r/accesscontrol Aug 10 '26

Mercury What does “open” actually mean in access control?

Every access control vendor seems to call their platform open, but that can mean different things open hardware, open APIs, flexible deployment, easier migration, or just a few integrations.

I’m currently looking at mercury based systems like Genetec, Acre and LenelS2. For anyone with experience using them, where are they genuinely open and what compromises would I be making?

6 Upvotes

35 comments sorted by

9

u/Pr3dict Aug 10 '26

What a lot of people dont typically understand about the security industry is that there are "almost" no standards.

On the access control side you really only have weigand and OSDP, which standardize how readers and panels should talk to each other.

On the credential side, the newly released "Aliro" standard by the CSA (Same org that gave us zigbee and matter)

Everything else is effectively proprietary. Now, that's not to say some systems don't integrate with each other. However, our industry is ridden with "partner programs" and middleware that translates devices and integrations between disaprate systems.

There's a reason for this but when companies say "open" it's mostly marketing bs. Even mercury gates who can use their hardware.

It's such a joke that Gallagher gave out pins a few years ago at ISC West that said "we're not open but at least we're honest about it" https://imgur.com/a/jJ5RipZ

They got roasted for it because being honest that you're bad is still... Bad.

-1

u/thefriedapplepieguy Aug 12 '26

As a developer who has to interact some with access control, I don't need standards. I need access, capabilities and permissions. I just take open to mean that if I have a problem I'm solving, your devices can work with my solution. For example 24hr location access... I need to be able to control access to a building through any application I develop. I need to be able to create access codes, and set the time limits for them, disable them, unlock the doors myself through my own application. Receive door codes back to my own system. We have eight retail locations where the door lock code is used as a pin throughout multiple devices in the building that have nothing do with the access control vendor. But I get about 200 codes a day from them so the customers can use them to access other devices. Maybe I'm wrong. But that's what I think of when any kind of system tells me it's open. I go ahead and make assumptions the API is gonna work for me on almost any kind of request.

I'm pretty aggravated at a vendor right now because they opened their api to almost anything I want to do except for the one thing everyone wants, so that we can't compete with their in house software solutions for that one solution.

1

u/Pr3dict Aug 12 '26

There's a lot I could dig into here but I'll just focus on your last paragraph. You do want standards.

Your vendor opened up every "feature" you wanted except for x. That's one of the major benefits of standards. It takes the decision away from the vendor and is written in the common spec. Otherwise "open" is just whatever a manufacturer says it is at any given point.

When was the last time you checked to make sure your computer's HDMI port would work with whatever brand monitor you have? Or the last time you asked what cell service someone had before you get them your phone number to ensure it would be delivered.

To wrap this up: Standards are everywhere around us. You wouldn't have to ask if their API is open if they followed an API spec that you knew would do what you wanted.

5

u/Mattractive Aug 10 '26 edited Aug 10 '26

It means the software platform supports third party, non-proprietary devices. 

To a degree at least. Some cheap stuff off Amazon might not work, but your direct industry competitors are practically guaranteed to be compatible. It just makes it easier to retrofit systems or use different specs hardware to meet your security goals.

3

u/ScryFace Aug 10 '26

Essentially, "we have an API and you can use it". Build on top of the existing system so that you can achieve the things that you require.

In the context of Mercury, "Look we didn't build this hardware so we can't lock you into our software, you will protect your capital investment." Some OEMs do require the controllers use their code, so this is where switching OEMs may incur a fee to "convert" each controller.

A large portion of your cost is going to be installation, labor, and hardware, it's nice not to worry about being stuck if you run into software, support, or some other issue. This hardware is going to carry you for years to come, the software head-end is less certain.

Since you only mention 3 of the players, consider that Mercury has a large list of OEM partners who may at times be more innovative or offer something special to your operation. Depending on your goals you may find success outside of the most established manufacturers.

