Start your EVOTECH request in under a minute.
Keycard Access in Sugar Land 77498: Choosing Credentials That Resist Cloning
On the 77498 side of Sugar Land, keycard work tends to land in medical and dental suites, small professional offices and HOA amenity centers. In all three, the decision that matters most isn’t the reader brand — it’s the credential you hand people. Here is how card technology, migrations and day-to-day administration really work.
The credential is the real lock
Readers, controllers and electric strikes get the attention, yet the card decides how secure the system actually is. If a credential can be copied, the best hardware on the door protects nothing.
A large share of older systems around Houston still run on 125 kHz proximity cards. A prox card has no encryption: it simply broadcasts a fixed number to any reader that energizes it. Handheld devices sold openly online can read that number from a short distance and write it to a blank card or fob, and the controller cannot tell the copy from the original.
Moving to 13.56 MHz is not automatically an upgrade. First-generation MIFARE Classic cards use a cipher that researchers broke publicly more than a decade ago. The credentials worth issuing today use mutual authentication and AES-class cryptography — MIFARE DESFire EV2 or EV3, HID Seos, and comparable secure-element cards. With these, reader and card prove their identity to each other before any data changes hands, and the protected contents can’t be dumped and replayed.
There is one trap even with good cards: a reader configured to read only the card’s serial number, called the UID, ignores the encryption entirely. UIDs can be emulated, so a DESFire card read that way is barely safer than prox. We configure readers to read the secured application on the card, keyed to your site.
Mobile credentials — a phone or watch presenting the key over Bluetooth or NFC — are a strong option on platforms that support them. People guard their phones far more carefully than a plastic card, and a missing phone gets noticed within hours.
Prox, smart card, fob, phone or PIN — side by side
| Credential | Resistance to copying | Where it fits | Caveat |
|---|---|---|---|
| 125 kHz prox card or fob | Low — no encryption | Existing systems only | Plan its retirement rather than expanding it |
| MIFARE Classic | Low — cipher broken | Not recommended for new issue | Often sold loosely as a smart card |
| DESFire EV2 / EV3 | High when configured with site keys | Offices, clinics, amenity centers | Weak if the reader only reads the UID |
| HID Seos and similar | High | Organizations standardizing on one ecosystem | Proprietary; cards come through that ecosystem |
| Mobile credential | High, bound to the device | Staff who always carry a phone | Requires platform support; keep a few cards for visitors |
| PIN keypad | Depends on discipline | Second factor on a sensitive room | Codes get shared and watched |
For a small Sugar Land practice or office, the usual recommendation is an encrypted smart card as the base credential, mobile keys for staff who want them, and card-plus-PIN on the one or two rooms where a lost card alone shouldn’t be enough.
The Sugar Land sites we see most, and what each one needs
77498 covers much of Sugar Land north of US-59/I-69, where neighborhoods built from the 1980s onward sit beside strip centers, medical and dental suites and low-rise office buildings along the Highway 6 corridor. Three kinds of site account for most keycard requests.
Medical and dental suites
The layout repeats: a public waiting room, a staff-only corridor behind the reception window, and a few rooms that deserve tighter control — records, medication or supply storage, the server closet. Keycards let the corridor door unlock for clinical staff all day while the storage rooms stay restricted to named people. Cleaning crews get a schedule that works only on their evenings. The log shows who opened a restricted room and when. What your policies require you to record is a question for your compliance advisor; we build the system so the log is available when they ask.
Professional offices in multi-tenant buildings
In a shared building the landlord may already run a system on the lobby and elevators. Your suite can either join that system as a tenant or run its own, and the choice affects which cards staff carry. Restricting elevator floors by card requires the building’s elevator contractor; we coordinate with them rather than wiring into elevator controls ourselves.
HOA amenity centers
Pools, clubhouses and fitness rooms are where resident cards live. The pool gate reader sits outdoors in direct sun and rain, so it has to be rated for exterior use and sealed at the cable entry. Pool enclosure gates generally must stay self-closing and self-latching, and the electrified hardware has to work with that latch, never replace it. Schedules follow posted amenity hours, and the board decides when a resident’s card is suspended — at move-out, for example. Boards typically want usage counts, not a detailed diary of individual residents, and the system can be set up that way.
Moving off an old prox system without reissuing everyone overnight
Few offices can hand every employee a new card on a Monday morning. A staged migration keeps doors working throughout.
- Inventory the current format. The common 26-bit format carries an 8-bit facility code and a 16-bit card number, which allows only 256 facility codes and card numbers from 0 to 65,535. Two unrelated organizations can hold identical credentials. New cards should use a format with a far larger number space so that collision can’t happen.
