
Data center access control that starts at the door
Data center access control from Alcatraz verifies every person at every zone boundary with sub-second facial authentication. Real-time tailgating detection, 3D liveness, and badge-plus-face multi-factor bring zero trust to physical entry, on your existing access control system via Wiegand or OSDP, with all biometric processing on the edge device.
Physical access is now a cybersecurity issue
Every control in your security stack assumes the person at the keyboard belongs there. A badge in the wrong hands defeats that assumption, and with it every firewall, EDR agent, and SIEM rule behind it. Physical entry is the layer under the stack, and in most facilities it is still protected by a credential anyone can carry.
The stakes have moved. Racks of AI accelerators concentrate more capital value per square meter than data centers have ever held, and the workloads running on them are the crown jewels of the companies that own them. Customers, insurers, and auditors have noticed. Questions that used to stop at the mantrap now go person by person, door by door.
Alcatraz answers those questions with verification. Every entry is a verified person, not a scanned card, and every boundary crossing is logged that way.
Zero trust at every zone transition
Zero trust means never trusting a prior check. Applied to the physical layer, it means re-verifying identity at every boundary: perimeter, corridor, data hall, cage. A badge cannot do that honestly, because a badge only proves possession.
Alcatraz makes continuous verification practical. Authentication is sub-second and hands-free, so re-verifying at each transition adds no friction for technicians moving through the facility. At critical boundaries, enable 2FA, badge plus face, for true multi-factor at critical boundaries: something you have and something you are, enforced at the door itself. 3D liveness detection blocks photo, screen, and mask spoofing, so the verification means what it claims.
Tailgating detection completes the model. When a second person follows a valid entry, the system flags it in real time and captures video at the door, detecting the second person through the door instead of reporting it the next morning. Zone integrity stops being an assumption and becomes a monitored fact.

Compliance and audit readiness
Data center operators live in audit season year-round: SOC 2, ISO 27001, customer security reviews, and for colocation providers, tenant audits that repeat with every renewal. The recurring question is the same. Prove who accessed what, and prove your controls actually control.
Alcatraz turns entry logs into evidence. Every access event in Rock Cortex is an immutable record tied to a verified person, producing audit-ready logs that support SOC 2 and ISO 27001 evidence collection. Tailgating events are documented with video, demonstrating that unauthorized-entry detection is real and operational, not a policy statement. For colocation providers, per-cage verification gives tenant auditors a person-level answer instead of a badge-level shrug.

Access zones
Access zones through the facility

Perimeter and lobby
The perimeter sets the tone. Facial authentication at staff entrances verifies employees and enrolled contractors hands-free in under a second, while visitor flows stay on their escorted track. Rock X covers exterior doors and parking-side entrances, rain or shine. From the first door, your logs record verified people rather than presented cards, which simplifies every audit conversation that follows.
Mantrap and vestibule
The mantrap is where data centers already concentrate control, and where Alcatraz strengthens it most. Facial authentication with 2FA at both doors enforces one verified person per cycle, and tailgating detection makes piggybacking a detected event rather than a folklore risk. Sub-second authentication keeps throughput acceptable even at shift change, so security does not become the bottleneck operations resents.
Explore biometric mantrapsCage and cabinet rows
In colocation halls, the cage boundary is the customer boundary. Deploy the Rock at cage doors so entry requires the verified, enrolled person the tenant authorized, with roles and permissions in Rock Cortex scoped per customer. Tenant audit requests become report exports. Remote hands teams authenticate at each cage they are cleared for, and nowhere else.
Enrollment, permissions, and audit reportingNetwork operations center
The NOC sees everything, which makes its door worth hardening. Facial authentication restricts entry to enrolled operations staff, with 2FA available for facilities that classify the NOC as a critical zone. Hands-free entry suits a room people enter carrying laptops and coffee at 3 am, and the access record ties every entry during an incident window to a named, verified person.
300%
Data center adoption growth year over year, as of April 2026
5M+
Employees protected by Alcatraz across all industries
91%
Customer satisfaction
Why biometrics
Why biometrics win at the data center door