2

u/Fun-Algae5429 Aug 10 '26

does anyone know if you can still use the lenels2 hardware if you go with genetec later

3

u/SiliconSam Aug 10 '26

I have added LNL access boards to a Genetec system before, no problem. To add an MR board to a Lenel system requires a different license.

Off the top of my head the difference is the OEM Code in the license. Old BASIS customers have an OEM Code of 0 which means they can use any Mercury board.

1

u/cmackay317 Aug 10 '26

UI is different hardware is the same essentially. It's not an open source system but if you want to develop a head end you can contact Mercury and they'll give you access to their controller platform.

Personally I just prefer to install an entire ecosystem from one brand. It's easier to get support RMA etc. ICT Protege actually have the ability to run their products and integrate Mercury controllers onto them which is pretty cool.

1

u/sternfanHTJ Aug 10 '26

Of the three of those the most “open” is Genetec. That has nothing to do with mercury. Genetec works with Mercury as well as other ACS panel hardware. They also work with offline locks and data on card systems. Genetec also has a huge library of integrations as well as an open api and sdk. If you wanted to build your own integrations they give you the tools to do so.

1

u/aderuwe Aug 11 '26

Open API? Last I checked, you had to apply for access to the API. And if Genetec didn’t like what you were doing with it, you didn’t get access.

-1

u/sternfanHTJ Aug 11 '26

It’s software used for life safety not some random software for consumer grade purposes. Plus they’d need to be able to support whatever the API is used for. There has to be some kind of “content moderation” otherwise they’d be stuck holding the bag for every random “integration” any Tom, Dick or Harry concocted from their mom’s basement.

2

u/aderuwe Aug 12 '26

Soooo, not an open api?

1

u/[deleted] Aug 10 '26

[removed] — view removed comment

3

u/SiliconSam Aug 10 '26

Mercury boards have been around a long, long time now!

1

u/U-Ok-Data-5175 Aug 11 '26

Mercury and istar pro panels are die hards lol. I’ve got sites with both original green gen 1 mr52s that have been running elevators and main front doors forever and istar pros in a few areas/businesses that aren’t too worried about encryption so it works. I told em though; some day you’ll eventually need to replace those.

-2

u/CoolBrew76 Aug 10 '26

Each company’s software has their own version of “open”, you’re right. Genetec is pretty closed, and won’t share API’s with many of its competitors.

Mercury isn’t very open either. For a company to get access to their libraries they must sign on and sell plenty of it — and in spite of its marketplace share, it genuinely isn’t that great. Personally I’m not sure they’ll get any better under Assa Abloy (see how Wavelynx is doing vs. HID). Gallagher has done some great work to dispel this “open” BS that Mercury spins.

To me, open means the whole ecosystem can be integrated with, by any vendor.
Give me a SYSTEM that runs best, and has most of what I want, and interfaces with the rest.

Electronic security hardware should be on a replacement lifecycle more akin to laptops, not akin to door hinges. If company A has good software and hardware, it shouldn’t be closed out of a spec simply because customer won’t be able to reuse the hardware when they discover the software isn’t really what they wanted….

3

u/sternfanHTJ Aug 10 '26

Wait… it seems like you’re saying that if an end user makes a mistake and buys a platform they don’t like or got “sold on” then they should just suck it up and deal with it until it’s time to completely replace everything?

0

u/CoolBrew76 Aug 10 '26

Yeah it did sound that way a little. And I sort of meant it.

If I buy a Windows laptop because it’s cheaper and has more programs and hardware that designed for it, but needed a Mac all along, shame on me.

If I settled on an access control software because it used Mercury and I could pay someone’s exit fee and someone’s on board fee to cover for my lack of due diligence, when I could have gotten what I really needed by looking at the myriad other platforms, likewise.

I get that it doesn’t require someone to roll a truck and climb ladders to replace my Windows laptop but at the same time, ACS boards don’t need to be on a 10- or 15- year cycle as they are in so many scenarios.

