Every quote for a security system is a price to enter. None is a price to leave.

That is not a trick anybody is playing on you. Quotes answer the question buyers ask, and buyers ask what it costs to get the cameras up and the doors locked. At the moment of signing, getting out is not on anyone's mind, so the number never gets calculated, written down, or negotiated.

Then it gets calculated for you, years later, in the worst circumstances: the software moved to a subscription model you did not budget for, the company that installed everything was acquired, service quality slid, or you want a competitive quote and discover you cannot meaningfully get one.

This article is about calculating that number early. It is emphatically not an argument against committing to a vendor — commitment buys real things, and a platform that genuinely integrates video with access control does more than two systems bolted together. See what a unified platform actually unifies for what that buys when it is done well. The argument is narrower: know the price of the exit before you need it. The only moment you have leverage to ask is before you sign. Afterwards you are not negotiating, you are appealing.

Five questions produce the number.

1. Whose is the data?

Start with video — the largest pile of data your building generates and the one most likely to matter in a dispute.

There is a difference between being able to view your recordings and being able to take them. Every system lets you view. Not every system lets you leave with a complete, usable copy of what it holds — or of the metadata that makes recordings findable, which is often the more valuable half. A year of footage you can only search inside one vendor's interface is a year of footage that ends when that interface does.

Ask three specific things:

  • Can recordings be exported in a standard container that plays outside the vendor's own player, at full recorded quality, in bulk — not clip by clip?
  • Does the event and metadata history come with it — analytic events, timestamps, camera names, the search index — or does the export produce video files with nothing to search them by?
  • Is there a documented path for a bulk export at the end of the relationship, and is it a supported operation or a professional-services favour?

The same question applies to access control, where the data is smaller but the consequences sharper. Your door event history is the record of who went where and when — what you reach for after an incident, a claim, or a dispute with a former employee. If it lives only inside a system you are leaving and cannot be exported into something readable, your history of the building ends the day you change vendors. That is not an archive. It is a subscription to an archive.

There is a governance point underneath this that owners miss. Under British Columbia's Personal Information Protection Act, an organization must protect the personal information in its custody or under its control with reasonable security arrangements (s.34), and must destroy or de-identify it once it is no longer needed for the purpose it was collected for and no longer required legally (s.35). Recordings of identifiable people are personal information. Those duties attach to you. They do not transfer to your integrator or a cloud provider because the footage sits on their equipment. So if you cannot get the data out, you still owe the obligations over it — and if the vendor keeps a copy after you leave, you need to know what happens to it. More in where your video actually lives and what your access control logs mean under PIPA.

Get in writing: export format, whether metadata is included, and what happens to the vendor's copy on termination.

2. Whose are the credentials?

This is the sharpest exit cost in the building, and it has its own article: the one question to ask your integrator about diversified site keys. Read that for what a site key is and why it should be unique to your building. This section is only about what it does to your exit.

A modern encrypted access credential works because the card and the reader share a secret. Whoever holds that secret can issue cards your readers will accept. Whoever does not, cannot — no matter how skilled they are or what hardware they install.

So if the key to your building is held by your integrator and by nobody else, changing integrators means re-badging the building. Not re-programming. Re-issuing physical credentials to every resident, employee, cleaner and contractor, and collecting the old ones. In a large residential or mixed-use property that is a project with a budget and a schedule, and it will land in a year you did not plan for it.

That cost is invisible on the original quote and entirely avoidable, by asking one question before commissioning rather than after: is the key unique to this site, and where is it held? Escrow naming you as owner turns a re-badging project into an afternoon of paperwork.

The reader wire has a parallel worth knowing. The Security Industry Association maintains OSDP, an open protocol for the reader-to-controller connection, published by the IEC as IEC 60839-11-5:2020. A supervised, open connection there is one less proprietary link in the chain you would have to replace. No mandate requires it in Canada, and anyone telling you otherwise is selling — but the exit logic favours it. The wire behind your reader covers the rest.

Get in writing: that site keys are diversified per site, where the key material is held, and what your route to it is if the relationship ends.

3. What is actually reusable?

When a system changes hands, the estate splits into three piles, and owners are usually surprised by where things land.

Almost always survives: cabling, conduit, back-boxes, mounting hardware, power infrastructure. This is the expensive, labour-heavy part of an installation — the part involving ladders, ceilings and drywall — and it is largely vendor-neutral. That is why a system change is never a total loss.

Usually does not survive on the access control side: readers and controllers. A controller is the brain of a specific manufacturer's system and generally goes when that system goes. Readers are more nuanced — some can be re-flashed or reconfigured, many cannot, and whether yours can is a question your integrator can answer today.

