C•CURE ACS Integration Configuration Guide
This guide walks you through integrating the Alcatraz Platform with Software House C•CURE 9000 via the Victor Web Service. Once configured, the Platform syncs credentials, clearances, and personnel data from C•CURE, and sends Alcatraz security events to the C•CURE Journal.
NOTE: Software-based ACS Integrations are a licensed feature from Alcatraz and are not required for a functioning Alcatraz system. Contact Alcatraz Sales for more information.
1. Requirements
| Alcatraz Platform Software |
v3.6.6 or newer (On-prem or Cloud*) |
| C•CURE 9000 |
2.9-SP4, SP5, SP6 Enterprise 3.0-SP1, 3.0.3, 3.0.4 3.1 |
| C•CURE 9000 License |
CC9WS-ALCAI - "Alcatraz AI - Frictionless Access - Integration" For C•CURE 9000 v2.9.0 the license option must be added with an injection script (see Section 2.1). This step is not required for v3.0 or newer. |
| Network Ports |
TCP 443 - outbound from the Alcatraz Platform (or Proxy Service) to the victor Web Service server. TCP 3033 - outbound from the Alcatraz Proxy Service to the Alcatraz Cloud (cloud deployments only). |
* Cloud deployments require the Alcatraz Proxy Service, see Section 4.
Cloud-hosted deployments connect the Alcatraz Proxy Service to your Alcatraz-hosted cloud instance.
2. Configure C•CURE
The following procedure verifies the Alcatraz license and creates the Privilege and Operator that the Alcatraz Platform will use for syncing with C•CURE via the victor Web Service.
2.1. Verify the Alcatraz Integration License
Open License Administration and confirm that "Alcatraz AI - Frictionless Access - Integration" appears under Options.
C•CURE 9000 v2.9.0 only: the license option must be added with an injection script, executed on each C•CURE server (each SAS) that the Alcatraz Platform will connect to. This step is not required for v3.0 or newer.
Create a batch file (sample.bat) with the following contents:
InsertLicenseOption /U /V /S:"WIN-L4C78I7S7D5\SQLEXPRESS" /N:"Alcatraz AI - Frictionless Access - Integration" /A:"Alcatraz AI" /G:5eb9318d-8e8b-49bf-9c61-0f012cb0123f /C:2 /P:0
@pause
In the sample, WIN-L4C78I7S7D5\SQLEXPRESS is the name of the SQL instance where the C•CURE database is located - update it to your actual SQL instance name. The Alcatraz Integration GUID 5eb9318d-8e8b-49bf-9c61-0f012cb0123f must NOT be changed.
EXECUTION
- Copy the batch file to the computer running C•CURE, into: C:\Program Files (x86)\Tyco\CrossFire\Tools
- Right-click the batch file and select Run as Administrator.
- Verify success: launch License Administration and check that Options shows "Alcatraz AI - Frictionless Access - Integration 0/10".
2.2. Create the Privilege
1. In the C•CURE Administration application, select Configuration → Privilege → New.
2. Assign the appropriate partitions to the privilege.

- Personnel → Personnel Records → Credential
- Personnel → Personnel Records → Personnel
- Personnel → Personnel Records → Custom Clearance
- Personnel → Personnel Related → Clearance
- Personnel → Personnel Related → Personnel Type
- Personnel → Personnel Related → CHUID Format
- Controllers → iSTAR → iSTAR Readers
- Controllers → iSTAR → iSTAR Door
- Controllers → Elevators → Elevator
- Configuration → Group
4. Check Enabled, then Save and Close.

5. Under Configuration → Journal Trigger, select Edit → New, check Enabled, then Save and Close. (The Journal Trigger is required for Send Security Events - it allows Alcatraz events to be written to the C•CURE Journal.)

