Infrastructure managers and the operators on their networks, across rail, road, ports and airports. Key2XS connects the IAM you already run to the keys on both estates.
Across rail, road, ports and airports, transport splits in two: those who run the infrastructure and those who operate on it. Key2XS governs the keys on both sides.
The fixed estate: unmanned installations along networks, around harbours and across airfields.
The operational estate: depots, workshops and terminals, run around the clock by crews and contractors.
Whoever can open a relay house or a tunnel service door is close to systems that keep vehicles moving and people safe. Four realities work against knowing who that is.
Main contractor, subcontractor, night crew. Key registration lags at every layer.
A crew needs one section for four hours; the key works for months.
Assets stretch along hundreds of kilometres, so keys are broad by design.
After a disruption, authorities want answers in hours, not after a week of reconstruction.
Every gap between who should have access and who can get in is a gap in your safety case.
Middleware between your IAM and the key systems on your infrastructure. Follow one corridor project through four events.
The project registration becomes access rights for exactly the relay houses and technical buildings on the corridor, at every layer of subcontracting.
The next work package moves the crew to the depot; the rights move with them, in near real time.
A night possession opens the line for four hours on top of the running package. Granted for the window, withdrawn when the line reopens.
When the project ends, every crew member's access ends with it, at every layer of subcontracting. The rights follow the registration, not the metal.
Transport is explicitly in scope of both directives: CER for the resilience of physical infrastructure, NIS2 for policies governing access to premises. The practical test is simple.
A relay house along the track sees a key long before it sees a network. Rights travel with the key, and a withdrawal is enforced at the next key update.
The next time the key is used or updated it picks up its new rights. Revocation propagates the same way.
Near real time, not instantaneous. Each key system closes the window with its own mechanism; Key2XS makes the decision centrally and logs the change.
Middleware through standard interfaces. Locks, keys and the locking plan stay as they are.
Identity decisions become access rights, with evidence.
Yes. Key2XS governs the keys you hold: depots, workshops, yards and station technical rooms, for your own staff and your contractors. Access follows your IAM either way.
Yes. Access rights follow the assignments in your IAM system. A project registration with an end date produces access that exists exactly as long as the work does, and every change is logged.
Yes. Anyone registered in your IAM, including contractor and subcontractor staff, can be governed the same way. Access follows the registration, so it ends when the engagement ends, regardless of the layer of contracting.
Yes. The audit trail shows for any location who held access rights at any moment, on whose authority, and when rights changed. Questions that used to take days of reconstruction become queries.
No. Key2XS is middleware. It orchestrates access rights through the standard interfaces of your existing key systems: iLOQ, ASSA ABLOY CLIQ, ASSA ABLOY Access or Traka. Locks, keys and the locking plan stay as they are.
A standard integration is live in under two hours, through pre-built connectors, with no custom development required from your team.
A guided walkthrough of how identity, policy and physical keys come together along the line and in the depots.