Home/Platform/Security & Trust Center

The Trust Center

Polaris security architecture, independent assessments, and the documents your team needs for its review.

Security at a glance

Secure boot & supply chain

Polaris ships with secure boot on a TAA-compliant supply chain. The device verifies Mersive-signed firmware before it runs.

Hardened Linux

A purpose-built, minimized Linux operating system designed for the room device.

Independent assurance

Our information security management system is ISO/IEC 27001:2022 certified, with no nonconformities at the June 2026 surveillance audit. SOC 2 Type 2 and SOC 3 cover the Polaris cloud management console. The room devices have a separate, independent physical assessment. Scopes and results are detailed below.

802.1X / EAP-TLS

Certificate-based wired network authentication supports your organization’s network access controls.

Security architecture

How Polaris protects the room and its connections.

Explore the device, cloud, and network controls behind Polaris. Certification scopes and independent assessment results follow below.

Boot & supply chain

Hardware-rooted secure boot verifies each stage through to the signed kernel. It is mandatory on production firmware. The device’s private keys are generated inside a secure element and never leave it.

The trust chain starts in hardware, before the OS. A key burned into the processor’s fuses verifies the first-stage bootloader. That bootloader verifies the signed firmware package carrying ARM Trusted Firmware and the bootloader proper. The bootloader then verifies the signed kernel image before handing over control. The root of that chain is a key hash burned into one-time-programmable fuses and locked, so it is fixed for the life of the device. Every signing key after it (the one covering ARM Trusted Firmware and the bootloader, and the one the bootloader uses to verify the kernel) can be rotated in a firmware release.

Secure boot verifies Mersive-signed firmware before it runs and is mandatory on production firmware. The device also performs integrity checks: on every boot, before the product starts, it reads the processor’s fuses and confirms the root-of-trust hash and the lock bits are burned. A device that was never fused, or whose model it does not recognize, refuses to start the product and comes up in a maintenance console instead. The same boot gate verifies that all five key objects provisioned into the onboard NXP SE050 secure element, which holds the device’s own identity and update-verification keys in hardware, are present and readable. An allowlist controls USB device access. Polaris ships with secure boot on a TAA-compliant supply chain. The secure element has specific change controls within the hardware lifecycle: replacing it requires CISO approval and an update to this page.

Device keys and network credentials. The device’s private keys are generated and used inside the secure element. The application requests cryptographic operations without receiving the keys. GlobalPlatform SCP-03 authenticates and encrypts communication with the element. The keys for that channel are held in ARM TrustZone secure firmware, outside the reach of the operating system and its applications. Customer 802.1X credentials use separate storage: certificates go to the device’s persistent certificate store, and the private-key password is held as a system-stored NetworkManager secret.

Signed firmware updates. Each update package is checked for authenticity and integrity before it is applied. The device rejects administrator-initiated downgrades to earlier firmware, preventing older versions from being reinstalled to reopen a fixed vulnerability.

Automatic recovery. The device holds two firmware partitions. A new image installs alongside the running version. If the new version fails to boot, the device returns to the last known-good version. This recovery process is separate from an administrator-initiated downgrade.

Session content. Shared content is assembled for the display without being written to the device. Ephemeral session data, including content, session keys, and their random values, is overwritten when the session ends, including sessions that are abandoned.

These controls describe the Gen 4 security architecture. The independent device assessment below documents its tested scope and findings.

In the cloud

Polaris Cloud brokers sessions and manages fleets without storing workspace content. It runs on Google Cloud, with administrative access controlled through IAM and multi-factor authentication. The Security Committee reviews its policies annually.

Polaris Cloud brokers sessions and manages fleets. It does not store workspace content. The signaling service exchanges session-setup messages between endpoints. Shared content travels directly between meeting devices without passing through Mersive servers. The cloud holds device and fleet data: configuration, firmware state, usage analytics, and alert settings.

Hosting
Google Cloud
Network
firewall rules and access controls
In transit
TLS from a public certificate authority
Admin access
administrative access behind IAM and multi-factor authentication
Availability
failover across multiple availability zones

Data classification. Under the audited data-management policy, room names, session names, device metadata, operating-system information and anonymized usage data are all classified Confidential. The classification levels are Confidential, Restricted and Public, with Restricted the default.

Security policies. The Security Committee reviews and approves the following policies annually. That review is an audited control.

  • Access control
  • Asset management
  • Business continuity and disaster recovery
  • Code of conduct
  • Cryptography
  • Data management
  • HR security
  • Incident response
  • Information security
  • Information security roles and responsibilities
  • Operations security
  • Risk management
  • Secure development
  • Third-party management

On the network

802.1X supports certificate-based authentication over Ethernet and Wi-Fi. Customer certificates are stored on the device; its secure element holds the device’s own identity keys. Wired and wireless connections remain isolated, allowing guests to share over Wi-Fi without access to the corporate LAN.

802.1X network authentication with EAP-TLS, PEAP, TTLS or EAP-PWD, on the wire and over Wi-Fi (WPA2-Enterprise). TTLS inner authentication supports PAP, CHAP, MSCHAP and MSCHAPv2; PEAP supports MSCHAPv2, GTC and MD5. The 802.1X certificate and its private-key password are held on the device, protected by secure boot and the hardened OS rather than sealed inside the secure element: the element holds the device’s own identity and update-verification keys. The pod holds an address on a wired network and a wireless network at the same time and does not route between them: its firewall drops every forwarded packet, and the firmware never enables IP forwarding. This keeps guest Wi-Fi separate from the corporate LAN.

In transit

Signaling and fleet management run outbound over HTTPS to Polaris Cloud. The device itself exposes no TLS listener. Same-network sessions stay on your LAN and cross-network sessions are direct, encrypted WebRTC between device and display, so shared content does not transit Mersive.

Workspace streams and signaling are encrypted with TLS. Same-network sessions stay on your LAN; cross-network sessions are direct, encrypted WebRTC between device and display, so content does not transit Mersive. See connection and data-flow details on the cross-network page.

Update policy

Local wireless sharing continues if a Polaris subscription lapses.

An active Polaris subscription includes software updates, security updates and new capabilities. Full warranty while on active subscription.

You can review firmware changes and release history on the firmware & release notes page.

Certifications

Certifications and their scope.

ISO/IEC 27001 covers the information security management system. SOC 2 Type 2 and SOC 3 cover the Polaris cloud management console. Review the scope and results of each below.

ISO/IEC 27001:2022

Certificate
011964-03
Issued by
BARR Certifications LLC
Registered
28 June 2024
Current issue
30 June 2026
Valid to
26 June 2028
Scope
the ISMS supporting the Mersive Collaboration Suite (Solstice Cloud System)
Against
statement of applicability v5.0, dated 18 June 2026

The June 2026 surveillance audit raised no nonconformities. The clause areas and Annex A control testing met design and operating effectiveness requirements. No nonconformities remained open from the prior year.

Scope exclusions. The June 2026 audit revalidated both exclusions: the physical-security controls of Annex A.7 are excluded because customer data sits in Google Cloud, and A.8.30 outsourced development is excluded because there is none.

Operating environment. “No physical locations were in scope. The scope of Mersive's ISMS operates in a fully virtual environment.”

SOC 2 Type 2 & SOC 3

An independent CPA firm examines the system annually.

Auditor
BARR Advisory, P.A.
Criteria
security, confidentiality and availability
Period
1 March – 31 May 2025
Opinion dated
15 July 2025
System in scope
the Polaris cloud management console
Excluded
Mersive SMART, Mersive Essentials and Mersive Pro

The reports cover entity-level controls and the Polaris cloud management console. Room appliances sit outside the attested system boundary and have separate independent testing, summarized below.

HIPAA control coverage

Within the SOC 2 examination, the opinion also covers controls implemented to meet 45 C.F.R. §164.308, the HIPAA Security Rule administrative safeguards. These auditor-reviewed controls support healthcare security reviews. This coverage is not a separate HIPAA certification.

NIST and HITRUST mappings

For procurement reviews, a control-by-control mapping of NIST SP 800-171 Rev. 2, as required by DFARS, is published inside the report.

