AWS Smart Building Access Control Case Study for Cloud-Based Physical Security

Ficode developed a secure, cloud-based physical access control solution for a UK-based smart-building platform by integrating Paxton Net2 door reader hardware with AWS-hosted management services. Our team stabilized Windows container deployments, centralized user access management, and enabled secure, scalable door access control through a unified cloud-native platform.

Our client is a UK-based smart-building technology provider delivering cloud-based building management solutions for commercial properties. Their platform enables centralized management of building operations, tenant services, and security systems. To strengthen physical security and simplify access management, the client required a scalable AWS-based solution capable of integrating door access hardware with cloud-hosted user and policy management.

As the platform expanded across multiple commercial buildings, managing physical access securely and efficiently became increasingly complex. The client required a reliable cloud-native solution that could centralize access control, simplify administration, and support future scalability without increasing operational overhead.

The platform’s access-control integration presented several challenges:

  • Paxton Net2 door reader hardware communicates through proprietary libraries that are Windows-native there is no Linux equivalent, and rewriting the integration was not an option.
  • The platform’s cloud deployment ran almost entirely on Linux infrastructure; adding a Windows service required deliberate configuration that standard deployment tooling does not assume.
  • The access-control service needed to communicate with the platform’s authentication and business data services both running as Linux services within the same cluster.
  • Before Ficode’s stabilisation work, the service was not deploying reliably the automated build pipeline was not producing consistent container images, and the service entered startup failures requiring manual intervention.

Deployment Stabilisation:

Three issues were preventing reliable deployment. The automated build pipeline was not producing correctly packaged Windows container images the application package structure needed correction to serve traffic correctly under IIS. The deployment configuration was not directing the Windows container to the Windows-capable infrastructure within the cluster. And the startup configuration was crashing when optional environment variables were absent rather than falling back gracefully. All three issues were resolved: the build pipeline corrected, scheduling configuration added, and startup handling updated to behave correctly across deployment environments.

Access-Control Management Interface:

The platform’s web interface provides building operators with the full range of access management capabilities for commercial multi-tenant environments: access levels defining which doors each user category can access; building user management; department grouping for simpler access policy management; door group definitions for policy assignment; visitor and contractor management with defined validity windows; and detailed access logs for security review and compliance audit.

  • Amazon EKS for Kubernetes workload hosting across Linux and Windows node groups.
  • Amazon ECR for container image storage and release versioning.
  • AWS Application Load Balancer with TLS termination and path-based routing for external access.
  • AWS CloudFormation, VPC, IAM, security groups, and subnets for repeatable infrastructure provisioning and governance.
  • Amazon S3, Amazon CloudWatch, AWS Lambda, and Amazon EventBridge where backup, monitoring, or automation patterns are used in the platform evidence.
  • Delivered physical access-control capability connecting door reader hardware to the platform’s central user management model.
  • Stabilised the Windows-based access-control service deployment within a Linux-dominant cloud cluster.
  • Connected physical access permissions to the platform’s central identity model managed in one place, enforced at the door.
  • Gave building operators a web interface to manage access levels, building users, departments, door groups, visitor passes, and access logs.
  • Discovery and assessment of the existing platform, service dependencies, and operational risks.
  • Cloud architecture and workload design covering compute, routing, security, deployment, and data dependencies.
  • Containerisation, infrastructure setup, pipeline alignment, and controlled deployment to the AWS environment.
  • Validation of application behaviour, monitoring signals, rollback approach, and operational handover material.
  • TLS-protected ingress through a controlled load-balancing layer.
  • Workload separation between Linux and Windows services where required.
  • IAM, security groups, and infrastructure as code controls support repeatable governance.
  • Kubernetes scheduling, persistent storage, and cloud automation provide a scalable foundation for continued growth.

1 Central Cloud Access Model Created:

Access rights can be managed through the smart-building platform rather than separate local access-control tools, reducing administration overhead for building teams.

100% Alignment with Platform User Policy:

User access changes in the platform can flow into the access-control model, reducing the risk of removed users retaining physical access in a separate system.

24-Hour or Date-Based Access Windows Supported:

Temporary visitor and contractor access can be limited to defined dates and times, reducing standing access risk and improving governance for short-term building access.

Audit Trail for 3 Access Event Types:

Successful entries, access attempts, and denials are recorded for security reviews, compliance checks, and incident investigation.

2 Operating Systems Stabilised in 1 Release Model:

The Windows-based Paxton Net2 integration can be deployed alongside Linux services through a controlled cloud release model, reducing manual deployment handling.

AWS Services & Infrastructure

Amazon EKS
Amazon ECR
Application Load Balancer
VPC
IAM
Amazon S3
AWS CloudFormation
Amazon CloudWatch

Platform Dependencies

MongoDB
Kafka
Zookeeper
Elasticsearch

Delivery Tooling

Jenkins
AWS CodeBuild
AWS CodePipeline
Docker
Kubernetes Manifests
GitOps
ArgoCD

Application Stack

Case Study Focus Tags

Physical Access Control
Smart Buildings
Paxton Net2
Facility Management
AWS EKS
Building Security
Tenant Management
Commercial Real Estate

This project demonstrates Ficode’s expertise in AWS cloud solutions, smart-building platforms, Kubernetes deployments, and physical access control systems. By integrating cloud-based identity management with building security infrastructure, we delivered a scalable, secure, and future-ready solution that simplifies access management while supporting long-term business growth.

About Ficode

Ficode is a global software development and AWS consulting company specialising in cloud-native application development, AWS infrastructure, DevOps, QA & Software Testing, AI solutions, enterprise software engineering, and digital transformation. We help businesses worldwide build secure, scalable, and high-performance technology solutions that accelerate innovation and business growth.

Partner with Ficode to build secure, scalable, and cloud-native solutions on AWS.

Get in Touch