Skip to content
For IT and CIOs

Architecture, cybersecurity and integration

An entry system is a security element inside your network, and IT rightly asks what deployment does to security. Here is the answer: a separate network, a local database, nothing exposed to the internet — and an open API.

Architecture

One application server, a dedicated network

The whole solution layer runs on the PSA platform application server: web administration, an MQTT bus for kiosks and peripherals, a local database and a booking server for pre-registrations. The components talk to each other on a dedicated network.

There are two deployments depending on who holds the perimeter: on-premise in your DMZ behind a firewall you manage — or a physically separate supplier network with its own connectivity where you do not want the system in your corporate network at all.

Decisions are made locally: a connectivity outage means remote administration and web pre-registration are unavailable, not a closed gate. Passages by plates and cards keep running.

Core principles

  • No component reachable from the internet
  • Local, non-exposed database
  • A dedicated network segment (DMZ / VLAN)
  • Service access only through a VPN
  • Local decisions independent of connectivity
Cybersecurity

Designed along NIS2 principles

The system controls physical entry to the site, so we treat it as a security element. Segmentation into a dedicated network blocks an attacker’s lateral movement; MQTT traffic must not leave its segment and booking data from the public portal flows in through an encrypted tunnel, not direct access.

Voice authorisation of entry has its own protection: the kiosk GSM module can only make outgoing calls and the voice channel is physically separated from the data network, so it cannot be used as a path into your LAN. Every manual passage approval has an audit record.

The SECAPRO REMOTE CARE remote monitoring communicates strictly outbound over an encrypted, mutually authenticated connection — no public IP address, no open ports, no firewall changes. It is a design aligned with NIS2 principles, not a certificate — the operator meets the directive, and we supply technology that makes it easier.

Security measures

  • Segmentation, MQTT confined to its own segment
  • An encrypted tunnel for booking data
  • GSM outgoing only, separated from the LAN
  • An audit trail of every intervention
  • Monitoring via outbound connection only
Integration

An open interface, not a sealed box

The integrations we build most often. Dock scheduling itself is handled by the Logistics module; the full list is on the System integration page.

Attendance and ACS

A turnstile passage is written into attendance; with a third-party access system we exchange identities, cards and permissions over an interface.

ERP and WMS

Notifications and delivery data drive whom the gatehouse expects. Nobody retypes reference numbers by hand.

Weighbridges and TMS

Weighing tied to a specific passage and delivery note; carriers handed over to the time-slot system.

M2M API

Reporting an entry from a third-party gate, querying permission by plate, controlling a passage. Secured with an API key and a JWT token.

We never promise an integration blind: before it appears in a quote, we want to see the other side’s interface documentation and know who owns it on your side. If no interface exists, we say so straight away and propose another route — such as a scheduled import instead of a live link.
Frequently asked questions

What IT asks most often

Where does the software run and where is the data?

Per your IT policy: on a server in your network, in the kiosk, or in our dedicated infrastructure. In the standard deployment the database is local and not exposed to the internet.

How do you handle remote service access?

Strictly over a secured VPN, never open ports. Remote interventions of the monitoring service use named access and leave an audit record — who, when and what they did.

What do you need from us for an integration?

Which system and version you run, whether it has a documented interface, who owns it, what data should flow which way and how often. Interface development is a separate line item, not hidden in the price.

What are the system’s network requirements?

The overview of ports and services is on the PSA platform page; the complete segmentation diagram comes with the project phase. Document readers at the gatehouse present themselves as keyboards — no driver installs.

Can we run without depending on the cloud?

Yes, the standard deployment is on-premise with local decisions. The cloud is not a condition of operation — only the public pre-registration runs outside and sends data in through an encrypted tunnel.

Want to discuss the architecture with our engineers?

Send us your IT team’s questions — topology, segmentation, interfaces. We will come back with specific answers, not marketing.