For healthcare reviews, the report also maps our controls to HITRUST CSF v11.5, so a healthcare reviewer can read across to the framework their questionnaire is built on. This is a control mapping, not a HITRUST certification or CSF assessment.

The document section below includes public certificates, summaries, and technical references. SOC 2 Type 2 and full penetration-test reports are available on request under NDA.

46 controls across 11 families were examined, and the report records a single exception, on the HR control covering annual performance evaluations: the exception concerns a people-process control; the report records no exceptions in access control, encryption, logging, change management, vulnerability management or incident response. Management's response is published in the report alongside it. SOC 3 is the general-distribution report; SOC 2 Type 2 is available on request under NDA.

Independent testing

Independent testing of the application and room devices.

Annual third-party penetration testing is a commitment in the SOC 2 report, with four engagements across 2025 and 2026 on file. Two consecutive annual application assessments reported no critical or high-severity findings. The testing standard advanced from OWASP ASVS 4.0.3 Level 1 to OWASP ASVS 5.0.0, covering every Level 1 control and a subset of Level 2. The application assessment and the separate physical device assessment are summarized below.

The assessments cover different parts of the platform: application controls, the room device’s network exposure, and physical access to the hardware. Each summary identifies the tested scope, date, and results.

The application, July 2026

Standard
OWASP ASVS 5.0.0, all Level 1 plus a Level 2 subset
Assessed
July 2026
Result
No critical, no high-severity findings

Publicly reachable endpoints were probed for account information and found free of defects.

Testing confirmed token integrity and signature validation, object-level authorization on tenant-owned records, injection and output-encoding defenses, mass-assignment protection and client-side component currency. For authentication, every in-scope token-handling control passed: forged, mutated, truncated, expired and foreign-project tokens were all rejected. This included a token from a different Firebase project signed by the same Google key.

The room device, July 2026

In the same engagement, network testing of the managed Pod surfaced no significant attack surface: the open ports are the casting and appliance functions, and no persistent media listener was enumerable at all. The real-time media path uses ephemeral, per-session UDP ports that answer only after ICE consent, so there is no standing media service on the room device to probe.

This network scan complements the separate physical device assessment below.

The device on the bench, May 2025

The tester was modeled as someone with technical skill, physical access to the device and the public documentation, whose goal was to gain logical access and turn the device into a man-in-the-middle or snooping agent without leaving evidence of tampering.

In scope
Gen 4 Pod and Gen 4 Pod Mini
Assessed
May 2025
Result
No findings at any severity: critical, high, medium or low. One informational entry.
Root over the debug UART
Root access was refused without a password prompt. No other working credentials were found.
JTAG
Header too small for standard probes and hard to source; desoldering failed; even with a harness we supplied, the debugger would not negotiate.
Firmware extraction
The flash is a ball-grid-array package, impractical to reach without JTAG.
Man-in-the-middle
The device rejected the invalid certificate and ended the handshake without establishing a connection.
Data at rest
No personally identifiable information was found stored on either device.

Assessment limits. The assessor concluded that compromise would require significant skill and effort. The result does not establish that compromise is impossible.

The results above summarize the assessments. Full reports, including findings and assessment limits, are available to customers on request under NDA.

Security comparisons

Compare the evidence behind each system.

The comparisons below separate company-level assurance from device-level controls. The company table covers ISO 27001, SOC 2, and the published scope. The product cards cover operating systems, signed firmware, network authentication, independent testing, and other device security evidence.

Certificate scopes vary. Some name a product; others cover a cloud service, management system, or a specific software version. Each comparison links to the source so your team can check whether the evidence applies to its planned deployment.

The comparisons use vendor documentation and public registries: ANSSI, BSI, the Common Criteria portal, NIST CMVP, FedRAMP, the DoDIN APL, and CSA STAR. Ratings reflect the availability and scope of documented evidence. They do not rate a product’s security or establish whether unpublished testing has taken place. Select a cell to read the supporting detail and source. Last updated August 2026.

The company

Company-level certifications and attestations, with their published scope and sources. Device controls are detailed in the product comparisons below.