Badge sharing ends
The top insider risk at the door is not forgery, it is lending. A face cannot be lent, cloned, or left in a car.
Tailgating becomes visible
Card systems are blind to the second person walking in. Alcatraz detects them in real time, with video evidence at the door.
Liveness proves presence
3D liveness detection defeats photos, screens, and masks, so every verified entry means a physically present, enrolled person.
Processing stays on device
All processing happens on the device. Templates are encrypted, no face images are stored, and biometric data never flows to a cloud.
Use cases
Every entrance type
Door
Data hall and corridor doors get sub-second facial authentication with tailgating detection, so every zone transition is a verified person and every piggyback attempt is a logged, video-documented event.
Turnstile
Lobby and perimeter turnstiles authenticate staff hands-free at walking pace, keeping shift-change throughput high while guaranteeing the person entering the secure side is enrolled and verified.
Mantrap
The vestibule becomes airtight: one verified person per cycle, 2FA at both doors, liveness-checked, with tailgating detection ensuring nobody rides a valid entry into the data hall.
Benefits
Why data center teams choose Alcatraz
Zero trust made physical
Sub-second, hands-free facial authentication makes re-verification at every zone boundary operationally free, and badge-plus-face 2FA gives critical boundaries true multi-factor. The zero-trust model your CISO enforces on the network finally extends to the doors in front of it.
Evidence, not assertions
Immutable, person-level entry records and video-documented tailgating events give SOC 2, ISO 27001, and tenant audits concrete evidence. Rock Cortex reporting turns the recurring who-accessed-what question into an export instead of an investigation.
Deployment without downtime
Rock and Rock X sit in line via Wiegand or OSDP with the access control systems data centers already run, including Genetec, LenelS2, and Software House C•CURE. Roll out door by door, starting at the mantrap, with no rip-and-replace and no migration freeze.
Proof at scale



Scott Data Center
Scott Data Center deployed Alcatraz facial authentication to verify identity at its critical boundaries. For a facility whose business is other companies’ uptime and data, moving from badge possession to person verification changed what its access logs can prove, to its own team and to every customer audit that asks.
A majority of the top 10 AI leaders
The companies building frontier AI protect the facilities behind it with Alcatraz. A majority of the top 10 AI leaders trust Alcatraz at their doors, where the concentration of compute value and IP makes person-level verification the only defensible standard.
300% data center growth
As of the April 2026 Series B announcement, Alcatraz data center adoption was growing 300% year over year, alongside 200% new-customer growth. Across all industries, Alcatraz protects more than 5 million employees with 91% customer satisfaction.
Verify every person, at every boundary
The cheapest way into a data center has never been through the network. It is through a door, behind someone else, or with someone else’s badge. Alcatraz closes both paths with facial authentication, tailgating detection, and multi-factor at critical boundaries, deployed in line with the access control system you already run. Start at your mantrap and prove it in one door.
FAQ
How does data center access control with facial authentication support zero trust?
It re-verifies identity at every physical boundary the way zero trust re-verifies every network request. Alcatraz authenticates the enrolled person in under a second at each zone transition, adds badge-plus-face 2FA at critical doors, and logs each crossing as a verified person, not a presented card.
How does Alcatraz stop tailgating in a data center?
The reader monitors the doorway after each valid entry and flags a second person in real time, capturing video at the door. Security receives an actionable event tied to the verified entry, and the recorded evidence documents the attempt for audits and investigations.
Can biometric access control help with SOC 2 and ISO 27001 audits in a data center?
Yes. Every entry becomes an immutable record tied to a verified person, and Rock Cortex produces audit-ready logs that support SOC 2 and ISO 27001 evidence collection. Video-documented tailgating events additionally demonstrate that unauthorized-entry detection is operational, which strengthens physical security control narratives.
Does facial authentication in a data center require replacing the existing access control system?
No. Rock and Rock X integrate via Wiegand or OSDP, sitting in line between the reader position and the panel. Existing platforms such as Genetec, LenelS2, and Software House C•CURE continue to run everything they run today, with Alcatraz adding identity verification at the door.
Where does biometric data go in a data center deployment?
Nowhere. All processing happens on the edge device, and faces are converted to encrypted, non-reconstitutable templates. No photos or videos of faces are stored, and enrollment is opt-in. For operators with data sovereignty requirements, biometric data stays at the facility by design.