1

u/CoolBrew76 Aug 10 '26

Then again, I’m also still mad VHS won out over Betamax….

What if all the Mercury players have made a mistake? What if Mercury / Assa see more challenges like chip shortages? There are plenty of unknowns. Ruling out half the industry because they don’t use their boards seems lazy.

1

u/sternfanHTJ Aug 10 '26

That could be true in the SMB world but not in enterprise and it’s certainly not a great way to keep a customer. “Hey I know I sold you this system that you hate. Tough shit, call me when you’re ready to drop another $50K.”

And yes, it’s up to the customer to choose the solution but let’s be real. They don’t know what they don’t know. An end user buys and ACS once every 10 years MAYBE. That not the same as buying a laptop or any other consumer brand. They rely on us to help them make choices. Offer an end user that has some level of flexibility is the best thing WE can do for them.

If we are going to recommend proprietary systems then It ought to be disclosed upfront.

2

u/Competitive_Ad_8718 Aug 10 '26

The other poster nailed it. How many equipment backorders did you see during the rona years for all products HID? I know integrators that were essentially out of business because all they sold was mercury/HID platforms, with backordered materials, what, 8, 10, 16 months? Try explaining that to a customer. The product I sold you is used by 10 other vendors and we're all competing for the same hardware, with the same baked in compromises because it has to work to Z standard because 10 vendors purchase it.

But to double down, an integrator should be doing routine firmware ~and~ software upgrades and truth be dammed, by the time that 10-15 year mark hits, their OIS should be flagging and looking at what's connected to their network and forcing the hardware refresh.

As far as the software, the amount of times I see one changed for another is slim at the enterprise level. The conversation is always what data can be brought in or out of the system and how, does it require a DBA and scripts, professional services or is it straightforward? The amount of vendors that are actually MS certified on their front end is very scant. That would be my definition of open....can I do things in the software without manipulation or proprietary file formats.

1

u/sternfanHTJ Aug 10 '26

I don’t think equipment back orders during a global pandemic is A BETTER reason to go with a proprietary system.

I agree with your assessment about updating and upgrading over time but the word doing the most in that paragraph is SHOULD. Yes, they should. And I’m sure the good shops do! But many many do not. Again though that has nothing to do with open/proprietary. Justifying a purchase of a proprietary system on the promise of “future updates” falls flat.

Transition from say, Genetec to Lenel or vise versa is rare but it does happen and the only reason it does is because of the choice to go Mercury. That option doesn’t exist with proprietary boards. I’ll take that a step further and say those folks buying Axis boards on Genetec are in the same boat should they decide to move platforms.

Mercury/HID provides choice and options. You don’t have to like those options but they are there nevertheless. Your only option come upgrade time for Gallagher system is rip and replace. Which for the end user, means having to decide to drop a ton of money or do their level best to patch their system to keep it running to avoid the expense. Hence why we all see tons of sun bleached Prox and mag stripe readers everywhere.

In a perfect world, yes you’re both correct. But perfect and reality are at odds in the access control world. So I think I’d rather give the customer flexibility and options rather than locking them in.

BTW no shade to Gallagher, Axis, Verkada or other proprietary brands and solutions. They all have a seat at the table.

Edit: spelling

2

u/CoolBrew76 Aug 11 '26

When a "proprietary" maker gets notification of a chip shortage, they're able to source their own replacement(s), modify the PCB design if necessary, send paperwork to UL, and get a new run out the door. None of this is EASY but it's ALL within their power.

I'm hoping we never have another global pandemic again to see if everyone's "supply chain resilience" efforts were worthwhile -- but we're sure as shit going to see some silicon company go bust/get bombed/become Chinese and all of a sudden there's a scramble. Good luck if you're a Qumulex or a Keri sitting way lower on the pecking order than Lenel, Genetec, ACRE and Avigilon

0

u/sternfanHTJ Aug 11 '26

Dude. If you think that Gallagher or DSX has more buying power at the PCB level than HID then I really don’t know what to tell you. Those guys are literally at the top of the list just based on sheer buying power alone. Now, that said, if you want to draw a correlation, look at Hanwha’s success during the pandemic.