Security questionMersiveBarcoCrestronKramerWolfVisionExtronAirtameScreenBeamBenQYealinkDisplayNoteViviCiscoMicrosoftZoom
SOC 2 report on file✓✓✓PolarisMersive publishes the SOC 3 summary openly on this page, with no NDA and no form; the full SOC 2 Type 2 report is available from here once an NDA is executed. That Type 2 was examined by BARR Advisory over 1 March to 31 May 2025 on the security, confidentiality and availability criteria, with one exception in the whole examination and that one on annual performance evaluations, a people-process control. Read the scope before the badge: the attested system is the Polaris cloud management console, and the report excludes the appliances by name.Get the reports · on this site—Barco ClickShareBarco publishes no SOC 2 report, bridge letter or SOC 2 reference. The Trust Center certificates page carries exactly three security items - ISO/IEC 27001:2022, a CyFun label and the ANSSI CSPN certificate - plus quality and medical ISO certificates, and closes with "note: more certificates will be added soon."Barco Trust Center - Certificates index · read 2026-08-14—Crestron AirMediaCrestron states the absence itself. The Certifications section of the Security Reference Guide: XiO Cloud Provisioning and Management Service, Doc. 8561G, dated 11/18/25, reads in full: "Crestron does not currently possess a SOC 2 Type 2 certification. However, since the XiO Cloud service is hosted on Microsoft Azure, several of the technical controls in use have been verified as a part of Microsoft's SOC 2 report for Azure." The Trust Center's compliance list carries no SOC 2 entry.Crestron Security Reference Guide: XiO Cloud, Doc. 8561G (11/18/25) · read 2026-08-14—Kramer VIANo SOC 2 report, Type 1 or Type 2, is published or referenced. Kramer's complete certificate index lists only ISO 9001, ISO 45001, ISO 14001 and ISO 27001, and no SOC 2 reference appears on the VIA product pages, the VSM on Cloud page or the platform brochure.Kramer Quality Policy - complete certificate index · read 2026-08-14—WolfVision CynapWolfVision's only security page is a responsible-disclosure policy (reporting address, PGP key, two-business-day acknowledgement). No SOC 2 Type 1 or Type 2 is referenced there, on the TAA page or in the Cynap Videobar Security White Paper. WolfVision publishes no statement of a SOC 2 report; note also that vSolution Link Pro is customer-hosted software rather than a WolfVision-operated cloud service.WolfVision Security page (responsible disclosure) · read 2026-08-14—Extron ShareLink ProNo SOC 2 Type 1 or Type 2 is referenced in any retrievable Extron ShareLink Pro document. The management platform Extron names for ShareLink Pro is GlobalViewer Enterprise, on-premises server software rather than a vendor-operated cloud, so no cloud service is presented for which a SOC 2 would apply. Note extron.com blocks automated retrieval, so a SOC 2 statement could exist there unread.Extron ShareLink Pro 1100 brochure 68-3623-01 Rev A · read 2026-08-14—AirtameAirtame claims no SOC 2 of its own. The only SOC reference on its security page belongs to its hosting provider: "The Airtame Cloud solution is hosted on Amazon Web Services... AWS is a multi-certified datacenter provider, including ISO 27001:2013 and SOC 1, 2 and 3 reports." That is AWS's attestation, not Airtame's.Airtame Security / Information Security Notice (Dec 2024) · read 2026-08-14—ScreenBeamNo SOC 2 Type 1 or Type 2 is referenced on the 1100 Plus datasheet, the public security overview or the site footer's legal index, despite ScreenBeam Cloud being a prerequisite for its paid Administrative Tools. ScreenBeam publishes no SOC 2 statement covering ScreenBeam Cloud or CMS Enterprise.ScreenBeam - How Secure is Wireless Display for my Business? · read 2026-08-14—BenQ InstaShowBenQ operates no trust center and publishes no SOC 2 Type 1 or Type 2 for DMS, AMS, X-Sign or BenQ account services. The only SOC 2 wording BenQ publishes is about its suppliers: "All providers are strictly audited for their compliance with key data protection regulations and standards, including ISO certifications, SOC 2, GDPR readiness, and regional laws."BenQ 'How BenQ Leverages Secure Cloud Services' (vendor SOC 2 attributed to providers) · read 2026-08-14✓Yealink RoomCastA SOC 2 Type 2 is published and dated 07/07/2025 on the Trust Center register, but two caveats. The report is not public: "This report is restricted to clients of the company's services. To obtain a copy, please contact a Yealink sales representative or SE." And the scope is the cloud, not the room device - Yealink describes YMCS, the Yealink Management Cloud Service, as the system that "has passed SOC2 Type 2 and GDPR certifications." No audit firm, period or Trust Services Criteria are disclosed publicly. A SOC 3, normally intended for unrestricted distribution, is listed at 03/09/2026 but sits behind a captcha form. (The linked page renders its content with script, so a plain fetch returns an empty body — open it in a browser.)Yealink Trust Center - SOC 2 Type 2 report access page · read 2026-08-14Yealink RoomPanel Series and RoomCast E2 Security White Paper (Dec 2025) · second source—DisplayNote MontageDisplayNote publishes no SOC 2 Type 1 or Type 2, no bridge letter and no NDA-gated report portal. The only SOC wording on any DisplayNote property belongs to its hosting providers: "Azure's data centers are geographically dispersed and comply with ISO/IEC 27001:2005, SOC 1, and SOC 2" and the same sentence for AWS. A third provider, DigitalOcean, is named with no certification claim attached at all.DisplayNote 'Network infrastructure' support article (certifications attributed to Azure and AWS) · read 2026-08-14—ViviVivi's own FAQ answer to "What security certifications, audits, or compliance standards does Vivi meet?" names ST4S and "enterprise security standards" and nothing else. No SOC 2 Type 1 or Type 2 is claimed for Vivi Central or any Vivi service, publicly or under NDA.Vivi FAQ, Network & Security section (page modified 18 Mar 2026) · read 2026-08-14✓Cisco Room BarA Webex Suite SOC 2 Type 2 report exists and Cisco makes it available on request through the Cisco Trust Portal, which requires a sign-in. It is not retrievable by a member of the public, its scope is the Webex cloud service rather than the room endpoint, and Cisco's own ungated Webex compliance page lists GDPR, HIPAA and ISO/IEC 27001 and does not mention SOC 2 at all.Webex Suite Meetings Security technical paper (industry standards section) · read 2026-08-31✓Microsoft MTRMicrosoft holds a current SOC 2 Type 2, but it is not retrievable by the public. The Microsoft 365 report downloads only from the Service Trust Portal, which requires a subscription sign-in, and the downloaded report is marked Microsoft Confidential under NDA terms that forbid redistribution. Its scope is the cloud service, not the room appliance, and no SOC 3 summary was found.System and Organization Controls (SOC) 2 Type 2 (Microsoft compliance offerings) · read 2026-08-30✓Zoom RoomsZoom holds a current SOC 2 Type 2 and, unusually for this page, publishes its period and its scope ungated: "October 2024 to October 2025", with "Zoom Rooms" named in the covered-product list. The report itself sits behind trust.zoom.com and requires registration rather than an NDA, its scope is the cloud service rather than the room appliance, and no SOC 3 summary was found.Zoom SOC 2 Type 2 (zoom.com trust center, scope list names Zoom Rooms) · read 2026-08-14
ISO 27001✓✓✓PolarisISO/IEC 27001:2022, certificate 011964-03, issued by BARR Certifications LLC on 30 June 2026, with the Year 2 surveillance report on the same date. The certified scope is the information security management system supporting the cloud, not a product certification, and our certification body inspects this site every year for exactly that distinction. Product-level assurance is the penetration testing below.Certificates and scope · on this site✓✓✓Barco ClickShareCertificate BE18/819943326, ISO/IEC 27001:2022, Barco NV, issued by SGS ICS Italia, Issue 11, certified since 4 January 2019 and valid 16 January 2026 to 4 January 2028. The scope names the product line directly: the ISMS covers "hard- & software design and development, manufacturing... sales, deployment, and support of: the wireless collaboration (ClickShare) product line the cloud management services (XMS) product line" across five named sites. It also states that ISO 27017:2015 and ISO 27018:2019 controls sit inside Statement of Applicability v4, so those two are control sets, not separate certificates.Barco NV ISO/IEC 27001:2022 certificate BE18/819943326, SGS ICS Italia · read 2026-08-14—Crestron AirMediaNo ISO 27001 certificate or claim is published. The Crestron Trust Center, scoped to "the XiO Cloud service" and updated 15 August 2026, lists exactly four compliance items: CSA STAR Level 1, NIST 800-53 Rev. 5, TX-RAMP Level 2 and VPAT. ISO 27001 is not mentioned there, nor anywhere in the XiO Cloud Security Reference Guide, whose entire Certifications section is the SOC 2 paragraph.Crestron Trust Center (SafeBase), compliance list · read 2026-08-14✓Kramer VIAKramer publishes an ISO 27001 certificate only as an image, and the certificates page at kramerav.com/certificates/iso-27001 is a client-rendered shell whose entire retrievable body is the heading 'ISO 27001' plus an empty image placeholder - re-fetched 15 Aug 2026. The certificate is visible only on the Quality Policy index, as a 250-pixel thumbnail whose file name is LISO_27001_2013_E-250x250.jpg, indicating the superseded :2013 edition. Version, certificate number, scope, issuing body and validity are all unreadable. Note also that ISO 27001 certifies an organizational ISMS, not a product, while Kramer's VIA brochure attaches it to VIA.Kramer Quality Policy page - certificate index (ISO 27001 shown as a 250px thumbnail) · read 2026-08-15 · confidence med—WolfVision CynapNo ISO 27001 claim, certificate number or registrar appears on WolfVision's security page, TAA page, or the Cynap Videobar Security White Paper, which sets out the company's security program in full and cites no external certification. WolfVision publishes no ISO 27001 statement; that is not the same as holding no certificate.WolfVision Security page (responsible disclosure) · read 2026-08-14—Extron ShareLink ProNo ISO 27001 claim, certificate number or registrar appears in the ShareLink Pro 1100 or 2500 brochures or the 2500 User Guide. Extron's only publicly reported management-system certification is ISO 9001 (quality, not information security), and that claim itself sits on extron.com, which blocks automated retrieval and could not be read here.Extron ShareLink Pro 1100 brochure 68-3623-01 Rev A · read 2026-08-14—AirtameSame page, same inheritance: the ISO 27001:2013 reference on Airtame's security page is AWS's, cited as evidence about the datacenter provider. Airtame publishes no ISO 27001 certificate, number or registrar for its own ISMS; its only registry artifact is a CSA STAR Level 1 self-assessment.Airtame Security / Information Security Notice (Dec 2024) · read 2026-08-14—ScreenBeamNo ISO 27001 claim, certificate number or registrar appears on the 1100 Plus datasheet, whose only listed approvals are FCC, UL, IC ISED, CE RED, RoHS and C-Tick, nor on the public security overview or the footer legal index. ScreenBeam publishes no ISO 27001 statement.ScreenBeam 1100 Plus data sheet - Regulatory and Compliance · read 2026-08-14✓BenQ InstaShowA company-level ISMS certificate, not a product or product-line one: "After