Domains assessed end to end
%
Identified critical issues resolved in post
Track remediation model
As access control systems become increasingly connected to IT networks, databases, mobile applications, video platforms and third-party systems, cybersecurity is now an essential part of physical security design. To ensure GuardPoint10 continues to meet the security expectations of modern deployments, Sensor Access carried out a full assessment covering the platform from source code through to a live customer-style installation, with a focus on reproducible, real-world vulnerabilities rather than theoretical risks.
Testing covered eight key areas of the GuardPoint10 environment:
- Application source code
- GuardPoint10 server and third-party API
- Operator desktop client
- Windows services and file permissions
- SQL Server database
- Network communications and TLS encryption
- Third-party software libraries
- Version-control history

This end-to-end approach allowed the assessment to consider how the individual components interact as part of a complete access control deployment.
Industry-standard tools were used for source-code analysis, dependency scanning, API testing, desktop-client review, Windows service auditing, database assessment, encryption testing and secret detection. A Software Bill of Materials was also generated to provide visibility of the third-party components used within the platform.
Critical findings resolved within the product
All critical-severity issues identified during the assessment have been resolved directly within the GuardPoint10 code.
Improvements introduced as part of the remediation work include:
- Reduced privileges for GuardPoint10 Windows services
- Stronger protection of application files and configuration directories
- Improved authentication and token validation
- Certificate verification between GuardPoint10 components
- Modern TLS encryption for system communications
- Updated third-party libraries
- Hardened installation defaults
- Improved SQL login auditing and password-policy enforcement
- Code signing for application binaries
These changes are incorporated into the GuardPoint10 installer, meaning customers receive the relevant product-level improvements when upgrading without needing to implement each correction manually.
Clear guidance for production deployments
Cybersecurity also depends on how a system is designed, configured and maintained within the customer’s environment.
For this reason, Sensor Access has adopted a two-track remediation model. Product-level matters are corrected within the GuardPoint10 software, while environment-specific decisions are addressed through a companion hardening guide.
The guide provides practical recommendations covering areas such as:
- Least-privilege SQL account configuration
- Data-at-rest encryption using technologies such as TDE or BitLocker
- Application allowlisting through AppLocker or Windows Defender Application Control
- Backup and recovery planning
- Optional network-layer encryption using IPsec
This gives consultants, installers and end users a documented route from an installer-default configuration towards a production-grade deployment suited to the individual building and its security requirements.
Where this leaves GP10
All critical-severity issues identified in this assessment have been resolved in code, closing the realistic "first-day" attack paths we found. Remaining items are scheduled for an upcoming release or documented as customer-configurable hardening. A Software Bill of Materials is generated on penetration test; the assessment is designed to be reproducible and is re-run against new releases, and an independent external penetration test is planned to validate these results.
Critical Paths Closed
All critical-severity findings identified were resolved in the product code.
Guided Hardening
The Companion Hardening Guide helps take an install towards production grade.
Self-Service Hardening
Customers can follow the guide themselves with clear, plain English, steps
Continuously Verified
The toolchain is re-run against new releases of GuardPoint10.
Ships by Default
Customers receive the fixes automatically on upgrade, no action needed.
External Validation Planned
An independent penetration test will confirm the results
Detailed technical findings are managed in accordance with Sensor Access Technology’s responsible-disclosure policy and may be shared with customers where appropriate.
To discuss GuardPoint10 cybersecurity, system design or deployment requirements, contact Sensor Access Technology at sales@sensoraccesscontrol.com or call +44 (0)1273 242 355.
