Visit us at Apartmentalized 2026 in New Orleans, Booth.

Security you can verify, not just read about.

EntryOne builds access control hardware and the cloud platform behind it, for corporate campuses, secure facilities, institutions, and residential communities alike. This page shows the certifications we hold, the controls that run every day, and the terms under which we handle your data.

Certifications and compliance

Each item below is either independently examined or verifiable against the published standard. Status is updated as attestations are issued.

SOC 2AICPA Trust Services Criteria

The EntryOne cloud platform and supporting controls are examined by Prescient Security, a licensed CPA firm, against the Trust Services Criteria for Security. The Type 1 examination (as of September 15, 2026) is in fieldwork; the Type 2 observation period follows immediately. The report is available to customers and prospects under NDA once issued.

Type 1 in progress
NDAA Section 889National Defense Authorization Act

EntryOne readers, controllers, kiosks, and cameras contain no components from telecommunications or video-surveillance manufacturers prohibited under Section 889.

Compliant
TAATrade Agreements Act, 19 U.S.C. §2501–2581

Products are manufactured or substantially transformed in the United States or in TAA-designated countries, making them eligible for U.S. federal procurement.

Compliant
FCC Part 15Federal Communications Commission

Wireless components (Bluetooth, Wi-Fi, NFC) are tested and certified to operate without harmful interference.

Certified
UL 294Access Control System Units

EntryOne hardware is designed to the UL 294 standard for life-safety and fire-code acceptance by authorities having jurisdiction. Listing is in progress.

Certification pending

Need a compliance letter or the SOC 2 report?

Procurement and IT security teams can request our NDAA and TAA declarations, SOC 2 status letter, or the SOC 2 report under NDA at privacy@entryone.com.

How we protect your data

Certifications describe a moment in time. These are the controls that run continuously on the EntryOne platform, and the part of the SOC 2 control set each one satisfies.

Serverless by design

The EntryOne cloud runs entirely on AWS serverless services. There are no servers to patch and no shared hosts, and a dedicated regional environment can be deployed for data residency.

System architecture

Encryption in transit and at rest

Devices, apps, and portals communicate over TLS 1.2 or later. Databases, object storage, and backups are encrypted with AWS KMS keys that rotate automatically.

Data protection

Least-privilege access

Every employee and administrator uses multi-factor authentication. The AWS root account is protected by hardware security keys. Permissions are granted by role and reviewed on a schedule.

Logical access

Continuous monitoring

Amazon GuardDuty threat detection, tamper-evident audit logging with AWS CloudTrail, and automated configuration monitoring alert our team to anomalies around the clock.

System monitoring

Vulnerability management

Application dependencies are scanned continuously and high-severity findings are fixed within defined service levels. Devices receive signed firmware updates through the platform.

Change and vulnerability management

Resilience at the door

Production data stores take daily automated backups with point-in-time recovery. Edge devices keep doors operating with local fallback behavior when the network is unavailable.

Availability and recovery

Customer-owned data

The organization that operates a facility decides what credential, event, plate, and face data is collected, and may shorten how long it is kept within the limits EntryOne enforces. EntryOne processes that data only to deliver the service to that customer, never sells it, and never pools it across customers.

Confidentiality

People and process

Security policies are published and acknowledged by every employee, risk is assessed annually, and incident response is documented and tested.

Governance

License plates, faces, and images: where we draw the line

A plate or a face is a credential that opens the gate or door in front of it, at your facility — nothing more. EntryOne does not run a camera network across customers, does not pool plate or face data across sites or time to track movement, keeps no watchlists, sells nothing, and gives no government agency standing access; records are disclosed only under valid legal process, limited to the records demanded, with notice to the customer where the law allows. From November 1, 2026, plate numbers of vehicles that aren't enrolled are not stored at all, and every image carries a fixed retention limit. Face credentials are moving to verification mode: a face is compared only with the one person who presented a code, card, or phone — never searched against a database. Section 5 of the Privacy Policy is our published usage and privacy policy for this data.

Retention at a glance

EntryOne sets the limits and enforces them. Customers can shorten retention; nobody can keep data forever.

DataRetained for
Access events (credential or enrolled vehicle, device, time, result)365 days
Images and video from readers, gates, and intercoms30 days
Images of vehicles that aren't enrolled7 days, never linked to a plate number
Plate numbers of vehicles that aren't enrolledNever stored
Face templatesLife of the credential; deleted 30 days after revocation or 12 months unused

Limits enforced from November 1, 2026. Per-event legal holds of up to 12 months are available for investigations. Full schedule in Section 6 of the Privacy Policy.

Subprocessors

ProviderPurposeLocation
Amazon Web ServicesCloud hosting, storage, and compute for the EntryOne platformUnited States (us-west-2)
TwilioTelephony and messaging for intercom and notificationsUnited States
MicrosoftIdentity, email, and internal collaborationUnited States

Customers are notified before a new subprocessor that handles customer data is added.

Report a security issue

If you believe you have found a vulnerability in an EntryOne product or service, email security@entryone.com. We acknowledge reports within two business days and do not pursue researchers acting in good faith.

Privacy Policy

Terms of Service