Secure Channel and replace default keys, and to "prefer standard over proprietary" cryptography.

What is in the Genetec Synergis high-assurance stack?

The Genetec Synergis high-assurance stack is a defined set of layers, each securing a different part of the path from card to software. Understanding which layer does what explains why there is no single "Genetec card" to buy — security is a property of the whole chain, anchored by keys held in the building.

LayerComponentWhat it secures
SoftwareSecurity Center / SynergisAccess decisions and audit; TLS to controllers
ControllerSynergis Cloud Link + Secure I/OEncrypted controller comms; CSPN / ANSSI qualified
ReaderTransparent readers (STid)Relay encrypted card data; hold no keys
Key custodySAM (Secure Access Module)Store the AES keys inside your building
CredentialAES-secured 13.56 MHz smart cardPer-card diversified AES keys

Where to source Synergis-compatible credentials

Because a Synergis credential is a keyed AES smart card whose keys live in your SAM, additional cards must be encoded by your integrator with your keys — there is no legitimate off-the-shelf "Genetec compatible card," and Security ID Systems does not offer one. For the reader-agnostic view of which credentials Synergis can ride, see the companion guide, Genetec Synergis: reader-agnostic credentials and the SAM.

Where we do help is the migration layer. Many Synergis sites still read 125 kHz proximity or a plain card serial number (CSN) on older doors and multi-technology readers. Those open and UID-based formats we supply as fully compatible, encoded credentials.

Compatible formats we do supply

Synergis has no proprietary card, and its keyed AES credentials must be encoded by your integrator using your in-building keys. Where Synergis still reads 125 kHz proximity or a plain card serial number, these open formats are ones we supply as fully compatible credentials.

Sources & references

Genetec and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Genetec Synergis — common questions

Is there a Genetec Synergis card?

No. Genetec Synergis is access-control software with no proprietary credential. It reads standards-based cards, most often an AES-secured 13.56 MHz smart card, and encodes them with your keys. Security comes from the software, controllers, readers, and key management, not from a special Genetec card.

What credential does Genetec recommend for secure access?

Genetec recommends a keyed AES-secured 13.56 MHz smart card read through transparent readers, with the card keys held in a SAM inside the building. Genetec's guidance also stresses enabling OSDP Secure Channel, changing default keys, and preferring standard over proprietary cryptography.

Is OSDP secure by default on Synergis?

No. Genetec warns that "OSDP is still vulnerable if the secure channel isn't enabled or if default keys are used." Synergis supports OSDP and SSCP, but the link is only protected once Secure Channel is turned on and the default keys are replaced with site-specific ones.

How does Genetec keep card keys safe?

In the Synergis high-assurance stack, the AES keys sit in a Secure Access Module (SAM) inside the building and the transparent readers hold no keys. Decryption happens within your premises, and Synergis plus Synergis Cloud Link carry CSPN certification and ANSSI qualification.

Can I buy a compatible Genetec Synergis card from a third party?

No. Synergis credentials are keyed AES smart cards whose keys never leave your SAM, so no third party can produce a working duplicate. Additional cards must be encoded by your integrator. Security ID Systems supplies the legacy prox and CSN formats a Synergis site may still read.