Polaris vs Barco ClickShare
| Security question | Polaris Pro | Polaris Essentials | Polaris Host | Barco ClickShare |
|---|---|---|---|---|
| Linux-hardened OS: no Windows attack surfacedevice | ✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site | ✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site | —Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site | ✓Barco ClickShareBarco names no base-unit OS for the C, CX or Bar range. The CX-50 Gen2 spec sheet's "Operating system" field lists only client platforms - "Windows 10 or higher, macOS 11 (BigSur) and higher, Android v11 and higher, iOS 14 and higher" - and no hardening, minimal-image or partition-integrity claim is published for the base unit itself.ClickShare CX-50 2nd generation spec sheet (29 Aug 2024) · read 2026-08-14 |
| Signed firmware / verified boot chaindevice | ✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site | ✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site | ✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site | ✓Barco ClickShareBarco publishes a "ClickShare Conference and ClickShare Present Security Whitepaper", TDE10355 v02, released 9 Oct 2025, listed publicly against C-5, C-10, CX-20, CX-30, CX-50 Gen2, Bar Core, Bar Pro and the Button. The landing page is open but the PDF itself could not be retrieved through its download control in this session, so the firmware-signing and boot-integrity text cannot be read at source by a member of the public via this route.Barco docs page: ClickShare Conference and Present Security Whitepaper TDE10355 v02 · read 2026-08-14 |
| TAA / NDAA 889 statement publisheddevice | ✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site | ✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site | —Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site | ✓Barco ClickShareNot published by Barco. The only TAA document we could retrieve is a Barco-authored compliance overview hosted on the distributor TD SYNNEX's website, dated 2024 — TD SYNNEX makes it available, Barco does not publish it themselves, and nothing on barco.com carries a TAA or Section 889 statement. Nine ClickShare "-US" part numbers are listed with country of origin Taiwan. A distributor cannot be held to a manufacturer's compliance claim, which is why this is graded partial rather than yes.Barco: Your trusted partner for government solutions - TAA-compliant product list · read 2026-08-14third-party host |
| 802.1x / EAP-TLS network authdevice | ✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site | ✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site | ✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site | ✓✓✓Barco ClickShareThe base unit itself is the supplicant, and the methods are named. Network Deployment Guide TDE10396 v06: "In terms of authentication protocols, ClickShare Base Units support PEAP, EAP-TLS and EAP-TTLS" on the wired interface, configured through a wizard in the web Configurator, with "Certificates for EAP-TLS can be provided via the web or rest interface. Alternatively, the baseunit can be instructed to query an NDES server and enroll to acquire a certificate." The same three methods are listed for WPA2-Enterprise wireless client mode. This corrects the earlier reading that only the Button acts as supplicant.ClickShare Conference and Present Network Deployment Guide, TDE10396 v06 · read 2026-08-14 |
| Security architecture documented in the open, ungateddevice | ✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site | ✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site | ✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site | ✓✓✓Barco ClickShareThe 44-page Network Deployment Guide TDE10396 v06 is served directly from Barco's own infopages domain with no form and no login, and carries real architecture content: four named deployment topologies (network connected, dual network, dedicated network, standalone), outbound port and hostname requirements, the base-unit firewall's traffic-bridging behavior, wireless client mode, REST API exposure and 802.1X configuration. Caveat: its scope is the C, CX and Bar base units - ClickShare Hub appears nowhere in it.ClickShare Conference and Present Network Deployment Guide, TDE10396 v06 (ungated PDF) · read 2026-08-14 |
| Independent security test published, and the report or certificate is retrievabledevice | ✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site | ✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site | ✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site | ✓✓✓Barco ClickShareCERTIFICAT ANSSI-CSPN-2026/15, product "CX-50 2nd generation", evaluation center ALMOND, developer and sponsor BARCO NV, validity "date de signature + 3 ans" against a DocuSign stamp of 4/6/2026, and "Dans le cadre de l'accord de reconnaissance mutuelle BSZ_CSPN, ce certificat est reconnu par le BSI." The signed certificate PDF is retrievable from the ANSSI registry and is also linked from Barco's own Trust Center. The certificate itself limits it: "Ce certificat s'applique uniquement a cette version specifique de produit dans sa configuration evaluee."ANSSI CSPN certificate ANSSI-CSPN-2026/15, ClickShare CX-50 2nd generation · read 2026-08-14independent registry |
| Third-party security assessment of the room device itself, not the cloud or the OSdevice | ✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site | ✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site | —Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site | ✓✓✓Barco ClickShareThe CSPN evaluation is device-level - category "Materiel et logiciel embarque" - and Barco publishes its own scope FAQ. The evaluated configuration is one Base Unit at firmware 02.20.02 with a paired Button and Desktop App v04.37.5, factory reset, Security Level 1, SNMP and Blackboarding off, LAN over DHCP, no proxy, single network, client mode disabled, WebUI on a self-signed certificate. Barco's own "not covered" table excludes XMS Cloud, remote management, enterprise network client mode, dual-network operation, proxy, AirPlay, Google Cast, Miracast, PresentSense, API access, third-party peripherals and "UC / MTR / room system integrations."Barco KB 16024 - ClickShare ANSSI CSPN Certification Scope FAQ (last updated 8 Jun 2026) · read 2026-08-14 |
Published evidence at a glance
Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Barco ClickShare has qualified documentation for the hardened Linux appliance; signed firmware and verified boot; the TAA and NDAA 889 statement.
Mersive Polaris
Strengths
- Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
- Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
- An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
- The security architecture is publicly available without registration.
- The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
- Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
- The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
- The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
- The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
- Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
- Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.
Barco ClickShare
Strengths
- Publishes in full on 802.1X network authentication, an ungated security architecture, a retrievable independent security test, and a third-party assessment of the room device.
- Publishes more than Mersive does on a retrievable independent security test.
Limitations
- The published evidence has qualifications. For the hardened Linux appliance; signed firmware and verified boot; the TAA and NDAA 889 statement, Barco ClickShare provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source. Mersive publishes evidence covering these questions in full.
- The reviewed Trust Center page lists ISO/IEC 27001:2022, a CyFun label, and the ANSSI CSPN certificate. No SOC 2 report, bridge letter, or SOC 3 was found in the reviewed documentation.
Sources +
Every document below is Barco ClickShare’s own unless the badge says otherwise.
| Document | Read for | Retrieved |
|---|---|---|
| ClickShare CX-50 2nd generation spec sheet (29 Aug 2024) | the hardened Linux appliance | 2026-08-14 |
| Barco docs page: ClickShare Conference and Present Security Whitepaper TDE10355 v02 | signed firmware and verified boot | 2026-08-14 |
| Barco: Your trusted partner for government solutions - TAA-compliant product list third-party host | the TAA and NDAA 889 statement | 2026-08-14 |
| ClickShare Conference and Present Network Deployment Guide, TDE10396 v06 | 802.1X network authentication and an ungated security architecture | 2026-08-14 |
| ANSSI CSPN certificate ANSSI-CSPN-2026/15, ClickShare CX-50 2nd generation independent registry | a retrievable independent security test | 2026-08-14 |
| Barco KB 16024 - ClickShare ANSSI CSPN Certification Scope FAQ (last updated 8 Jun 2026) | a third-party assessment of the room device | 2026-08-14 |