undergoing stringent reviews by the British Standards Institution (BSI), BenQ was awarded the ISO/IEC 27001:2013 certification on September 14, 2020." It names no certified legal entity, no sites and no scope, it is to the withdrawn :2013 edition, and BenQ publishes no :2022 claim anywhere despite the 31 October 2025 transition deadline having passed.BenQ ISO 27001 certification announcement (15 Sep 2020) · read 2026-08-14✓Yealink RoomCastYealink publishes a current-edition entry, "ISO/IEC 27001:2022", dated 07/11/2025 on its Trust Center register - one of the few competitors past the :2022 transition. But the certificate itself cannot be retrieved: the linked page is nothing but a lead form and captcha, "Please complete the form and we will send the reports to you", so no certificate number, no registrar, no scope statement and no validity window is visible. Yealink's ISO 9001, 14001, 45001 and 14064 certificates download directly; ISO 27001 and both SOC reports alone route to the gate. (The linked page renders its content with script, so a plain fetch returns an empty body — open it in a browser.)Yealink Trust Center ISO certificate page (form and captcha, no certificate content) · read 2026-08-14—DisplayNote MontageNo DisplayNote ISMS certificate, number, registrar or scope statement is published anywhere. Every ISO 27001 mention on a DisplayNote property refers to Microsoft or Amazon, and cites a withdrawn edition: "Azure's data centers... comply with ISO/IEC 27001:2005" and "Amazon AWS servers... including ISO/IEC 27001:2005". ISO/IEC 27001:2005 was superseded in 2013 and again in 2022; the article carrying it was last updated 12 February 2026.DisplayNote 'Network infrastructure' support article (ISO/IEC 27001:2005, providers only) · read 2026-08-14—ViviThe same FAQ answer names no ISO certification of any kind. No ISO/IEC 27001 certificate, registration number or registrar appears on vivi.io, in the Support Hub or in Vivi's press material.Vivi FAQ, Network & Security section (page modified 18 Mar 2026) · read 2026-08-14✓Cisco Room BarCisco does claim it publicly, but the public claim is a single sentence: "Webex is ISO/IEC 27001:2013 certified." The page carries an April 2026 date and names the :2013 edition, which was withdrawn and whose transition deadline to :2022 passed in October 2025. No certificate number, no registrar, no scope statement and no expiry are given, and the certificate itself must be requested from Cisco support.Webex Compliance and Certifications (help.webex.com, page dated 15 Apr 2026) · read 2026-08-14✓Microsoft MTRThe two halves of this column are not equal and the difference should be stated. Microsoft's position is weaker for this purpose: the public description of its ISO/IEC 27001 certificate covers "Azure, Dynamics 365, Power Platform, and select Microsoft 365 cloud services" without naming Teams Rooms, and the certificate is retrievable only through a Service Trust Portal sign-in.ISO/IEC 27001:2013 Information Security Management Standards (Microsoft compliance offerings) · read 2026-08-30✓Zoom RoomsThe two halves of this column are not equal and the difference should be stated. Zoom publishes it cleanly and ungated: the latest certification was "issued on February 17, 2026", the scope list names "Zoom Rooms" explicitly among 30-plus products, and the page links the certificate by number to the registrar's directory.Zoom ISO 27001 (zoom.com trust center, certificate issued 17 Feb 2026, scope includes Zoom Rooms) · read 2026-08-14
Certification scope published: number, scope, issuing body and expiry all readable✓✓✓PolarisISO/IEC 27001:2022, certificate 011964-03, BARR Certifications LLC, issued 30 June 2026 and valid to 26 June 2028, with the scope sentence and the statement-of-applicability version published on the Trust Center rather than summarized.Certificates and scope · on this site✓✓✓Barco ClickShareAll four are legible on a downloadable PDF: number BE18/819943326, scope naming the ClickShare and XMS product lines and five sites, issuing body SGS ICS Italia S.r.l. of Milan, and validity 16 January 2026 to 4 January 2028. Barco separately publishes a CyFun label from the Center for Cybersecurity Belgium, Assurance Level Important, valid 27/04/2026 to 27/05/2027 - but that one is "substantiated by an underlying self-assessment verified by BRAND COMPLIANCE B.V." and its scope reads "wholesale of electrical equipment... design of computer programs," not a product scope.Barco NV ISO/IEC 27001:2022 certificate BE18/819943326 (full PDF) · read 2026-08-14—Crestron AirMediaNo certificate with a readable number, scope, issuing body and expiry is published for AirMedia or for Crestron's ISMS. The four Trust Center compliance items - CSA STAR Level 1, NIST 800-53 Rev. 5, TX-RAMP Level 2 and VPAT - resolve to detail pages behind a "Get access" request, and CSA STAR Level 1 is a self-assessment rather than an issued certificate. All four fields are therefore missing to a member of the public.Crestron Trust Center (SafeBase), compliance and documents sections · read 2026-08-14—Kramer VIAAll four are missing. Kramer's certificates page for ISO 27001 is a client-rendered shell containing only a heading and an empty image placeholder - re-fetched 15 Aug 2026 - and on the Quality Policy index the certificate appears only as a 250-pixel thumbnail. No certificate number, no scope statement, no issuing body and no expiry date is legible to a member of the public. The thumbnail file name LISO_27001_2013_E-250x250.jpg points to the :2013 edition, but that is filename inference, not a reading, and it does not rule out a current :2022 certificate Kramer has simply not published.Kramer Quality Policy page - certificate index (ISO 27001 shown as a 250px thumbnail only) · read 2026-08-15 · confidence med—WolfVision CynapThere is no certificate to read: WolfVision publishes no certification badge, number, registrar or expiry on its security page, TAA page or product documentation, and has no trust center or certificates page. The TAA page is the only compliance artifact and it offers certificates only on request.WolfVision Security page (responsible disclosure) · read 2026-08-14✓Extron ShareLink ProAll four elements are readable on one public page: number #4840, scope "Extron Secure Shield" software cryptographic module at FIPS 140-2 Level 1 with a named tested-configuration list, issuing body CMVP (NIST with the Canadian Center for Cyber Security, lab Acumen Security), and Sunset Date 9/21/2026. The qualification is scope, not legibility - it certifies a crypto library on four Extron platforms, none of which is ShareLink Pro, and there is no ISO 27001 or SOC 2 certificate to read.NIST CMVP Certificate #4840 - Extron Secure Shield · read 2026-08-14independent registry✓AirtameThree of the four are readable on the CSA registry page and the artifact itself downloads: scope "Airtame Cloud," issuing body Cloud Security Alliance, artifact "CAIQ Self-assessment v4.0.2... Created or renewed about 4 years ago, on June 22, 2022," listed since 2021-09-09. Missing: no certificate or registration number, and no expiry - instead CSA flags the entry "(Deprecated)" with the explanation that it "has not been updated within its validity period." It is also a self-assessment, not a certification.CSA STAR Registry Listing for Airtame Cloud (STAR Level 1, CAIQ v4.0.2) · read 2026-08-14independent registry—ScreenBeamThere is no certificate to read. The only approvals ScreenBeam publishes are regulatory and safety marks - "Approved: FCC, UL, IC ISED, CE RED, RoHS, and C-Tick" - carrying no registration number, no security scope, no issuing body for an information-security scheme and no expiry. ScreenBeam has no trust center or certificates page.ScreenBeam 1100 Plus data sheet - Regulatory and Compliance · read 2026-08-14✓BenQ InstaShowPartial: of the four attributes this row asks for, only the issuing body is readable - "the British Standards Institution (BSI)" - alongside an edition, ISO/IEC 27001:2013, and an award date of September 14, 2020. The certificate number, the scope statement and the expiry are all unpublished, no certificate document or image exists anywhere on benq.com, and without a number the BSI client directory cannot be searched. For the EAL6+ and FIPS claims nothing at all is published - no certificate number, scheme, evaluation lab, Protection Profile, Security Target or certification date.BenQ ISO 27001 certification announcement (only issuing body and date readable) · read 2026-08-14✓Yealink RoomCastPartial, and the gap is the whole certificate. The register publishes the standard and edition, "ISO/IEC 27001:2022", and an issue date of 07/11/2025 - more than most competitors publish. But of the four attributes this row asks for, none is readable: no certificate number, no issuing body or registrar, no scope statement and no expiry, because the certificate page resolves to a captcha form. The SOC 2 page is a flat refusal and the SOC 3, a report type designed for unrestricted public distribution, is also behind the form.Yealink Trust Center - Compliance register (titles and dates only) · read 2026-08-14—DisplayNote MontageDisplayNote holds no certification of its own, so none of the four attributes exists to publish. What it does publish is borrowed and stale: Azure and AWS described as complying with "ISO/IEC 27001:2005", a withdrawn first edition two revisions behind current, with no certificate number, registrar, scope or expiry for any party, on an article last updated in February 2026.DisplayNote 'Network infrastructure' support article (borrowed provider certifications) · read 2026-08-14—ViviNone of the four elements is published. The ST4S badge appears as an image and an announcement with no registration number, no scope statement, no issuing-body certificate document and no expiry or renewal date, and the ST4S verification register would not render. Asked directly which security certifications it meets, Vivi's FAQ names no certificate and no number.Vivi FAQ, Network & Security section (page modified 18 Mar 2026) · read 2026-08-14—Cisco Room BarNone of the four are readable. Cisco's only public ISO statement is "Webex is ISO/IEC 27001:2013 certified" with no registration number, no scope, no registrar and no expiry, naming a withdrawn edition of the standard; the certificate is request-only and the Cisco Trust Portal requires a sign-in. The FIPS letter does carry a number (#4747) and a date but it is a self-issued compliance letter, not a certificate with a published scope and expiry for the device.Webex Compliance and Certifications (help.webex.com, page dated 15 Apr 2026) · read 2026-08-14✓Microsoft MTRThree of the four are readable on the Zoom side and effectively none on the Microsoft side. Microsoft's ISO and SOC certificates require a Service Trust Portal sign-in and the downloads are marked confidential, so a member of the public reads none of the four.ISO/IEC 27001:2013 Information Security Management Standards (Microsoft compliance offerings) · read 2026-08-30✓Zoom RoomsThree of the four are readable on the Zoom side and effectively none on the Microsoft side. Zoom publishes the certificate number (1407508-7), the issuing body (Schellman), the issue date (17 February 2026) and a scope list that names Zoom Rooms - but no expiry is stated on the page, and the registrar's own certificate directory returns its results client-side, so a lookup on that number produced no rendered record from this environment.Zoom ISO 27001 page - certificate number 1407508-7, Schellman, issued 17 Feb 2026 · read 2026-08-14