Depends entirely on openness, on the camera side: the cameras. This is the one place where a decision made at purchase determines the answer years later. A camera conforming to a published interoperability profile can be adopted by a different recorder or video management platform. A camera speaking only its manufacturer's protocol cannot, and the fact that it is a perfectly good camera makes no difference.

Here is where owners get misled by a line on a quote. "ONVIF compliant" with no profile letter attached tells you nothing — a device conforms to specific lettered profiles, and one conforming to a profile your next recorder does not use is, for your purposes, a device that does not interoperate. A conformance claim is also a manufacturer's self-declaration published in ONVIF's list, not a certificate from an outside testing body, so check the specific model in that list rather than trusting a marketing line. What ONVIF profiles actually mean explains how to ask.

One number you can estimate before signing: ask your integrator, in writing, which line items on this quote would still be in service if the platform changed. The answer sorts the quote into infrastructure and commitment. What an open-platform VMS actually costs covers the tradeoff honestly — open is not free, and pretending otherwise is its own sales pitch.

Get in writing: the ONVIF profile letters for every camera and for the recorder, and a plain statement of which hardware is platform-specific.

4. What is leased and what is owned?

Bundled pricing has quietly become normal in security, and it is often a genuinely good deal — one monthly figure covering hardware, software, monitoring and maintenance is easier to budget than a large capital outlay followed by unpredictable service bills.

But a bundle can be structured two very different ways that look identical on an invoice. In one, you bought the equipment and are paying for services around it. In the other, the equipment remains the vendor's property for the life of the agreement and the monthly figure includes its use. Under the second, cancelling does not mean you keep the cameras and stop paying for the software. It may mean the cameras come off the wall.

There is no dishonesty in either model. What causes damage is not knowing which one you are in — and that happens routinely, because the question is never asked and the answer lives in a schedule nobody reads. It also shapes a property sale: what you cannot show title to is not part of what you are selling, and an unassignable equipment agreement found during diligence is a problem for your side of the table.

Cloud and hybrid arrangements add a layer, because there the ongoing charge covers storage and processing with no physical form to repossess. Three things to settle before going hybrid cloud covers what to pin down.

Get in writing: an itemized statement of what you own outright at each stage of the agreement, and what happens physically to any leased equipment at termination.

5. What shape is the contract?

Finally, the paperwork — where the useful move is not to hunt for villains but to read for structure. Four features determine your exit, and every one is knowable before you sign:

Term and renewal mechanics. Does the agreement renew automatically, and for how long each time? Auto-renewal is not a problem in itself; it becomes one when the notice window sits inside a renewal you already triggered by not writing a letter.

The notice window. When does it open, when does it close, to what address, and in what form? Put the opening date in your calendar on the day you sign. That single administrative act is the cheapest insurance in this article.

Assignability. Can the agreement be assigned if you sell the building, and can the vendor assign it if the vendor is acquired? Both directions matter and they are frequently drafted asymmetrically.

Who holds the administrator password. Not a service account — the top-level administrative credential on your video platform and your access control system. If only the vendor holds it, you do not fully control the system you paid for. This is the site key question wearing different clothes.

None of this requires an adversarial posture. A good integrator has answered these before and finds them unremarkable. Vagueness is the signal, not refusal.

The list to get in writing at purchase

These belong in the scope of work or the agreement itself, not in a conversation.

  1. Export format for video, at full recorded quality, in bulk, playable outside the vendor's player.
  2. Export of event and search metadata, not just video files.
  3. Export of access control event history in a readable, documented format.
  4. Disposition of the vendor's copy of your data on termination, and the confirmation you receive.
  5. Diversified site keys per site, with the key material escrowed and you named as owner.
  6. A defined handover of key material on termination, written into the agreement.
  7. ONVIF profile letters for each camera and for the recorder or platform, with the model as listed in ONVIF's conformant product list.
  8. An owned-versus-leased schedule, itemized, with what happens to leased equipment at the end.
  9. Term, renewal mechanics and notice window, with the notice opening date entered in your calendar on signing day.
  10. Named holder of the administrator credential, and the process for you to obtain it.

Ask for these while you are still a prospect. That is the entire trick. The same ten questions asked eighteen months into a difficult relationship are ten requests for a favour; asked before signature, they are ordinary line items in a competitive process — and the vendor who answers them cleanly has told you something useful about how they will behave later.

You may still choose to commit deeply to one platform. Often that is the right call. Just make it a choice you priced, rather than one you discover you made.

Sources

  • Personal Information Protection Act (SBC 2003, c. 63), ss. 34 and 35 — https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/03063_01
  • ONVIF, Profile Q (profile listings, conformance and Declaration of Conformance model) — https://www.onvif.org/profiles/profile-q/
  • Security Industry Association, Open Supervised Device Protocol (OSDP) — https://www.securityindustry.org/industry-standards/open-supervised-device-protocol/