Most card access installed in Canada still runs 125 kHz proximity cards over unencrypted Wiegand wiring. Both were designed before cloning hardware cost thirty dollars. The system logs every entry accurately and stops nobody who has spent an afternoon on the internet.
The card in the employee's wallet is the whole security model. This is the part of an access system vendors are least eager to discuss.
| Credential | Frequency | Security | Verdict |
|---|---|---|---|
| Prox (HID Prox, EM4100) | 125 kHz | None — no encryption, static number | Cloned in seconds. Do not specify. |
| MIFARE Classic | 13.56 MHz | Crypto-1, publicly broken since 2008 | Legacy only. Plan a migration. |
| MIFARE DESFire EV2/EV3 | 13.56 MHz | AES-128, mutual authentication | Current standard for new work. |
| Seos and equivalent | 13.56 MHz | AES, credential-level keys | High-security and multi-site. |
| Mobile (BLE/NFC) | — | Device-bound, revocable instantly | Strong, where phone policy allows. |
Wiegand is a one-way, unencrypted, unsupervised protocol from the 1980s. Anyone who can reach the wiring behind a reader can capture credentials or inject a valid one, and the panel cannot tell that a reader has been removed. OSDP — SIA's open protocol, also published as IEC 60839-11-5 — runs two-way over RS-485 with AES-128 Secure Channel and supervises the reader, so a tampered or disconnected reader raises an alarm. New installations should be OSDP. Existing Wiegand can usually be converted reader by reader rather than all at once.
Fail-safe hardware unlocks when power is lost; fail-secure stays locked. Magnetic locks are inherently fail-safe, electric strikes are usually fail-secure. The choice is not a preference — it is governed by the means-of-egress provisions of the Ontario Building Code and the Fire Code, and electromagnetic locks on egress doors carry specific requirements around release on fire alarm and on loss of power. Have the door schedule reviewed by the authority having jurisdiction before hardware is ordered, not after it is installed.
The deterrent value is real but modest. The operational value is larger and much less discussed: knowing who was in the building at 2 a.m., closing out a terminated employee in thirty seconds across every door and every site, and producing an entry record alongside video when an incident is disputed. Systems specified only against intruders tend to disappoint. Systems specified against disputes tend to pay for themselves.
Specified by pixel density, not by megapixels
Read more →Retention you can actually prove, on hardware built for it
Read more →Alarms that mean something, so someone still answers them
Read more →Protection on day one, before there is power or a fence
Read more →Someone watching, not just something recording
Read more →They work exactly as well for someone standing near your employee in a parking lot. A 125 kHz proximity card broadcasts a static number with no encryption, and copying one takes a cheap handheld and a few seconds of proximity. If the doors matter, the credential is where to spend.
No. Most migrations run in stages — multi-technology readers accept both old and new credentials during the transition, so cards can be reissued over months and doors converted by priority.
Yes, and it is the single most useful integration available. Every badge event, forced door and held door gets the matching clip attached, which turns a log line into evidence and removes a search that otherwise takes an hour.
Each location page covers what is specific to that area — the industrial districts, the site types and the constraints that change the design.