The room device

Choose a vendor and product to compare its published evidence with Polaris.

Polaris vs Barco ClickShare

Security questionPolaris ProPolaris EssentialsPolaris HostBarco ClickShare
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓Barco ClickShareBarco names no base-unit OS for the C, CX or Bar range. The CX-50 Gen2 spec sheet's "Operating system" field lists only client platforms - "Windows 10 or higher, macOS 11 (BigSur) and higher, Android v11 and higher, iOS 14 and higher" - and no hardening, minimal-image or partition-integrity claim is published for the base unit itself.ClickShare CX-50 2nd generation spec sheet (29 Aug 2024) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓Barco ClickShareBarco publishes a "ClickShare Conference and ClickShare Present Security Whitepaper", TDE10355 v02, released 9 Oct 2025, listed publicly against C-5, C-10, CX-20, CX-30, CX-50 Gen2, Bar Core, Bar Pro and the Button. The landing page is open but the PDF itself could not be retrieved through its download control in this session, so the firmware-signing and boot-integrity text cannot be read at source by a member of the public via this route.Barco docs page: ClickShare Conference and Present Security Whitepaper TDE10355 v02 · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site✓Barco ClickShareNot published by Barco. The only TAA document we could retrieve is a Barco-authored compliance overview hosted on the distributor TD SYNNEX's website, dated 2024 — TD SYNNEX makes it available, Barco does not publish it themselves, and nothing on barco.com carries a TAA or Section 889 statement. Nine ClickShare "-US" part numbers are listed with country of origin Taiwan. A distributor cannot be held to a manufacturer's compliance claim, which is why this is graded partial rather than yes.Barco: Your trusted partner for government solutions - TAA-compliant product list · read 2026-08-14third-party host
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Barco ClickShareThe base unit itself is the supplicant, and the methods are named. Network Deployment Guide TDE10396 v06: "In terms of authentication protocols, ClickShare Base Units support PEAP, EAP-TLS and EAP-TTLS" on the wired interface, configured through a wizard in the web Configurator, with "Certificates for EAP-TLS can be provided via the web or rest interface. Alternatively, the baseunit can be instructed to query an NDES server and enroll to acquire a certificate." The same three methods are listed for WPA2-Enterprise wireless client mode. This corrects the earlier reading that only the Button acts as supplicant.ClickShare Conference and Present Network Deployment Guide, TDE10396 v06 · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓Barco ClickShareThe 44-page Network Deployment Guide TDE10396 v06 is served directly from Barco's own infopages domain with no form and no login, and carries real architecture content: four named deployment topologies (network connected, dual network, dedicated network, standalone), outbound port and hostname requirements, the base-unit firewall's traffic-bridging behavior, wireless client mode, REST API exposure and 802.1X configuration. Caveat: its scope is the C, CX and Bar base units - ClickShare Hub appears nowhere in it.ClickShare Conference and Present Network Deployment Guide, TDE10396 v06 (ungated PDF) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓✓✓Barco ClickShareCERTIFICAT ANSSI-CSPN-2026/15, product "CX-50 2nd generation", evaluation center ALMOND, developer and sponsor BARCO NV, validity "date de signature + 3 ans" against a DocuSign stamp of 4/6/2026, and "Dans le cadre de l'accord de reconnaissance mutuelle BSZ_CSPN, ce certificat est reconnu par le BSI." The signed certificate PDF is retrievable from the ANSSI registry and is also linked from Barco's own Trust Center. The certificate itself limits it: "Ce certificat s'applique uniquement a cette version specifique de produit dans sa configuration evaluee."ANSSI CSPN certificate ANSSI-CSPN-2026/15, ClickShare CX-50 2nd generation · read 2026-08-14independent registry
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site✓✓✓Barco ClickShareThe CSPN evaluation is device-level - category "Materiel et logiciel embarque" - and Barco publishes its own scope FAQ. The evaluated configuration is one Base Unit at firmware 02.20.02 with a paired Button and Desktop App v04.37.5, factory reset, Security Level 1, SNMP and Blackboarding off, LAN over DHCP, no proxy, single network, client mode disabled, WebUI on a self-signed certificate. Barco's own "not covered" table excludes XMS Cloud, remote management, enterprise network client mode, dual-network operation, proxy, AirPlay, Google Cast, Miracast, PresentSense, API access, third-party peripherals and "UC / MTR / room system integrations."Barco KB 16024 - ClickShare ANSSI CSPN Certification Scope FAQ (last updated 8 Jun 2026) · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Barco ClickShare has qualified documentation for the hardened Linux appliance; signed firmware and verified boot; the TAA and NDAA 889 statement.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Barco ClickShare

Strengths
  • Publishes in full on 802.1X network authentication, an ungated security architecture, a retrievable independent security test, and a third-party assessment of the room device.
  • Publishes more than Mersive does on a retrievable independent security test.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; signed firmware and verified boot; the TAA and NDAA 889 statement, Barco ClickShare provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source. Mersive publishes evidence covering these questions in full.
  • The reviewed Trust Center page lists ISO/IEC 27001:2022, a CyFun label, and the ANSSI CSPN certificate. No SOC 2 report, bridge letter, or SOC 3 was found in the reviewed documentation.
Sources +

Every document below is Barco ClickShare’s own unless the badge says otherwise.

DocumentRead forRetrieved
ClickShare CX-50 2nd generation spec sheet (29 Aug 2024)the hardened Linux appliance2026-08-14
Barco docs page: ClickShare Conference and Present Security Whitepaper TDE10355 v02signed firmware and verified boot2026-08-14
Barco: Your trusted partner for government solutions - TAA-compliant product list third-party hostthe TAA and NDAA 889 statement2026-08-14
ClickShare Conference and Present Network Deployment Guide, TDE10396 v06802.1X network authentication and an ungated security architecture2026-08-14
ANSSI CSPN certificate ANSSI-CSPN-2026/15, ClickShare CX-50 2nd generation independent registrya retrievable independent security test2026-08-14
Barco KB 16024 - ClickShare ANSSI CSPN Certification Scope FAQ (last updated 8 Jun 2026)a third-party assessment of the room device2026-08-14

