Is there a "Genetec Synergis card"?
No. Genetec Synergis is the access-control side of Genetec's Security Center platform, and Genetec does not make a proprietary credential of its own. Instead, Synergis reads and encodes standards-based credentials — most commonly an AES-secured 13.56 MHz smart card — and it is the software, controllers, readers, and keys around that card that make the system secure.
This surprises people searching for a "Genetec compatible card," but it is the correct model: Synergis is deliberately open, so a site chooses its own credential technology and keeps control of it. The security question with Synergis is therefore never "which Genetec card do I buy" but "how are my card keys managed" — and Genetec's answer is to keep them inside the building.
How does Genetec Synergis secure credentials?
Genetec Synergis secures credentials by combining a keyed AES smart card with end-to-end encryption from the card all the way to the software. Genetec describes "advanced end-to-end encryption … from credentials to readers … to controllers and software," layered over TLS. In its high-assurance configuration, the card's secret keys are held in a Secure Access Module (SAM) and read through transparent readers, so — in Genetec's words — "decryption happens securely within your building" rather than in a reader that could be pulled off a wall.
Genetec backs this with third-party certification: Synergis and Synergis Cloud Link carry CSPN certification and ANSSI qualification from the French national cybersecurity agency. The high-assurance stack pairs Synergis with transparent reader hardware from STid — the same key-ownership philosophy covered in the STid Architect & SECard guide.
What is a SAM, and how do keys stay in your building?
A SAM (Secure Access Module) is a tamper-resistant secure element that stores your card's AES keys and performs the authentication, so the secret keys never sit in an exposed reader or travel across the network. In the Synergis high-assurance stack, the transparent reader simply relays the encrypted conversation, and the SAM behind it — inside the secured building — does the decryption and verification.
The benefit is that pulling a reader off the wall yields nothing useful: it holds no keys to extract. This is the mechanism that keeps a Synergis credential clone-resistant, and it is explored in more depth in the companion guide, Genetec Synergis & the SAM: how card keys stay in your building.
Is OSDP automatically secure on Synergis?
No — OSDP is only secure on Synergis if Secure Channel is enabled and default keys are changed. Genetec is explicit about this in its own guidance on legacy access control, warning that "OSDP is still vulnerable if the secure channel isn't enabled or if default keys are used." The same blog details how legacy credentials fall to card cloning, skimming, and relay attacks "similar to those used in car theft," and how unencrypted Wiegand wiring can be tapped.
Synergis supports both OSDP and SSCP for the reader-to-controller link, so a site can run an authenticated, AES-encrypted connection end to end. But the protocol alone is not the protection — Genetec's stated best practice is to enable Secure Channel and replace default keys, and to "prefer standard over proprietary" cryptography.
What is in the Genetec Synergis high-assurance stack?
The Genetec Synergis high-assurance stack is a defined set of layers, each securing a different part of the path from card to software. Understanding which layer does what explains why there is no single "Genetec card" to buy — security is a property of the whole chain, anchored by keys held in the building.
| Layer | Component | What it secures |
|---|---|---|
| Software | Security Center / Synergis | Access decisions and audit; TLS to controllers |
| Controller | Synergis Cloud Link + Secure I/O | Encrypted controller comms; CSPN / ANSSI qualified |
| Reader | Transparent readers (STid) | Relay encrypted card data; hold no keys |
| Key custody | SAM (Secure Access Module) | Store the AES keys inside your building |
| Credential | AES-secured 13.56 MHz smart card | Per-card diversified AES keys |
Where to source Synergis-compatible credentials
Because a Synergis credential is a keyed AES smart card whose keys live in your SAM, additional cards must be encoded by your integrator with your keys — there is no legitimate off-the-shelf "Genetec compatible card," and Security ID Systems does not offer one. For the reader-agnostic view of which credentials Synergis can ride, see the companion guide, Genetec Synergis: reader-agnostic credentials and the SAM.
Where we do help is the migration layer. Many Synergis sites still read 125 kHz proximity or a plain card serial number (CSN) on older doors and multi-technology readers. Those open and UID-based formats we supply as fully compatible, encoded credentials.
Compatible formats we do supply
Synergis has no proprietary card, and its keyed AES credentials must be encoded by your integrator using your in-building keys. Where Synergis still reads 125 kHz proximity or a plain card serial number, these open formats are ones we supply as fully compatible credentials.
Sources & references
- Genetec — Synergis high-assurance access control (SAM, transparent readers, keys in the building)
- Genetec — Synergis (end-to-end encryption, CSPN/ANSSI, OSDP & SSCP support)
- Genetec — Cyber risks of a legacy access-control system (cloning, relay, OSDP default-key warning)
- STid — transparent reader / Architect platform used in the high-assurance stack
Genetec and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.