
C Y B E R S E C U R I T Y
Someone has to secure the security system.
We would rather it was us than you.
Drawbridge Cloud runs your access control the way your email already works — hosted, maintained, backed up and monitored by us, reachable from any device, with nothing on site to patch, replace or budget for. For over 30 years AMT has protected people and property without complexity, lock-in, or excessive cost.
T H E R I S K
What an attacker gets from a door system
An access control system is a directory of people, a map of a building, and a set of keys, in one database. It knows every employee, every contractor, every credential number, and which of them can reach the server room at 2 a.m. In a school district it also holds student records; in a hospital, staff movements through restricted areas.
It is also, in most organizations, the least maintained system on the network. It was commissioned once, it works, and nobody has logged into the server since. Districts and municipalities have been a standing ransomware target for years, and the machine in the security closet is frequently the softest thing on the network.
An unpatched server is an open door
Access control servers run operating systems that need updates like any other. The ones in closets rarely get them.
Nobody is watching
An on-premise system generates logs that nobody reads until after an incident, if then.
Backups on the same network are not backups
Ransomware encrypts what it can reach. A backup drive on the same LAN is in scope.
A R C H I T E C T U R E
Hardened, multi-layer, secure by design
Secure by design means the security was not added after the product worked. Drawbridge was built as a cloud-hosted, mobile-first system, so there is no on-premise server to harden, no VPN to punch through a firewall, and no remote desktop session standing open for support.
HOSTING
Drawbridge runs on Amazon Web Services. AWS infrastructure undergoes independent third-party SOC examinations, including SOC 3, under SSAE 18. AMT does not operate its own data center.
TRANSPORT
Encrypted, authenticated connections, with digital certificates actively maintained by AMT — renewed on schedule rather than after an expiry breaks something.
APPLICATION
A hardened, multi-layer architecture, maintained and patched continuously by AMT as part of the service rather than as a customer project.
THE EDGE
Controllers and readers in the building, on standard non-proprietary hardware. No inbound firewall openings required for AMT to manage the system.
The important structural point: there is no server of yours in this diagram. That is not a convenience feature. It is the largest single reduction in the attack surface that moving to a hosted system produces.
R A N S O M W A R E
Backups an intrusion cannot reach
Ransomware works because the backups are usually reachable from the machine that got infected. Encrypt the server, encrypt the share it backs up to, and the organization has no way back except payment.
Drawbridge backs up continuously — hourly — and those backups are verified rather than assumed. Critically, they are isolated: held where an intrusion on your network has no path to them. An attacker who reaches everything on your side of the wire still has not reached the copy that restores your access control system.
HOURLY
Continuous backups, not a nightly window.
ISOLATED
Held beyond the reach of an intrusion on your network.
VERIFIED
Checked, because a backup nobody has tested is a hope rather than a plan.
M O N I T O R I N G
Watched continuously, by people and by machines
An on-premise system writes logs that nobody reads. A hosted one is watched as a condition of the service.
Automated and live monitoring — machine monitoring continuously, with people reviewing what it surfaces
Unusual and suspicious activity monitoring — behavior outside the normal pattern gets attention
Resource monitoring — network, server, database, memory and disk, so constrained resources are found before they become an outage
Performance bottleneck detection — degradation is visible to us before it is visible to you
Predictive maintenance — problems addressed on a schedule rather than after a failure
None of this is exotic. It is ordinary operational discipline, applied full time, which is precisely what an organization running its own access control server cannot realistically sustain — and not for lack of competence. It is a question of whether this is the best use of their week.
S H A R E D R E S P O N S I B I L I T Y
The honest division
Cloud security is shared, and any vendor who tells you otherwise is selling. Here is thesplit.
AWS
Physical data centers, hardware, network infrastructure and hypervisor. Independently examined — SOC examinations including SOC 3, under SSAE 18.
YOU
Your people and your doors. Who has an account, who has a credential, what your access policy is, and revoking both when someone leaves.
AMT
The Drawbridge application and its hosting configuration: patching, certificate management, backups and their isolation, monitoring, and incident response on the platform.
Worth stating plainly: the SOC examinations above are of AWS infrastructure. AMT is not itself SOC-certified, and we would rather tell you that here than have you find it out in a questionnaire.
EVALUATING
Six questions worth asking — of us and of everyone else
1. Where are the backups held, and can something on my network reach them?
2. How often are backups taken, and is anyone verifying that they restore?
3. Who patches the system, on what schedule, and what happens if they don't?
4. What is audited independently, by whom, and does the audit cover the application or only the hosting?
5. If I have an incident, who do I call, and what do they actually do?
When I leave, what happens to my data?
We will answer all six in writing. Ask us.