Polaris vs Barco Hub

Security questionPolaris ProPolaris EssentialsPolaris HostBarco Hub
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓✓✓Barco HubThe Hub Core spec sheet states the room-device OS outright: "Operating system: Android (MDEP)." It is Android, not Linux - a Microsoft-managed AOSP build - so there is no Windows attack surface, and Barco does publish a hardening claim for it, describing MDEP as giving "enterprise-hardened protections" with monthly Microsoft security patches. Hub Pro carries the same OS line. This is a stronger published position than the C/CX/Bar range, where Barco names no base-unit OS at all.ClickShare Hub Core spec sheet (24 Jul 2026) · read 2026-08-14Barco - MDEP and meeting room security (26 Mar 2026) · second source
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓Barco HubBarco states it for Hub, but only in a news article. "What ClickShare adds on top of MDEP" lists "Secure boot: Helps protect the device by allowing only trusted, authorized software to load at startup" and "Firmware encryption: Helps protect core OS instructions from unauthorized access or modification," over an MDEP baseline of "Hardware-based attestation (PKI)." No signing scheme, key custody, root-of-trust or boot-chain document is published, and Hub is absent from the product list of Barco's security whitepaper TDE10355. This is different evidence from ClickShare CX/C/Bar, whose signing claims sit in that whitepaper instead.Barco - MDEP and meeting room security (26 Mar 2026) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—Barco HubNot published by Barco. The only TAA document we could retrieve is a Barco-authored compliance overview hosted on the distributor TD SYNNEX's website, dated 2024 — TD SYNNEX makes it available, Barco does not publish it themselves, and nothing on barco.com carries a TAA or Section 889 statement. No Hub SKU appears on it. A distributor cannot be held to a manufacturer's compliance claim, which is why this is graded partial rather than yes.Barco TAA-compliant product list (Hub absent) · read 2026-08-14third-party host
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site—Barco HubBarco publishes no 802.1X or EAP statement for Hub. The Hub Core spec sheet has no authentication-protocol field at all and reads "Network connection: LAN" - unlike the CX-50 Gen2 sheet, which carries an explicit "Authentication protocol" row naming 802.1X. The deployment guide that documents PEAP, EAP-TLS and EAP-TTLS on the base unit, TDE10396 v06, covers the C, CX and Bar units only; Hub does not appear in it.ClickShare Hub Core spec sheet (24 Jul 2026) · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓Barco HubWhat is open for Hub is a spec sheet and a security-themed news article - both ungated, but marketing rather than architecture. Hub is outside the scope of both Barco security documents: it is absent from the product list of the security whitepaper TDE10355 and absent from the 44-page Network Deployment Guide TDE10396 v06. So unlike ClickShare CX/C/Bar, which have a genuinely ungated architecture guide, Hub has no published architecture document of its own.Barco - MDEP and meeting room security (the only open Hub security material) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site—Barco HubNo independent test result is published for Hub. Barco's only product security certificate, ANSSI-CSPN-2026/15, names "CX-50 2nd generation" at Base Unit version 02.20.02.0027 and does not cover Hub. The MDEP article claims "Rigorous security validation: We apply extensive security testing as part of product assurance" but names no firm, scheme, date or report. This is the same certificate that gives ClickShare CX/C/Bar a positive grade on this row; Hub simply is not in it.Barco Trust Center - Certificates index (CSPN certificate names CX-50 Gen2 only) · read 2026-08-14Barco - MDEP and meeting room security (26 Mar 2026) · second source
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—Barco HubNo device-level third-party assessment of Hub Core or Hub Pro is published. Barco's device-level evaluation is the ANSSI CSPN, and its evaluated configuration is the CX-50 Gen2 Base Unit at firmware 02.20.02 with a paired Button and Desktop App v04.37.5; Barco's own scope FAQ lists "UC / MTR / room system integrations" as outside the certification. Hub's security story rests on Microsoft's MDEP platform, which is an OS-layer claim, not a room-device assessment.Barco KB 16024 - CSPN scope FAQ (evaluated configuration excludes Hub) · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Barco Hub has no published evidence in the reviewed sources for the TAA and NDAA 889 statement; 802.1X network authentication; a retrievable independent security test; a third-party assessment of the room device, and has qualified documentation for signed firmware and verified boot; an ungated security architecture.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Barco Hub

Strengths
  • Publishes in full on the hardened Linux appliance.
Limitations
  • The published evidence has qualifications. For signed firmware and verified boot; an ungated security architecture, Barco Hub provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source. Mersive publishes evidence covering these questions in full.
  • No published evidence was found for the TAA and NDAA 889 statement; 802.1X network authentication; a retrievable independent security test; a third-party assessment of the room device in the reviewed Barco sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Barco Hub on the TAA and NDAA 889 statement, 802.1X network authentication, a retrievable independent security test, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed Trust Center page lists ISO/IEC 27001:2022, a CyFun label, and the ANSSI CSPN certificate. No SOC 2 report, bridge letter, or SOC 3 was found in the reviewed documentation.
Sources +

Every document below is Barco Hub’s own unless the badge says otherwise.

DocumentRead forRetrieved
ClickShare Hub Core spec sheet (24 Jul 2026)the hardened Linux appliance and 802.1X network authentication2026-08-14
Barco - MDEP and meeting room security (26 Mar 2026)signed firmware and verified boot and an ungated security architecture2026-08-14
Barco TAA-compliant product list (Hub absent) third-party hostthe TAA and NDAA 889 statement2026-08-14
Barco Trust Center - Certificates index (CSPN certificate names CX-50 Gen2 only)a retrievable independent security test2026-08-14
Barco KB 16024 - CSPN scope FAQ (evaluated configuration excludes Hub)a third-party assessment of the room device2026-08-14

Polaris vs Crestron AirMedia

Security questionPolaris ProPolaris EssentialsPolaris HostCrestron AirMedia
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site—Crestron AirMediaCrestron publishes no statement of the AirMedia receiver's operating system in either direction. A full-text read of the Security Reference Guide: AirMedia Presentation Gateway, Doc. 7693AM, returns operating-system references only in the sender context - the user's PC, the Windows Miracast stack, the download of the client application - and none for the receiver. No hardening, minimal-image or read-only-partition claim appears anywhere in the document.Crestron Security Reference Guide: AirMedia Presentation Gateway, Doc. 7693AM · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—Crestron AirMediaCrestron publishes no firmware-signing or verified-boot claim for AirMedia. A full-text read of Doc. 7693AM returns zero occurrences of secure boot, root of trust, signed firmware, firmware signing, TPM or tamper. The guide's only integrity content concerns TLS certificates for the presentation stream, and its published stream cryptography is "AES-128/TLS Security."Crestron Security Reference Guide: AirMedia Presentation Gateway, Doc. 7693AM · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site✓✓✓Crestron AirMediaCrestron publishes a dated TAA product list, revised 2026/07/13, naming all six AirMedia receivers by material number - 6513019 AM-3000-WF-I, 6511540 AM-3100-WF, 6511541 AM-3100-WF-I, 6513188 AM-3200-GV "AirMedia Receiver 3200, Government Version", 6511483 AM-3200-WF and 6511484 AM-3200-WF-I - each with a Country Of Origin column reading TW. Two qualifications a buyer should read: the basis is the Trade Agreements Act via the WTO Government Procurement Agreement, with no separate Section 889 statement, and country of origin is Taiwan, not the United States.Crestron TAA-compliant products list (revised 2026/07/13) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Crestron AirMediaConfirmed and kept at y after opening the document. Crestron's AirMedia Series 3 Receivers Product Manual (Doc. 9020) documents an 802.1x Configuration page whose Authentication Method drop-down offers "EAP-TLS Certificate or EAP MSCHAP V2- password", with a Machine certificate store and a trusted-CA list for server validation; the AM-200/AM-300 Product Manual (Doc. 8254) carries the identical EAP-TLS Certificate flow. Qualifications a buyer should know: this is wired, port-based 802.1X on the LAN port (the -WF models' Wi-Fi radio is guest Access Point mode, not an enterprise supplicant), and the legacy AM-100/AM-101 feature table in Doc. 7693AM has no 802.1X row at all.802.1x Configuration - AirMedia Series 3 Receivers Product Manual (Doc. 9020) · read 2026-08-15
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓Crestron AirMediaThe Security Reference Guide: AirMedia Presentation Gateway, Doc. 7693AM, is a substantial security document served as a direct PDF from crestron.com with no form and no login, covering per-model security feature tables, the AirMedia protocol set, four named guest-network deployment options, port and service requirements and certificate handling. The gap is content, not access: it contains nothing on boot integrity, firmware signing or the receiver's own operating system.Crestron Security Reference Guide: AirMedia Presentation Gateway, Doc. 7693AM (ungated PDF) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓Crestron AirMediaCrestron asserts external testing without publishing a result. Doc. 8561G: "Crestron products are regularly subject to internal penetration tests. External penetration tests are also performed at regular intervals." No firm, date, scope, methodology or findings are given and no report is retrievable; the Trust Center's documents sit behind a "Get access" request, and the only self-assessment it features is a CAIQ, which CSA defines as a self-assessment rather than third-party attestation.Crestron Security Reference Guide: XiO Cloud, Doc. 8561G, Policy and Process section · read 2026-08-14
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—Crestron AirMediaNo third-party assessment scoped to an AirMedia receiver is published. The pen-test assertion Crestron does make appears in the XiO Cloud guide and is unscoped, and the Trust Center is explicitly "the Crestron's Trust Center for the XiO Cloud service" - a cloud scope, not a device scope. The AirMedia Security Reference Guide never mentions penetration testing, evaluation or certification of the receiver.Crestron Trust Center - scoped to the XiO Cloud service · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Crestron AirMedia has no published evidence in the reviewed sources for the hardened Linux appliance; signed firmware and verified boot; a third-party assessment of the room device, and has qualified documentation for a retrievable independent security test.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Crestron AirMedia