IMPORTANT - partition access. The privilege must include the partitions that contain the doors, readers, personnel, and credentials you want to sync. If a required entity is in a partition the Operator cannot access, synchronization fails even with the permissions above. Grant only the partitions Alcatraz needs - assigning everything makes the integration load unnecessary entities and can slow synchronization.
2.3. Create the Operator
- In the C•CURE Administration application, create an Operator and Add the read-only privilege created in Section 2.2.
- Note the User Name and Password - you will enter them in the Alcatraz Admin Portal in Section 3.2.

NOTE: You can see when this Operator logs in and out in the C•CURE Monitoring Station's Activity Viewer.
3. Configure the ACS Integration in the Alcatraz Admin Portal
3.1. Before You Start
WARNING: When initially enabled, the ACS Integration will delete profiles that do not have at least one badge that is also present in the ACS. It is recommended that a VM snapshot is generated and the system is backed up before attempting to configure an ACS Integration.
IMPORTANT: Card Format Mapping (facility codes): The facility codes for cards to be synced must be configured BEFORE enabling the ACS Integration. Failure to do so could result in the deletion of profiles. In the Card Format Mapping list (Account → ACS Integration), assign facility codes to each card format the Alcatraz Platform should sync with C•CURE. If a card format is missing from the list, add it in the Card Formats section - see Adding Card Formats.
Pre-enable checklist
- Take a full system backup.
- Assign facility codes to the card formats that the Alcatraz Platform should sync with C•CURE.
- If you plan to use CHUID Format Mapping, configure at least one CHUID format before enabling the integration.
- Plan reader-to-Rock mapping.
- Confirm network ports are open (see Requirements).
- Confirm the C•CURE Operator has only the permissions it needs - not full partition access.
Planned C•CURE maintenance: Disable the ACS Integration in the Alcatraz Admin Portal before performing maintenance, upgrades, or restarts on the C•CURE server or the victor Web Service, and re-enable it once C•CURE is fully back online.A full sync starts automatically when the integration comes back online - no manual sync is needed. Disabling matters because the automatic sync also runs whenever a dropped connection re-establishes on its own - if the integration stays enabled while C•CURE is only partially available, that sync may treat missing data as deleted and remove valid profiles.
3.2. Main Settings
In the Alcatraz Admin Portal, go to Account → ACS Integration → Enable ACS Integration, then select C•CURE from the ACS Integration list.

