Volume 120
Volume 120 | November 3, 2025
Click on the above image and use code sxst3gkbkn to hear the audio version.
Reminder to JOIN the The PhySec Collective community Slack channel to network, engage, and be part of something big! You can sign up here.

Before reading on in, I recommend giving the Acquired episode on Visaa listen. It deeply influenced how I approached this Brief and frankly, it’s a masterclass in storytelling. (It’s also very long so maybe read and listen in parallel).
This Brief has been forming in the in-between moments, on planes, in hotels, between meetings. It finally clicked for me in a “green room” conversation at the Brivo and Eagle Eye Cloud Security Summit. The topic was familiar: open systems, the bullshit surrounding it, and how “it is never going to happen with the traditional industry.” It was another conversation circling around how much our industry talks about openness but rarely delivers it. Someone commented, “It’s not like Genetec is ever going to let Brivo integrate into their system.”
That struck me (again). I replied in so many words, “Exactly, but unlike in the past, that kind of control no longer defines the market. The value is shifting and so is where it pools. It is why many in our industry are declining, even when growing.”
This conversation crystallized what this Brief is about and got me to finish it.
Our industry is on the verge of its Visa and Stripe moment. I truly believe it and although it may have been brewing for awhile or tried by others, now is the time. The flow of value is moving away from control and toward networks, usability, and speed. Two companies I highlight here are simply examples, but there are many others capable of leading this shift or trying to do it. Whether it’s AccessGrid (I do think they are solving for a similar but different problem), Alert Enterprise (trying to solve many problems right now), Any2Any (definitely doing this in Europe), Bearing (solving for a similar but doing it on a specifc platform), Sharry (could do this as its core), SoloInsight (I think they are more of a systems integrator though), CoreWillSoft (solving for a different problem), IDCube (solving for a different problem), Oloid(solving for a different problem), or even the incumbent players like Allegion, ASSA ABLOY (more specifically HID), and dormakaba(especially LEGIC), someone(s) will solve it. It could also come from outside our ecosystem entirely.
What I am 100% sure of is this: we need the network, usability, and speed problem solved. When it is, it will mark the turning point. It will mark the inflection that ushers in mainstream change and unlocks the $100B opportunity ahead…just like it did in finance.
Physical Security needs Access Control

In physical security, PhySec, access control isn’t just a product category or just a function. Access control is a foundational utility in the physical environment. It’s quietly gone mainstream, hidden within a cottage industry. Everyone interacts with it, and when we move beyond its original value prop of keeping bad people out, locking, and unlocking ($10B), its value becomes exponential ($100B). Access control is inherently sticky, exists in every physical space, and delivers measurable value by making environments safer, more efficient, and with endless opportunities as it goes digital. More importantly, it is the one area of our industry that holds the power in security to go from behind-the-scenes function to a mainstream force for awareness, experience, and trust.
Full stop: access control is the single solution that can shape all of security. I may be biased here, but I do believe it to be true.
Sorry, video, it ain’t you.
For decades, the physical access control industry has been defined by silos: hardware-centric systems, proprietary integrations, and bespoke projects that connect one building or organization at a time. Every integration is a one-off. Expensive. Returning low value for amount of effort. Every credentialing workflow is slightly different. Every innovation must climb the same wall of interoperability before it can scale, if it can scale at all (which it doesn’t).
This is why the access control needs its own Visa and Stripe moment.
To see why, first let’s talk about how the financial industry solved similar problems decades ago.

The “Network of Trust”
Visa did not start as a payment giant. It began as Bank of America’s BankAmericard program in the 1950s, designed to allow consumers to carry revolving credit. When the concept proved too big for one bank to manage, Bank of America opened the system to other banks. Over time, this network of issuers and acquirers evolved into Visa: a shared infrastructure connecting consumers, merchants, and financial institutions.