Strengths
  • Publishes in full on the TAA and NDAA 889 statement, 802.1X network authentication, and an ungated security architecture.
Limitations
  • The published evidence has qualifications. For a retrievable independent security test, Crestron AirMedia provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for the hardened Linux appliance; signed firmware and verified boot; a third-party assessment of the room device in the reviewed Crestron sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Crestron AirMedia on the hardened Linux appliance, signed firmware and verified boot, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • Crestron documents its SOC 2 status: the XiO Cloud security reference guide reads “Crestron does not currently possess a SOC 2 Type 2 certification”, and references Azure’s report for the underlying technical controls. That report covers Microsoft’s service. No Crestron SOC 3 was found in the reviewed documentation.
Sources +

Every document below is Crestron AirMedia’s own unless the badge says otherwise.

DocumentRead forRetrieved
Crestron Security Reference Guide: AirMedia Presentation Gateway, Doc. 7693AMthe hardened Linux appliance, signed firmware and verified boot, and an ungated security architecture2026-08-14
Crestron TAA-compliant products list (revised 2026/07/13)the TAA and NDAA 889 statement2026-08-14
802.1x Configuration - AirMedia Series 3 Receivers Product Manual (Doc. 9020)802.1X network authentication2026-08-15
Crestron Security Reference Guide: XiO Cloud, Doc. 8561G, Policy and Process sectiona retrievable independent security test2026-08-14
Crestron Trust Center - scoped to the XiO Cloud servicea third-party assessment of the room device2026-08-14

Polaris vs Kramer VIA

Security questionPolaris ProPolaris EssentialsPolaris HostKramer VIA
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓Kramer VIAThe range is split and Kramer publishes it plainly. The VIA platform brochure's model comparison table gives "Operating system" as Linux for VIA GO2 and VIA Connect2, and "MS-Windows" for VIA Campus2 and VIA Campus2 Plus. No Linux distribution is named for the Linux models, no Windows edition is named for the Windows models, and no hardening claim is published for either.Kramer VIA wireless collaboration and conferencing platform brochure (June 2024) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—Kramer VIAKramer publishes no firmware-signing, secure-boot, verified-boot, TPM or hardware-root-of-trust statement for any VIA model. The only retrievable VIA security white paper describes four security layers - WPA2/AES on the access point, TLS 1.2, "File Server Level Security" and "Windows firewall protection" - and contains no boot-integrity or firmware-signing content at all.Kramer white paper - Content Security: Kramer's approach to securing data within wireless transmission · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—Kramer VIAKramer publishes no TAA statement, no Section 889 statement and no country-of-origin declaration for any VIA model. Its complete certificate index on the Quality Policy page carries exactly four items - ISO 9001, ISO 45001, ISO 14001 and ISO 27001 - and there is no trust center or compliance portal on kramerav.com where a procurement statement could sit.Kramer Quality Policy - complete certificate index · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓Kramer VIAThe claim is published but unsupported by any configuration document. The VIA platform brochure states "VIA utilizes 802.1X authentication to ensure only authorized access, all connections are encrypted, and the room Wi-Fi is isolated from the enterprise network," and the VIA Connect 3 page lists "802.1x User authentication" as a feature. No EAP method is named anywhere, no supplicant configuration guide is retrievable, and the only retrievable VIA security white paper never mentions 802.1X. The same brochure sentence pairs it with "1024 bit encrypted," which matches no cipher in Kramer's own documented stack of AES and TLS 1.2.Kramer VIA platform brochure, Robust network protection section · read 2026-08-14VIA CONNECT3 - Compact and Secure 4K Wireless Presentation and Collaboration Solution (Kramer product page) · second source
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓Kramer VIAThe only retrievable VIA security document is ungated but is 2016 marketing covering discontinued hardware. It names VIA Collage, VIA Campus and VIA Connect PRO - none of them current - carries a Gartner-quote executive summary, and contains the incoherent line "By implementing the TLS Record Protocol, VIA also provides connection security with an encryption method (the Data Encryption Standard (DES))." It has no architecture content: no topology, no port table, no network integration guidance. Kramer's deeper VIA guides are served from cdn.kramerav.com as application/octet-stream and could not be read.Kramer VIA security white paper (2016 edition) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓Kramer VIAKramer asserts one and publishes nothing behind it. The VIA platform brochure states "VIA meets the highest standards for enterprise security, including ISO 27001 and third-party security certification," and the VIA Connect 3 and Campus2 pages carry a bare "3rd party Security Certification" bullet. No scheme, laboratory, certificate number, protection profile or date is named on any Kramer page, and Kramer's own certificate index contains no such certificate - only ISO 9001, 45001, 14001 and 27001.Kramer VIA platform brochure, Enterprise-level security section · read 2026-08-14VIA CONNECT3 - Compact and Secure 4K Wireless Presentation and Collaboration Solution (Kramer product page) · second source
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—Kramer VIANo device-level third-party assessment of any VIA model is published. The unnamed "third-party security certification" claim in Kramer's brochure has no scheme, lab or number attached and cannot be checked against any registry, and Kramer's certificate index holds only management-system certificates - ISO 9001, 45001, 14001 and 27001 - none of which evaluates a device.Kramer Quality Policy - complete certificate index (no product certificate) · read 2026-08-14Kramer VIA wireless collaboration and conferencing platform brochure (June 2024) · second source

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Kramer VIA has no published evidence in the reviewed sources for signed firmware and verified boot; the TAA and NDAA 889 statement; a third-party assessment of the room device, and has qualified documentation for the hardened Linux appliance, 802.1X network authentication, an ungated security architecture, and a retrievable independent security test.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Kramer VIA

Strengths
  • No published evidence was found for Kramer VIA on the questions in this comparison. The ratings reflect the documentation available for review.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; 802.1X network authentication; an ungated security architecture; a retrievable independent security test, Kramer VIA provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for signed firmware and verified boot; the TAA and NDAA 889 statement; a third-party assessment of the room device in the reviewed Kramer sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Kramer VIA on signed firmware and verified boot, the TAA and NDAA 889 statement, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed documentation identifies no SOC 2 or SOC 3 attestation for Kramer and no documented route to request a Type 2 report under NDA. Its attested scope and examination period could not be confirmed from those sources.
Sources +

Every document below is Kramer VIA’s own unless the badge says otherwise.