|
ACS Integration |
C•CURE |
|
Client version |
Select the option matching your C•CURE 9000 version: 2.9 - 3.0 or 3.1. (Selecting 3.1 requires Platform v3.4.2 or newer.) |
|
Victor Web Service URL |
victor Web Service URL including the protocol prefix. Example: https://192.0.2.32/victorwebservice/ The victor Web Service may run on a machine other than the C•CURE server - in that case, use that machine's hostname, IP address, or FQDN. |
|
Username |
The C•CURE Operator created in Section 2.3. |
|
Password |
Password for the C•CURE Operator. |
|
Schedule Full Sync |
Time of day to start a full synchronization with the ACS. |
|
Use Proxy Certificate in PEM format |
Enables the Certificate in PEM format download, for use with the Alcatraz Proxy Service (for cloud deployments - see Section 4). Available only when Use Proxy is checked. Click Download to save the PEM certificate, then use it when installing the Alcatraz Proxy Service |
|
Bio opt-out sync |
The C•CURE personnel field used to identify people who have opted out of facial authentication (default: Logical3). Personnel flagged in this field are excluded from biometric enrollment. |
|
Auto delete disabled profiles after |
Grace period after which Alcatraz profiles tied to disabled ACS personnel records are automatically deleted: Do Not Delete (default), 10, 30, or 90 days, or a custom value. Profiles are deleted at midnight based on the chosen time period. |
|
Use CHUID Format Mapping |
Syncs credentials using the CHUID formats defined in C•CURE. Configure at least one CHUID format before enabling this option - enabling it with no CHUID format configured can produce an incorrect initial sync. |
|
Manage Visitors from the ACS |
Syncs C•CURE visitor records so visitors are managed from the ACS. |
|
Send Security Events |
Sends Alcatraz security events to the C•CURE Journal. Requires the Journal Trigger created in Section 2.2, step 5. |
|
Advanced Logging |
Produces more detailed ACS Integration logs, listing exactly which credentials were skipped and why, instead of an aggregate count. |
|
Use Alternate Keep Alive |
Uses an older keep-alive mechanism for compatibility with older C•CURE versions. Enable this only if you experience frequent connection losses. |
|
Disable Data Deletion |
When enabled, Alcatraz only receives information from your ACS - no biometric profiles, credentials, readers, clearance levels, or other applicable information will be deleted in Alcatraz. (Requires Platform v3.4.2 or newer.) |
|
Bio Consent Enrollment* |
Requires explicit consent as part of biometric enrollment for synced personnel. |
Card Format Mapping: below the settings, the Card Format Mapping list shows the card formats and facility codes the integration will use. Card formats themselves are managed in the Card Formats section above (see Adding Card Formats).
Notes:
- Test Connection: click Test Connection to verify communication with C•CURE, then Save. When using the Alcatraz Proxy Service, Test Connection always reports unsuccessful - this is expected; verify via Section 6 instead.
- ACS Integration status can be seen at the top of the "Account" page and in the "ACS Integration" section under "Account."
4. Installing Alcatraz Proxy Service (Cloud Deployments)
Alcatraz Proxy Service opens a connection between the Alcatraz Platform and C•CURE when the two are running in separate networks. Install it on a server that can reach the victor Web Service directly over the network - usually on your own network, often on the C•CURE server itself. The Proxy connects locally to the victor Web Service (TCP 443) and opens a single outbound-only TLS connection to your region's Alcatraz cloud endpoint (US / EU) on TCP 3033, authenticated with your PEM certificate. No inbound firewall ports are required.
Alcatraz Proxy Service is required in the following cases:
- You are an Alcatraz Enterprise Cloud user.
- Your Alcatraz Platform runs on-premises, but it cannot reach the C•CURE server over the network (the two are in separate networks).
- In the ACS Integration settings, check Use Proxy.
- Click Download under Certificate in PEM format and save the file.
- Install the Proxy Service on a Windows Server with visibility to the victor Web Service - follow Installing Alcatraz Proxy Service for OS requirements and installer steps.
- During installation, enter your region's (US/EU) Alcatraz cloud endpoint on port 3033 (endpoints are listed in the install guide).
5. Map C•CURE Card Readers to Rocks
- In the Admin Portal, go to Device Management → Readers.
- Click Add Reader, then type a few characters from the reader's name as it appears in C•CURE - the list shows all readers containing those characters. Select the one you want and map it to the Rock.


NOTE: After mapping a reader to a newly added Rock, run a Full Sync so existing profiles receive access on the new device. Until a sync completes, enrolled users may not be able to authenticate at the new Rock.
6. Verifying the Integration
1. Confirm the service is running (Proxy deployments only): open Services (services.msc) and check that Alcatraz Proxy Service shows Running.
2. In the Alcatraz Admin Portal, open Account. The status at the top of the page should show ACS Online.

3. Run a Full Sync and confirm entries appear in the ACS Integration logs. The ACS Integration section includes the integration logs, a button to start a full sync, and an option to export the logs as a CSV file.