Visa didn’t lend money or issue cards. It provided the rails: the authorization, clearing, and settlement technology that allowed money to move securely between parties that didn’t know or trust each other. Its genius was in becoming a neutral platform that everyone could plug into. It connected everything.
That neutrality built scale. As more banks and merchants joined the network, its value increased for consumers. The more consumers used it, the greater the incentive became for merchants to accept it. That feedback loop created one of the most powerful network effects in history.
Visa’s business model was also simple: charge a small fee per transaction. As global commerce exploded, so did Visa’s volume. Today, it processes more than 250 billion transactions annually. The company’s product is not credit: it’s trust at scale.
The structure of Visa’s network also solved a critical coordination problem. It established shared standards for identity, data formats, and security protocols, enabling participants to build upon a stable foundation. Each bank could differentiate through its card products, marketing, or rewards, but they didn’t have to reinvent how payments moved between systems. Visa handled that.
In essence, Visa became the connective tissue of modern commerce: invisible, indispensable, and immensely valuable.

The “Developer Layer”
If Visa built the payment network, Stripe made it usable.
Founded in 2010, Stripe recognized that while Visa and Mastercard handled the backend plumbing, integrating payments into an online product was still complex. Developers had to navigate gateways, banks, acquirers, and local regulations. Stripe abstracted all of that into a set of clean APIs.
With a few lines of code, any developer could accept a payment, manage subscriptions, detect fraud, and send payouts…all through Stripe. It democratized the ability to participate in digital commerce.
Stripe doesn’t replace Visa. It builds upon it, simplifying access to the network and extending its capabilities. It’s a developer-facing business that transforms infrastructure into a product.
That model, a neutral network plus developer platform, has transformed the global economy.
It’s also exactly what access control is missing.
The analogy here is “Access as a Transaction”
Access control, at its core, is a transaction system. Instead of moving money, it moves permissions and people (notice, stopping people is a form of moving people, but we need to recognize that letting the right people in is the mainstream motion. Keeping people out is the cottage). When someone presents a credential, whether it's a card, a phone, or a biometric, the system authorizes or denies access. It’s the physical equivalent of a payment authorization.
Today, this happens within isolated systems: one manufacturer’s readers, one software stack, one building. Integrations are hard-coded and brittle. They are isolated and siloed. Credentials issued in one system rarely work elsewhere (there is an entire network of identity integrators cleaning up the slop of systems that don’t work together). Identity providers, HR databases, and tenant apps each rebuild the same logic, creating endless friction. Over and over and over again. It is why we don’t see many hockey stick growth companies.
Imagine if every merchant had to build their own credit card network. That’s the current state of access control.
A “Visa for access” would provide a neutral, trusted network that connects identity providers, building systems, credential issuers, and devices. It would standardize how access permissions are issued, validated, and revoked across systems. A “Stripe for access” would expose developer-friendly APIs and SDKs, allowing any app to provision, manage, or revoke credentials without worrying about the underlying hardware.
The Visa layer provides trust and interoperability. The Stripe layer provides usability and speed. Together, they create a foundation for innovation.
They are already here, and more are on the way.
To provide some context to the discussion, I would like to highlight two companies that I believe are doing just this. Note, like I said above, they are not the only ones. They are just the two clearest examples to me of two companies that are trying to solve for both of these two functions. I believe our industry needs to meet the mainstream market where it is. I also want to highlight them as examples because they are two of the most misunderstood companies when it comes to people explaining to me what they do and the value they bring. I also want to use them as concrete examples because too many newer companies in our industry that are solving real problems or doing the work to grease the skids for our industry mainstream moment define their business based off of yesterday’s terminology and business models (I’m looking at you Soloinsight, Genea, and Sharry) that I hope to show that we need companies being who they are solving for what they solve so we can have all the nice things ahead.
We need it. You need it. We all need it (well, at least those that aren’t threatened by the opportunity at our doorstep).
