The Case for a Smarter Security Architecture

By Joshua Douglas, SVP of Product and Engineering, Xtract One Technologies

Physical security teams are sitting with a question that procurement conversations rarely address directly. How do you deploy AI-powered weapons detection intelligently across a facility where not every door carries the same risk, and where the cost of hardware screening at every access point doesn’t reflect how risk actually distributes across a building?

That’s the architecture conversation the industry needs to have, and it’s one we think about constantly as we build the products that sit at the center of it.

Risk Doesn’t Distribute Evenly. Your Security Program Should Reflect That. 

Every facility has a risk profile, and most of them aren’t uniform across every door. A hospital has an emergency department entrance, a main visitor entrance, and a labor and delivery wing. It also has a loading dock, a parking garage, a staff entrance, and a dozen other access points that see lower volumes and lower risk. A corporate campus has a primary lobby where visitors check in and secondary entrances that employees badge through. A university has controlled academic buildings and open common spaces.

The mistake some security procurement conversations make is treating all of those entry points the same. They’re not. The appropriate technology at a high-volume, high-risk entry point differs from the appropriate technology at a low-traffic staff entrance, and designing a program as if they’re equivalent produces either an overspend that doesn’t get approved or a program that leaves real exposure in the places it should have covered.

A risk-based architecture is more straightforward than security teams expect. At entry points where volume is high, where the population is diverse and unknown, and where the consequences of a missed weapon are most severe, dedicated AI-powered screening belongs. Individuals walk through at a natural pace, the system identifies specific threat objects, and staff respond to specific information rather than managing noise. At lower-risk access points, access control paired with camera-based monitoring and centralized oversight from a security operations center covers the exposure without the per-lane hardware cost.

That’s a sensible architecture that allocates the highest-capability technology where the risk justifies it and uses scalable, cost-effective monitoring everywhere else.

The API Is the Architecture 

Modern physical security systems weren’t built to operate in isolation.. Xtract One’s open API allows detection data to flow into video management systems, access control platforms, and security operations centers. When SmartGateway or Xtract One Gateway generates an alert, that signal can trigger a camera to track the individual, notify a remote security team, lock a door, or initiate a response protocol, all without requiring a human to manually connect the pieces.

We’re already seeing this play out with our customers. Major manufacturers and pharmaceutical companies are deploying our systems at primary entry points and pairing them with camera networks and centralized access control at secondary access points. The detection event at the primary screen informs how the rest of the facility responds. A confirmed alert at the main entrance can initiate a lockdown of specific zones, reroute access permissions, and notify a centralized security team monitoring the full site, all through integrations that exist today.

Large corporate operators want AI-powered screening at their highest-risk entry points and camera-based monitoring with remote access control capability everywhere else, unified through a central operations platform that gives security leadership a complete picture of the facility in real time. The technology to build that architecture exists. The API frameworks are open and the integration pathways are documented. What some organizations are missing is the strategic framing that tells them which technology belongs where and why.

Where Camera-Based Detection Fits and Where It Doesn’t

Camera-based weapons detection software has a genuine role in a well-designed security program. It covers distributed access points that can’t realistically be converted into screening checkpoints. It extends detection coverage into parking lots, loading docks, hallways, and open campus areas where hardware screening would be operationally impossible. For a university with dozens of buildings and hundreds of access points, camera-based detection across the existing camera network is a meaningful layer of coverage that a hardware-only approach couldn’t replicate economically.

What camera-based detection can’t do is replicate the accuracy, specificity, and legal defensibility of validated hardware screening at a high-risk entry point. A camera can see a brandished firearm in a hallway. It can’t tell you that a concealed knife is tucked into the waistband of the third person in a stadium entry queue. Those are different problems requiring different solutions, and positioning one as a substitute for the other misrepresents what each technology actually does.

SmartGateway holds DHS SAFETY Act Designation, TSA and FAA validation, DOJ certification, and NPSA listing. Those certifications exist because the technology has been independently tested against specific threat detection standards under controlled and operational conditions. They matter to professional sports leagues, healthcare systems, and public institutions with regulatory, insurance, or contractual requirements for their security programs. Camera-based detection software carries different certifications because it’s solving a different problem at a different point in the security architecture.

The Hackathon That Showed Us Where This Is Going

At our first internal hackathon earlier this year, six cross-functional teams of engineers, product managers, and ML specialists spent 48 hours building on top of our existing platform. Several of the most compelling ideas that came out of that event weren’t about improving detection at the primary screen. They were about what happens after the alert fires, how detection data flows into the broader security ecosystem, and how automation can compress the time between a detected threat and a coordinated facility response.

Three patent submissions are currently under review from that event. The ideas that generated them reflect where the product is heading: a detection platform that participates actively in the facility’s response to them, through open integrations, automated workflows, and centralized operational intelligence that gives security leadership a complete picture in real time.

That’s the direction the industry is moving, and it’s the direction we’re building toward. Hardware screening at high-risk entry points connected through open APIs to the camera networks, access control systems, and operations centers that cover the rest of the facility. Each layer doing what it does best, informed by the others.

The Question Worth Asking

When a facility is evaluating its security program, the most useful question is where in the facility the risk profile justifies dedicated, validated screening, and where intelligent monitoring with automated response capability covers the exposure at an appropriate cost.

We’ve built our platform with open APIs specifically because our systems operate within a broader security architecture. The venues, health systems, and enterprise customers getting the most out of their programs have thought carefully about that architecture and deployed each technology where it makes the most sense.

A risk-first approach to security architecture produces programs that are more capable, more cost-effective, and more defensible than programs built around any single technology. The hardware belongs where the risk is highest. The monitoring belongs everywhere else. And the integration layer that connects them is where the real operational intelligence lives.