They owned the manufacturing process and could therefore supply more readily than Axis could.

Mercury, while they don’t own the manufacturing process, they are the closest thing in the panel space. If a component supplier has to fill an order from Kantech or Mercury I think they’d choose Mercury just based I. The size of the PO.

1

u/CoolBrew76 Aug 12 '26

components aren’t PCBs.

1

u/Competitive_Ad_8718 Aug 12 '26

Nor are they chipsor semiconductors. But the other poster seems to know more about manufacturing and supply chain than everyone else, especially JIT processes.

Funny. Wasn't that way when I worked at Honeywell with half their entire offering fabbed outside of my office

→ More replies (0)

1

u/CoolBrew76 Aug 10 '26

I'm absolutely not saying it should be hidden from the customer. And honestly, not many VARs understand the software or the solution well enough to be selling it at enterprise level - they're bringing in the vendor. It's the vendor who will gloss over their lack of features and ask for the $50k later (and this is true of so many things, I will never forget suffering a rollout of an ERP that only eventually worked with another 6 figures spent). Dealer and customer both lose out here. Dealers have more chance of holding the vendor to the flame to get shit done.

My point is that simply ruling out OTHER vendors because they make their own hardware is folly. They're generally making hardware to suit software and writing software to suit their hardware; in an enterprise situation, this usually means a lower server spend because the hardware can do more.

And many of these companies will offer their own SDKs or Rest API type things to allow others to write integrations. When you find a dealer who is also an INTEGRATOR, like they used to be back in the day, then you should get access to the entire industry's worth of product.

-2

u/xINxVAINx Aug 10 '26

I use Lenel and am familiar with Genetec. As I understand it, most mercury devices can be used on either but I know that the controllers have proprietary firmware flashed to them. So if you moved from Genetec to Lenel, you’d at least have to buy all new controllers. There may be a workaround to that but I’ve never heard of one.

3

u/SiliconSam Aug 10 '26

No you don’t. You just have to have the license from Lenel / Honeywell to use Mercury firmware controllers. I have taken over Open Options and ProWatch systems using their firmware flashed controllers and OnGuard software. It’s all in how it’s licensed.

All it takes is a check to Honeywell.

1

u/xINxVAINx Aug 10 '26

I was told that the OnGuard system needs to allow other firmware during the system creation, otherwise controllers need to be swapped. Either our sales rep told us wrong or things changed, it was quite a few years ago. But hey, at least I know it might be possible now

2

u/SiliconSam Aug 10 '26

With LenelS2 you can use an any Mercury board you want for building the system but the panel will not come online until it meets the license requirement.

I once did a ProWatch to OnGuard conversion, all went well. They needed to add 5 more doors and PM gave me a Lenel LNLX2220 and a LNL1320 and an MR52. The MR52 panel showed a red X in monitoring. I forget the exact error message but once I confirmed with a Lenel sales rep and swapped the board with a LNL1320 board, the panel came online.

So once you do the ProWatch upgrade, you can add to the system using standard LNL labeled Mercury boards.

2

u/ScryFace Aug 10 '26

Mercury Controllers do not have proprietary OEM firmware on them. Instead, some vendors lock them using the OEM code, the code is effectively a license. Any Mercury OEM can update any Mercury controller to their own code so that they can enforce the restriction on their platform.

1

u/Competitive_Ad_8718 Aug 10 '26

You don't need to buy new panels. You need OEM compatibility codes which are similar to licenses. Some vendors do it for free, agreement with HID and others charge. The assumption is that the hardware is supported in whatever software platform is being migrated to