Here’s how SwiftConnect (even if their website doesn’t articulate this) and Seam are good examples solving for the Visa and Stripe moment of our industry:
SwiftConnect calls itself the “leading identity and access network for the physical world.” Its AccessCloud platform connects identity providers, access control systems, mobile wallets, and devices through a unified backbone. It allows a user’s corporate credentials to sync automatically with a building’s physical access system. It is removing the manual provisioning that has plagued property managers and enterprises for years.
SwiftConnect’s model looks a lot like Visa’s. It doesn’t issue credentials itself; it connects issuers and verifiers. It aims to be a neutral network that sits between corporate directories, tenant apps, and physical access systems. Its integrations with Apple Wallet and Android NFC suggest a move toward standardization, not proprietary lock-in.
The opportunity here is scale. The more buildings, tenants, and identity systems that connect, the more valuable the network becomes. Each new integration expands the utility for all participants. If executed well, SwiftConnect could evolve into the default “access rail” the same way Visa became the default payment rail.
Of course, challenges remain. Reliability and uptime are existential concerns. We are a safety product: doors must open even if the cloud is down. Governance, data privacy, and business model alignment across owners, tenants, and integrators are all complex. Plus, and most importantly, we are a people business and they need to figure out how how to build consensus and action around it. But the architecture points in the right direction: interoperability as a service.
If SwiftConnect is trying to build the Visa of access, Seam is trying to be the Stripe.
Seam offers a unified API and SDK that enables developers to control locks, readers, and access systems from various vendors through a single interface. It is not a new, but they are different (you need to visit their SF office and meet with Sy and team) and timing may be right. Instead of integrating separately with Salto, Allegion, ASSA ABLOY, or other systems, a developer can call Seam’s API to issue a credential, revoke access, or check status.
For enterprises with their own development resources or coworking platforms, hotels, or proptech startups, that abstraction is invaluable. It eliminates months of integration work, allowing teams to focus on user experience instead of wiring diagrams. Seam’s documentation resembles Stripe’s: simple, modular, and developer-centric.
By transforming fragmented hardware ecosystems into software primitives, Seam enables the embedding of access functionality anywhere, including tenant apps, visitor management systems, logistics platforms, and even consumer experiences.
That’s what Stripe did for payments.
The big question for Seam is scale. Can it become the default SDK for physical access, much like Stripe has become for online payments? Success will depend also on reliability, security, and the breadth of integrations that can be achieved. Sounds familiar. Plus, I hope they don’t get bored with doing plumbing. However, the concept of a universal API for the physical world, although not new (I see you, RemoteLock), is powerful.
Why this moment matters and is important for the industry.
Again, this is about the moment, not a specific company. If access control had a Visa and a Stripe, everything in the ecosystem could move faster, and we could have all the nice things.
-
For building owners: simpler onboarding for tenants and service providers. Operator dream. Downstream user experience amazingness.
-
For enterprises: unified identity across physical and digital systems. High security and user experience.
-
For developers: the ability to innovate without dealing with proprietary SDKs. So many new ideas.
-
For users: frictionless, secure, mobile-first access experiences. Again, amazing user experiences.
It would also open entirely new business models. Access events could be monetized per use, analyzed for operational insight, or combined with digital services. Space-as-a-service, coworking, and flexible real estate all depend on this kind of interoperability. It may be one of the things that saves the real estate industry.
The access control industry has spent decades perfecting the mechanics of locking and unlocking doors. It’s been the best at keeping bad people out. The next decade (or possibly three) will be about connecting the physical world through those doors into a trusted, programmable network.
Visa proved that trust can be scaled through shared standards. Stripe proved that infrastructure can be democratized through APIs.
SwiftConnect, Seam, and others like them worldwide are demonstrating what happens when these ideas intersect with the physical world and you don’t let the existing mindsets or business formations get in the way of what’s needed.
The question for the rest of the industry is simple: are we done with the silos, or will we join the network and let the chips fall where they may?
I’m ready.
PS: I am sure some of you may forward this, but please do so sparingly and encourage others to sign up here. Thank you!

