Anti-passback and tailgating in data centers: why biometrics alone does NOT solve anything
Your access control vendor just sold you a USD $2,000-per-door fingerprint reader and told you your data center is now “biometric and secure”. What they did not tell you is that a USD $5 silicone finger opens that same reader. Or that anyone with your cloned badge walks in behind you without the system logging it. Biometrics is one factor — not the solution. Anti-passback and tailgating are the two vulnerabilities that no fingerprint, facial or iris reader solves on its own, and these are the ones SOC 2 auditors and enterprise clients will look for in your next assessment.
The two threats your system is probably NOT controlling
Anti-passback: the ‘badge lending’ loophole
Anti-passback (APB) is the logic that prevents a person from using the same badge to enter twice without having exited first. Without APB active, a malicious employee (or one who lent their badge to a third party) can enter the data center multiple times with the same credential, leaving an audit trail that appears legitimate. In hardware, APB is implemented with two readers per door — one entry, one exit — plus the logic that verifies that the entry-exit-entry sequence is consistent.
Tailgating: an open door nullifies everything
Tailgating (also called piggybacking) is when an unauthorized person follows an authorized one through a controlled door without presenting their own credential. In most DCs in Mexico, all it takes is the authorized employee holding the door out of courtesy — “go ahead” — and the system records a single entry and lets anyone in. Biometrics does not solve this because the system records a valid entry; the problem is that physically there are two people passing through.
Why biometrics alone does not solve anything
The typical sales pitch says: “fingerprint or facial recognition = security”. The operational reality:
The problem: no biometric protects you from tailgating. If the door is open and two people pass through, the system records one authorized entry. The biometric confirms that a specific person entered — not that only one person entered.
The 5 concentric zones model (deny by default)
The standard practice in modern DCs is a concentric layers model, where each zone inward requires more controls. For a critical zone (data hall), you need all five:
- Zone 0 — Site perimeter: fence, guard house, perimeter CCTV.
- Zone 1 — Building lobby: staffed reception, visitor log, temporary credential issuance.
- Zone 2 — Vestibule / mantrap: two interlocked doors where dual-factor authentication is performed.
- Zone 3 — Data hall / white space: card + biometric access, APB enforced, CCTV at each door.
- Zone 4 — Rack / cage / cabinet: individual locks with audit trail down to the U position.
Each inner zone requires a stronger credential and shrinks the authorized population. Without this model, a single credential reaches the “crown jewels” — and a breach in one zone exposes the next, not the core.
The 3 physical tools that actually solve tailgating
1. Mantrap / sally port / airlock
It is the only device that prevents tailgating mechanically. Two interlocked doors — the first closes and locks before the second opens. The occupant is trapped inside the vestibule for 5-15 seconds while the system verifies. Overhead sensors (3D, weight mat, optical) confirm that only one person is inside. If occupancy > 1, the doors remain closed and the alarm fires. Throughput: one person every 15-30 seconds. Cost: USD $8-20K per opening including hardware. Best fit: data halls, vaults, switch cores.
2. Optical turnstile with piggyback detection
Unlike the mantrap, the turnstile does not physically prevent — it detects and alarms. Optical sensors detect if a second person follows the first with a valid credential. The door closes and a second authentication is required. Throughput: 30+ people per minute. Cost: USD $15-30K per lane. Best fit: high-traffic lobbies, not data halls.
3. Speed gates with weight sensor + cameras
Combination of a speed gate with a weight mat and a face-capture camera. Faster than an optical turnstile, less expensive than a full mantrap. Best fit: transition between zones, not the data hall core.
Anti-passback implementation: the minimum essentials
APB is implemented in hardware (not only in software). The system needs:
- Two readers per door (in/out) with timestamps synchronized to the central server.
- Hardware-level logic that verifies the entry-exit sequence. If the system only logs entry without exit, the next swipe with the same card is denied.
- Regional vs global anti-passback: regional validates within a specific zone (more permissive); global validates across the entire facility (stricter).
- Documented emergency override: in case of evacuation, the system must allow free exit, but must log the event.
What is NOT anti-passback: a biometric reader alone, a password, a PIN, or any factor that does not verify the temporal sequence of credential use.
The recommended stack for your data hall
If you are designing the data hall (zone 3) access control from scratch, this is the stack hyperscalers are using in 2026:
- Outer door (zone 2 → 3): cylindrical mantrap such as a Boon Edam Circlelock with overhead 3D sensor + face-capture camera. Inner diameter 1000mm, clear height 2300mm.
- Inner door: dual-factor — card (something I have) + facial recognition or palm vein (something I am). Facial must include liveness detection against spoofing.
- APB enforced: hard APB with hardware-level logic, regional or global depending on criticality.
- CCTV: face-capture camera at the inner door, integrated with the access control system for video verification on alarm.
- Audit trail: all events (entry/exit/denied/override) must be logged with timestamp + user ID + door ID + 5-second video clip before/after.
Typical cost of this stack per data hall door: USD $25-50K hardware + USD $3-5K annual maintenance + USD $2-5K integration with your existing access control (Genetec, LenelS2, C•CURE).
Should we quote your anti-passback + tailgating upgrade?
If your data center is evaluating an access control upgrade — or a greenfield where you need to design the 5 zones from the RFP — Noxtel delivers the assessment of your current access control, the specification of the anti-passback + mantrap + dual-factor biometric stack, and the phased implementation timeline compatible with your budget.
Quote your anti-passback + tailgating upgrade → [link to leads form]
Sources
- Score Group — ‘Data Center Physical Security Key Controls: Complete 2026 Guide’ (Mar 2026). https://score-grp.com/en/post/data-center-physical-security-key-controls-complete-2026-guide
- National Lock Supply — ‘Data Center Door Hardware Spec Guide’ (May 2026). https://nationallocksupply.com/blog/data-center-door-hardware-spec-guide
- EngineerSuniverse — ‘Mantrap vs. Turnstile — Concept Explainer’. https://engineersuniverse.com/studios/physical-security/concept-explainers/mantrap-vs-turnstile
- Boon Edam — ‘3 Reasons Mantrap Portals Provide the Highest Level of Security Compliance for an Entry’. https://blog.boonedam.us/3-reasons-mantrap-portals-provide-the-highest-level-of-security-compliance-for-an-entry
- Zero Trust Workplace — ‘Data Center Access Control — Facial Authentication’. https://zerotrustworkplace.com/industries/data-centers
- AI Data Center Guide — ‘Physical Security: Siting, Zones & Kinetic/Drone Threats’. https://aidatacenterguide.com/part-11-security/11-2-physical-security-siting-zones-and-kinetic-drone-threats
Want to master this?
Noxtel Academy →