Security Security, for the IT lead
Safe by design. Explained like a human. The page to send the IT lead.
Access control usually comes with a 40-page security PDF written by a lawyer to scare other lawyers. This is the opposite: five things Bolt does to keep your building safe, and straight answers to the questions we actually get asked.
Five things Bolt does to keep a building safe, and straight answers to the questions your customer will ask, so the sign-off doesn’t stall on you.
Or write to security@boltaccess.co.uk. A person reads it.
Need your data kept on your own network? Bolt can also run on-premises, on request.
If you only read five things, read these. Five things to tell the IT lead.
Secure at the door, in the cloud, and everywhere in between. Each one with the line to use when they ask.
-
Encrypted on every hop
Nothing Bolt says travels in plain text.
Every connection, from your laptop to the cloud and from the cloud to the controller in the wall, runs over TLS. The wireless mesh between controllers is encrypted too. Anyone listening hears static.
In other words: The padlock on your bank’s website, on every conversation inside Bolt.
For you: No VPN, no firewall holes on the customer’s network. Tell the IT lead it all goes out over TLS.
-
Every command signed
A forged instruction never opens a door.
When Bolt tells a door to unlock, the message carries a cryptographic signature covering what to do and which door to do it to. The controller checks it before it obeys. Altered in transit, or sent by someone pretending to be Bolt: rejected.
In other words: A signed cheque. The bank only pays out if the signature is real.
For you: A forged unlock is rejected by the controller itself, not by a server you have to secure.
-
Only our firmware runs
Updates are checked before they’re installed.
Every firmware update is signed by us. The controller verifies the signature before it installs anything, and refuses to roll back to an older version.
In other words: A sealed parcel that the controller won’t open unless the seal is ours.
For you: Firmware updates come with the licence, signed, and can’t be rolled back to an older version.
-
Doors decide locally
An outage doesn’t open your building, or lock it.
Each controller holds its own rules. If the internet goes, or our cloud does, doors keep letting the right people in and keeping everyone else out. Nothing about access depends on a live connection to us.
In other words: A key that still works when the phone lines are down.
For you: An outage at our end isn’t a call-out at yours. The doors carry on.
-
Your data stays in the UK
No quiet trips across the Atlantic.
Bolt is hosted in the UK, with the database in London. Who came in, which door, and when stays here in normal operation. We act as your data processor and sign a DPA that describes what we actually do.
In other words: Your records are kept in London, not in a warehouse in Virginia.
For you: One answer for the procurement form: UK hosting, database in London, DPA signed.
-
Found something?
Email security@boltaccess.co.uk. A person reads it and replies.
The questions every procurement team asks. The questions your customer will ask you.
Answered here, so you don’t wait for an email.Answered here, so you’re not the one improvising.
- “What if someone hacks your servers and opens all our doors?”
- The controller in your wall won’t act on an unlock that isn’t signed, and it makes access decisions locally. Taking over a server doesn’t hand anyone a master key.
- “What if someone deletes everything?”
- Every change is logged, timestamped and tied to the person who made it. Backups run nightly, are stored off-site and are kept for 90 days.
- “What happens if a controller is stolen off the wall?”
- Remove it in the app and the rest of your system stops trusting it. Then talk to your installer about the doors it ran, the same as you would a lost master key.
- “Can someone clone one of our cards?”
- Bolt.Reader reads MIFARE DESFire, which uses AES encryption. The cheap 125 kHz cards that can be copied in the car park with a gadget off the internet aren’t something we sell.
- “What if the authorities want our data?”
- We only hand data over under valid UK legal process, and we tell you, the data controller, unless the law stops us.
- “What if Bolt goes under?”
- Controllers keep working offline for everyone already enrolled. Your data is yours, and we’ll hand it over in a format you can take elsewhere.
We’d rather be honest than pretend.
Some accreditations we’re in the middle of. Some we haven’t started. Here’s the state of play, updated as it moves.
| UK GDPR | Processor We act as your data processor and sign a DPA with you. |
|---|---|
| Cyber Essentials | In progress Under way. We’ll update this line when it’s done. |
| ISO 27001 | On the roadmap Not started. We won’t claim it until we hold it. |
| SOC 2 | Not planned We’re UK-first. If customers need it, we’ll look again. |
| Reporting a problem | Open Email security@boltaccess.co.uk. A person reads it and replies. |
Bring your awkward questions.
Book a call with the people who built it. Bring your IT lead, your procurement checklist and your worst-case scenario.
Bring your customer’s IT lead, their procurement checklist and their worst-case scenario. You get the people who built it.