BioStar X is Suprema's open on-prem access control platform, built natively around the world's most advanced biometrics.
With v1.0.3, BioStar X strengthens that foundation with greater accountability, more secure communications, tighter operational control, and smarter facial authentication. The release is designed to help security teams manage access with greater trust and precision while keeping control of their security environment on premises.
BioStar X v1.0.3 at a Glance
- Compliance, strengthened: Complete audit trail across access control and time & attendance, with before/after change tracking and sensitive-data access logging, closing the gap that blocked entry into regulated industries.
- Security, hardened: Secure by default for device-to-server communication, supporting the EU Cyber Resilience Act’s secure-by-default requirement, plus TLS 1.3 across major communication channels and DESFire EV2/EV3 Secure Messaging.
- Real-time monitoring, immediate response: Live door and elevator status, action-needed filtering, and one-click emergency actions like lockdown. Administrators can see what needs attention and act on it immediately, without digging through menus.
- Access control, fine-tuned: Role-based permissions down to the submenu level, with dedicated camera group permissions and automatic deactivation of inactive accounts. Gives precise control that closes a common security gap without adding administrative overhead.
- Face Authentication, extended: Rapid face authentication, new Multi Face Authentication and Anti-Tailgating, plus a configurable re-authentication block. Enhanced access experience at busy or high-security entrances.
Feature Snapshot: What You Get With BioStar X v1.0.3
Read the full release >>
| Compliance & Security |
- Secure device-to-server secure communication by default, compliant with the EU Cyber Resilience Act
- TLS 1.3 across major communication channels
- Secure Messaging for DESFire EV2/EV3 (auto card-version detection, force-SM option)
- Auth-failure Lockout: PIN brute-force prevention, EN 60839 SG4 requirement
- Access Control Audit Trail enhanced: before/after values, sensitive-data access, Export logging
- Full time & attendance audit trail, covering shift/schedule changes and reports (compliant with GDPR)
|
| Fine-tuned operations & monitoring |
- Detailed door/elevator status in Preview (contact, relay, alarm, lock time left)
- Filter to items needing action only (Override, Alarm, abnormal)
- Restored batch door/elevator control, plus group-level control and batch stop
- Map Status Tree improvement: Per-element icons, and area shown on facility click
- On-Site roll call (excludes absentees, with report)
- One-click header exposure for urgent Quick Actions (Lockdown, etc.)
- Granular permission and control: Submenu level and admin level
- Device Template configuration, reusable across devices
- Automated deactivation of inactive/idle accounts
|
| Authentication & Access |
- Rapid Face authentication, supporting up to 35 authentications per minute (Latest firmware update on BioStation 3 and BioStation 3Max)
- Multi-Face Authentication (paid device licence)
- Anti-Tailgating Detection (optional)
- Configurable Re-authentication Bloc
|
| Hardware & Integration |
- DESKO ID scanner, easy user registration with just an ID card scan. (Auto-fill user information, photo, and face credential)
- BioStation 3 Max now with customizable idle-screen video. Customize on what shown on the large screen of BS3 Max when idle (wayfinding, notices, promotion, or internal messaging)
- XPass Q2 – DPB (PoE), for sites standardized on PoE. Power and data run over one cable
- New XPass 2 V2 revisions
|
What Compliance Gaps Does BioStar X v1.0.3 Close?
The core concept behind this release is Trust & Compliance. Two key additions raise BioStar X's compliance and security standards for identity-first, compliance-sensitive businesses.
A Complete Audit Trail
BioStar X now records create and delete actions, captures before-and-after values for updates, and logs sensitive-data access and exports. For organizations subject to strict internal audits, privacy obligations, or information-security governance, complete accountability records are often a prerequisite for platform approval.
What the new version offers:
- Complete CUD logging: Every Create, Update, and Delete action is now recorded, and every Update captures which field changed and from what value to what.
- Sensitive-data tracking: Read access is logged whenever sensitive data, such as personal information, is involved, and every Export is logged too.
- Time & Attendance (T&A) audit trail: On the T&A side, changes to shifts and schedules, along with report creation, viewing, and export, are all tracked.

Communications Security & Regulatory Compliance
BioStar X now has secure communication “ON” by default, now in compliance with key standards for EU and regulated industries.
- Secure communication by default: Device-to-server communication is now secure by default, supporting the EU Cyber Resilience Act’s (CRA) secure-by-default requirement, while major communication channels have been upgraded to TLS 1.3.
- Credential upgrade for secure messaging: On the credential side, DESFire EV2/EV3 cards get Secure Messaging with auto-detection of card versions.
- Activated auth-protection lockout: New authentication-failure lockout which blocks PIN brute-force attempts; one of several requirements toward the EN 60839 SG4 security grade.

The benefits for compliance:
-
Stronger audit readiness. Complete activity records, before-and-after change tracking, sensitive-data access logs, and export logs help organizations support internal audits, privacy accountability, and regulated-industry review.
-
Faster incident investigation. Detailed records of who changed, viewed, or exported sensitive information make it easier to trace suspicious activity and understand root causes.
-
Secure-by-default device communication. TLS 1.3 across major communication channels, protected card exchanges, and authentication lockout help reduce exposure from the server to the reader and credential.
-
Faster readiness for regulated markets. Together, the audit trail and communication-security upgrades help organizations move closer to GDPR accountability, CRA expectations, and demanding security-governance standards.
-
Less security configuration to manage. Default-secure communication and automatic card-version detection reduce manual setup while helping teams apply consistent protection across deployments.
-
Lower risk as system grows. Built-in safeguards against interception, credential tampering, and brute-force attempts help maintain a stronger security baseline across more users, devices, and sites.
How Does v1.0.3 Tighten Day-to-Day Operations?
Day-to-day operations often depend on how quickly administrators can see what is happening, identify what needs attention, and act without switching between multiple menus. BioStar X v1.0.3 focuses on enhancing that workflow by improving real-time visibility, batch control, role-based access, and device configuration tools.