- Check the controller. If the existing panel can’t accept OSDP readers or the new card format, or the manufacturer no longer supports it, the migration includes a panel replacement. Better to learn that during the survey.
- Install multi-technology readers. These read both the old prox cards and the new smart credentials, so nobody is locked out mid-transition.
- Reissue in waves. Department by department, or by shift, with each new credential enrolled against the same user record.
- Turn prox off. Once the last old card is replaced, disable 125 kHz reading at every reader. Skipping this step leaves the cloneable path open indefinitely, and it is the step most often forgotten.
Existing reader cable can sometimes be reused when readers move to OSDP on short runs. RS-485 prefers a twisted pair, though, and many older installations used untwisted cable, so on longer runs we test before relying on it.
What administration looks like after installation
- Groups, not individuals. Build access around roles — front desk, clinical, management, cleaning crew — then drop each person into a role. Changes take seconds.
- Holiday calendars. Load them once a year so the front door doesn’t unlock itself on a day the office is closed.
- Lost cards. Disabling a card takes a few clicks, and any later attempt to use it is logged.
- Two administrators, minimum. A system with a single login that walks out the door with one employee is a common and avoidable problem.
- Keep personal data minimal. A name and a group are enough for most sites. Store photos only if you print badges.
- Cloud or local. Cloud platforms handle updates and remote management for a subscription; local software is paid up front and depends on you maintaining the computer and its backups.
- Firmware. Controllers and readers receive security updates; someone should own applying them.
The installation, start to finish
The physical work follows a set order. A site survey confirms every door, frame and cable path. A written door list and credential plan come back to you for approval. Cable is pulled and readers, locks, door contacts and exit sensors are mounted. The controller and the lock power supply with its standby batteries go in, usually beside your network equipment. Then comes enrollment day, when we load users — often from a spreadsheet — and issue credentials. Each door is tested for valid, invalid and out-of-schedule cards, exits, forced and propped conditions, and power loss. Last, whoever will run the system gets hands-on training.
Pricing: the variables, not a number
- How many doors and gates, and whether any are outdoors, glass or fire-labeled.
- Credential type and how many people need one; a secure credential carries a higher unit cost than a prox card.
- Whether readers must support both old and new cards during a migration.
- Controller replacement if the existing panel can’t be upgraded.
- Platform licensing, one-time or subscription.
- Coordination with an elevator contractor, fire alarm contractor or building management.
- Trenching or conduit to reach a detached pool gate.
You receive an itemized quote after the on-site survey.
Where Sugar Land keycard projects go wrong
- Buying cards advertised as 13.56 MHz that turn out to be MIFARE Classic, or configuring secure cards to be read by UID only.
- Leaving prox reading enabled after the migration is finished.
- Shipping DESFire cards with the manufacturer’s default keys instead of site-specific keys.
- Pool gate hardware installed so the gate no longer latches on its own.
- One administrator account, owned by someone who later leaves.
- An outdoor reader not rated for sustained direct sun and driving rain.
Related services
Frequently asked questions
Our Sugar Land office still uses prox cards. Are they really that easy to copy?
Yes. A 125 kHz prox card transmits an unencrypted number, and inexpensive handheld devices can read and duplicate it. The copy works at every reader that accepts the original. Moving to an encrypted smart credential, configured to read the secured application rather than the serial number, closes that gap.
Can we keep our current cards while we upgrade?
Yes, temporarily. Multi-technology readers accept both old prox cards and new smart credentials, so you can reissue in stages. Once everyone has a new credential, switch prox reading off at every reader so the old weakness doesn’t linger.
Can our HOA board suspend a resident’s pool card remotely?
On a networked system, yes — the board or its management company switches the card off in the portal, and the pool gate and clubhouse reject it on the next tap. When to suspend is a board policy decision; the system only enforces it.
Can keycards control which floor the elevator goes to?
It is possible in many buildings, but it involves the elevator equipment, so the building’s elevator contractor has to be part of the project. We install and program the access side and coordinate with them on the interface.
Can phones replace cards entirely?
For most staff on a platform that supports mobile credentials, yes. We still recommend keeping a small stock of cards for visitors, temporary workers and anyone without a compatible phone.
Pick credentials you won’t have to replace later
Book an on-site estimate in Sugar Land and we will review your doors, your current cards and your migration options, then send an itemized quote. Call (832) 359-2425.
Book an on-site estimate
Ready for EVOTECH to help?
Before you leave, send the quick version. We will review the page you came from and reply with the clean next step.