Proxy logs are stored under the Data Directory (default C:\ProgramData\Alcatraz AI\Proxy).
7. Troubleshooting
7.1. Connection
|
Symptom |
Likely cause |
What to check / fix |
|
Test Connection fails (no Proxy) |
Wrong URL or protocol; victor Web Service not running; port 443 blocked |
Verify the URL format (https://<host>/victorwebservice/); confirm the victor Web Service is running (IIS) on the correct machine; confirm TCP 443 is reachable from the Alcatraz Platform. Tip: browse to the Victor Web Service URL from the Platform server — a response page or credential prompt means the service is reachable. |
|
Test Connection fails (Use Proxy enabled) |
Expected behavior |
Verify via the ACS Integration status and sync logs (Section 6) instead. |
|
Authentication error on connect |
Wrong Operator credentials; privilege not enabled; Alcatraz license option missing |
Verify the Operator's username and password; confirm the privilege from Section 2.2 is Enabled and assigned; confirm "Alcatraz AI - Frictionless Access - Integration" appears in License Administration. |
|
Frequent connection drops, especially with older C•CURE versions |
Keep-alive incompatibility |
Enable Use Alternate Keep Alive (Section 3.2). |
|
Integration stays offline after an extended C•CURE outage or network interruption |
The connection does not always re-establish automatically |
Disable and re-enable the ACS Integration in the Admin Portal. In HA environments, verify the integration after failover and failback. |
7.2. Synchronization
|
Symptom |
Likely cause |
What to check / fix |
|
Full sync fails repeatedly |
A facility code used by synced badges is not configured in the Alcatraz Platform |
Configure every facility code in use for the card formats being synced, then run a Full Sync. A single missing facility code will cause the sync to keep failing. |
|
Full sync fails on specific credentials |
A badge number exceeds the parameters of its card format (for example, more bits or digits than the format allows) |
Enable Advanced Logging to identify the affected credentials, then correct the badge number or the card format in C•CURE. |
|
Incorrect or incomplete initial sync with Use CHUID Format Mapping enabled |
No CHUID format is configured |
Configure the required CHUID formats before enabling the option, then run a Full Sync. |
|
Credentials with facility code 0 do not sync, or enrollment fails for them |
Facility code 0 handling conflicts - for example, a Default Facility Code is set in the Platform, or multiple card formats share facility code 0 |
Use only one card format with facility code 0 per account and avoid combining it with a Default Facility Code. Contact Alcatraz Support when planning a facility-code-0 deployment. |
|
Sync runs but some personnel, credentials, or readers are missing |
The Operator's privilege lacks access to the partition containing those entities |
Add the required partitions to the privilege (Section 2.2), then run a Full Sync. |
|
A change made in C•CURE (badge status, clearance, door group) is not reflected in the Platform |
The incremental sync did not capture the change |
Run a Full Sync. If the issue persists, contact Alcatraz Support. |
|
Profiles or access unexpectedly removed after C•CURE maintenance or a network interruption |
A synchronization ran while C•CURE was only partially available, and the sync treated the missing data as deleted |
Disable the ACS Integration before planned C•CURE maintenance (Section 3.1) and re-enable it afterward. Consider enabling Disable Data Deletion (Section 3.2) as a safeguard. If deletions have already occurred, contact Alcatraz Support before running further syncs. |
|
Enrolled users cannot authenticate at a newly added Rock |
Profiles have not yet propagated to the new device |
After mapping the new Rock's reader, run a Full Sync (Section 5). |
7.3. Events
|
Symptom |
Likely cause |
What to check / fix |
|
Alcatraz events not visible in the C•CURE Journal |
Send Security Events disabled; Journal Trigger missing or not enabled |
Enable Send Security Events (Section 3.2) and create/enable the Journal Trigger (Section 2.2, step 5). |
7.4. Upgrades and Proxy
|
Symptom |
Likely cause |
What to check / fix |
|
Integration goes offline after a C•CURE upgrade |
The victor Web Service version no longer matches C•CURE, or the Client version setting no longer matches the installed version |
Upgrade the victor Web Service together with C•CURE; set Client version (Section 3.2) to match. C•CURE 3.1 requires Platform v3.4.2 or newer. |
|
Proxy installed but integration stays offline |
Wrong regional endpoint; outbound TCP 3033 blocked; SSL/TLS inspection; outdated PEM certificate |
Verify the endpoint for your region; check firewall rules and SSL-inspection exemptions; re-download the certificate, replace the file, and restart the Proxy Service. |
|
Profiles were deleted when the integration was first enabled |
Facility codes not configured before enabling; badges not present in C•CURE |
Follow the pre-enable checklist (Section 3.1); restore from backup if needed. |