Real-time Monitoring & Immediate Response
- The preview screen now shows detailed door and elevator status. contact, relay, alarm, lock reason, and remaining time.
- Users can now filter down to only what needs action. Administrators can now filter the view down to only overrides, alarms, and abnormal states; surfacing only the handful of items that need attention.
- Device lock status indication and an improved map tree (per-element icons, Facility→Area) make situational awareness faster to reach. Administrators can move from a broad site to view a specific device more quickly.
- Batch control of multiple doors and elevators in a single action. Also, a batch stop action across multiple devices. letting administrators halt multiple devices across the system at once.
- One-click access to urgent Quick Actions like Lockdown. Urgent actions such as Lockdown are now available directly from the header with a single click, rather than being buried inside menus. This removes the extra navigation steps between spotting a problem and acting on it.
- Device-level authentication to hold a door open or return it to the door without depending on the server. This is useful for class hours, scheduled events, or any situation calling for temporary open access.
- On-site roll call rounds this out with a report based on who is actually present. It automatically excludes people who haven't checked in and generates a report reflecting real-time presence, proving useful during an evacuation, drill, or headcount check.

Large-scale operations & Permission Management
- Granular permissions: Access is now controlled with precision down to the submenu level, per operator, and with dedicated camera group permissions.
- Idle user cleanup: Long-inactive user accounts are automatically flagged and deactivated with advance notice, closing off a common security blind spot without adding manual review work.
- Device template: Multiple devices can be configured at once with template features such as configuration-file export and same-model Batch Edit.
The benefits for day-to-day operations:
-
Accurate and detailed access status: Zeroing in on target door and site to check their status in detail, not just through the Door and Device trees.
-
Faster awareness and quick response: See exactly what needs attention, and act instantly with one-click lockdown and batch control.
-
Roll call accuracy: Confirm roll call only for who is actually present with detailed records on absentees.
-
Right-sized user access and no stale accounts: Give each operator access to only what they need.Auto-deactivate idle or expired user accounts.
-
Seamless device migration and configuration: Easy export/import of config files, batch edit, quick edit using device templates.
What is new in Face Authentication?
The new version of BioStar X gives administrators more control over how face authentication handles busy or high-security entrances.
- Rapid Face Authentication: Delivered via the latest firmware for BioStation 3 and BioStation 3 Max (released alongside this version of BioStar X), this speeds up how quickly the device authenticates by supporting up to 35 authentications per minute. Instead of pausing after each result, the device moves straight to the next person in line and automatically skips anyone who's already been authenticated within a set re-authentication window.
It's on by default, at no additional cost or license.
- Multi-face Authentication: Unlike rapid face authentication, when several people are in view together, the device authenticates every recognized face in that group in one pass, rather than requiring each person to step up and be processed individually.
This is a paid, license-based feature, well suited to entrances with heavy simultaneous traffic such as shift changes, lobbies, elevator cabins, or shuttles.
- Anti-tailgating: An optional configurable feature where the biometric readers stop authenticating in the case of two or more faces detected at the same time. This feature prevents unauthorized people from following a credentialed person into a restricted area.
- Re-authentication Block: Skip a person, who has already authenticated, for a customizable window of time, to avoid re-authentication when still in view. It's configurable or can be turned off. Helps keep authentication records clean at entrances where people naturally pause nearby.
BioStar X v1.0.3 is built around the same idea: give security teams the accountability, control, and usability that industry best practices call for, in a platform that's easier to run day to day. A complete audit trail and secure-by-default communications raise the bar on trust. Tighter, role-based operations give security teams precise control without added complexity. And new smarter face authentication makes the experience at the door better for everyone who passes through it. Together, this is the release that lets you say yes to a higher standard, across the board.
Download BioStar X v1.0.3 >>
Frequently Asked questions about BioStar X
Does the EU CRA "secure by default" mandate apply to all of BioStar X?
No. Secure by default applies specifically to device-to-server communication, in line with the EU Cyber Resilience Act's requirement for that scope. It should not be described as covering the entire product.
Is BioStar X v1.0.3 GDPR compliant ? ?
The latest version v1.0.3 strengthens the accountability controls GDPR and similar regulations require, specifically, a recorded history of who accessed, changed, or exported personal data. Full regulatory compliance also depends on how the system is configured and operated by the customer.
Do I need a separate license for Rapid Face Authentication? ?
No. Rapid Face Authentication is on by default on both BioStation 3 and BioStation 3 Max devices with no extra setup or license (firmware update). Multi Face Authentication, for authenticating several people at once, requires a separate paid device license.
Which devices support Rapid Face Authentication?
BioStation 3 and BioStation 3 Max.
What's new for administrators managing day-to-day access control?
Page permissions now go down to the submenu level, with dedicated camera group permissions and automatic deactivation of long-inactive accounts. Additionally, it offers fine-tuned, role-based control rather than broad, all-or-nothing access.
What new hardware does v1.0.3 support? ?
This release adds support for new Suprema hardware and integrations. XPass Q2 previously came only as a DB model, and the new DPB adds PoE. There are also new XPass 2 revisions, DESKO ID-scanner registration, and configurable idle-screen video on the BioStation 3 Max's large screen.
Are there new licensing options in v1.0.3?
Yes. Advanced Access Control (AAC) features are no longer sold as a single bundle. They're now split into individual licenses, so a site only buys what it needs. Map is now included in the Essential tier, and other add-ons are available starting from Essential as well, rather than being locked to higher tiers. When a customer purchases several licenses at once, they can all be activated in a single batch instead of one at a time.