DocumentRead forRetrieved
Kramer VIA wireless collaboration and conferencing platform brochure (June 2024)the hardened Linux appliance, 802.1X network authentication, and a retrievable independent security test2026-08-14
Kramer white paper - Content Security: Kramer's approach to securing data within wireless transmissionsigned firmware and verified boot and an ungated security architecture2026-08-14
Kramer Quality Policy - complete certificate indexthe TAA and NDAA 889 statement and a third-party assessment of the room device2026-08-14

Polaris vs WolfVision Cynap

Security questionPolaris ProPolaris EssentialsPolaris HostWolfVision Cynap
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓✓✓WolfVision CynapWolfVision names the OS and describes the hardening: "Cynap Pure (Next Gen) uses a Linux operating system. The distribution is a WolfVision specific variant, which in addition to the Linux kernel contains only the individual libraries and packages required... every update is installed to a read-only partition that cannot be changed after the installation process." The Videobar white paper repeats this as "a closed custom-built Linux operating system" and lists it under "Systems hardening."WolfVision Network Integration Guide: Cynap Pure Pro Next Gen v1.0, s1 Basics · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—WolfVision CynapDowngraded to nothing published: the only source was withdrawn. The claim that "the loading of unsigned firmware files is blocked by default" appeared solely in the Cynap Videobar Security White Paper, which now 404s. The word unsigned appears nowhere in either live Network Integration Guide, and no secure boot, TPM or hardware root of trust is described in any document WolfVision still publishes. The capability may well be in the product; the document a buyer could check is gone.Cynap Videobar support page - document list, showing no security white paper (checked 30 Aug 2026) · read 2026-08-30
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site✓✓✓WolfVision CynapWolfVision publishes a dedicated page: "WolfVision fully complies with the provisions of the Trade Agreements Act (TAA)... all current WolfVision systems and solutions are eligible for procurement through the General Services Administration (GSA) Schedule" and "all current systems and solutions are compliant with Section 889(a)(1)(A)" with Huawei/ZTE/Hytera/Hikvision/Dahua named as excluded. Scope is portfolio-wide, not per-SKU, and the underlying certificates are not published - "For copies of current certificates or for more information, please contact us."WolfVision TAA Compliance (USA) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓WolfVision CynapHeld at qualified, and now sourced to a document that still exists. Both live Network Integration Guides publish 802.1X for the room device: "When using wired network, use authentication (IEEE 802.1x) to maximize security." The qualification is the credential type, and it is unchanged: the only EAP methods WolfVision names are "PEAP with MSCHAPv2 and TTLS-PAP", and EAP-TLS appears nowhere in either guide. Only root certificates are supported, loaded through the web interface.Cynap Videobar Network Integration Guide v1.3, network interface and LAN security sections · read 2026-08-30
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓WolfVision CynapDowngraded from full: the security white paper has been withdrawn. WolfVision published a 13-page Cynap Videobar Security White Paper covering OS design, interface security tables, user levels, mirroring-protocol encryption and a systems-hardening list; that document, and the Cynap systems paper alongside it, now return 404, and a third legacy path returns HTTP 200 while serving the homepage rather than the PDF. Neither the Cynap Videobar support page nor the Cynap support page lists a security white paper any longer, and wolfvision.com/en/security carries only a vulnerability-disclosure policy and a PGP key. What remains ungated is the per-model Network Integration Guide, which does document the network interface tables, 802.1X, WPA standards and the DTLS cipher used for mirroring - real security documentation, but a network guide rather than a security architecture.Cynap Videobar Network Integration Guide v1.3 (the security white paper it replaces is withdrawn) · read 2026-08-30
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site—WolfVision CynapDowngraded to nothing published: the assertion and its document are both gone. WolfVision previously stated that it "uses external companies to conduct in-depth penetration testing on its Cynap Videobar systems (further details available on request)" - an assertion that already named no lab, date, scope or findings. That sentence lived only in the withdrawn security white paper, and penetration testing is mentioned nowhere in the live Network Integration Guides or on the security page. No Common Criteria, CSPN or FIPS validation is claimed anywhere.WolfVision Security page - vulnerability disclosure policy and PGP key only, no test report (checked 30 Aug 2026) · read 2026-08-30
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—WolfVision CynapDowngraded to nothing published, for the same reason as the row above. The only statement that the room appliance itself had been assessed by an outside party was in the withdrawn white paper, was limited to the Cynap Videobar rather than the Cynap, Cynap Core or Cynap Pure, and was never substantiated by a retrievable report or certificate. With that document gone there is no published third-party assessment of the device at any scope.WolfVision Security page - no third-party assessment of the room device published (checked 30 Aug 2026) · read 2026-08-30

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. WolfVision Cynap has no published evidence in the reviewed sources for signed firmware and verified boot; a retrievable independent security test; a third-party assessment of the room device, and has qualified documentation for 802.1X network authentication and an ungated security architecture.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

WolfVision Cynap

Strengths
  • Publishes in full on the hardened Linux appliance and the TAA and NDAA 889 statement.
Limitations
  • The published evidence has qualifications. For 802.1X network authentication; an ungated security architecture, WolfVision Cynap provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source. Mersive publishes evidence covering these questions in full.
  • No published evidence was found for signed firmware and verified boot; a retrievable independent security test; a third-party assessment of the room device in the reviewed WolfVision sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for WolfVision Cynap on signed firmware and verified boot, a retrievable independent security test, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed documentation identifies no SOC 2 or SOC 3 attestation for WolfVision and no documented route to request a Type 2 report under NDA. Its attested scope and examination period could not be confirmed from those sources.
Sources +

Every document below is WolfVision Cynap’s own unless the badge says otherwise.

DocumentRead forRetrieved
WolfVision Network Integration Guide: Cynap Pure Pro Next Gen v1.0, s1 Basicsthe hardened Linux appliance2026-08-14
Cynap Videobar support page - document list, showing no security white paper (checked 30 Aug 2026)signed firmware and verified boot2026-08-30
WolfVision TAA Compliance (USA)the TAA and NDAA 889 statement2026-08-14
Cynap Videobar Network Integration Guide v1.3, network interface and LAN security sections802.1X network authentication and an ungated security architecture2026-08-30
WolfVision Security page - vulnerability disclosure policy and PGP key only, no test report (checked 30 Aug 2026)a retrievable independent security test and a third-party assessment of the room device2026-08-30

Polaris vs Extron ShareLink Pro

Security questionPolaris ProPolaris EssentialsPolaris HostExtron ShareLink Pro
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site—Extron ShareLink ProExtron names no operating system for ShareLink Pro. The 103-page ShareLink Pro 2500 User Guide and the ShareLink Pro 1100 brochure describe the platform without identifying an OS, and neither uses the words Linux, Windows, Android or hardening. (The 2019 AWIND-platform CVEs imply a Linux/CGI stack on the earlier ShareLink 200/250, but that is inference, not an Extron statement about ShareLink Pro.)Extron ShareLink Pro 2500 User Guide 68-3824-01 Rev B · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—Extron ShareLink ProNo firmware-signing or verified-boot statement appears in the ShareLink Pro 2500 User Guide (which documents the firmware update procedure) or in the 1100 and 2500 brochures. Extron publishes no signed-firmware or secure-boot claim for ShareLink Pro; the published security features are 128-bit content encryption, HTTPS, SSH for control, display codes and admin/moderator/user passwords.Extron ShareLink Pro 2500 User Guide 68-3824-01 Rev B · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site✓Extron ShareLink ProExtron maintains a page indexed as "TAA Compliance - Trade Agreements Act" at https://www.extron.com/article/taacompliance, but every extron.com URL returns "Request Rejected / Bot Defense" to automated retrieval, so its text, its scope and whether ShareLink Pro is covered could not be verified. What is retrievable - the ShareLink Pro 2500 User Guide and the 1100/2500 brochures - carries no TAA, Section 889 or country-of-origin statement; regulatory lines stop at "CE, c-UL, UL, C-tick, FCC Class A, ICES, VCCI" and RoHS/WEEE.Extron ShareLink Pro 1100 brochure 68-3623-01 Rev A (regulatory compliance) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site—Extron ShareLink ProA full-text search of the 103-page ShareLink Pro 2500 User Guide returns no occurrence of 802.1X, EAP, EAP-TLS, PEAP or RADIUS; the 1100 brochure likewise lists only 128-bit encryption, HTTPS, SSH, four-digit display codes and dual-NIC guest/private segmentation. Extron publishes no 802.1X or EAP-TLS supplicant capability for ShareLink Pro.Extron ShareLink Pro 2500 User Guide 68-3824-01 Rev B · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓Extron ShareLink ProExtron's product documentation is genuinely ungated - the 103-page ShareLink Pro 2500 User Guide and the brochures download from media.extron.com with no form and no login - but it is a configuration manual, not a security architecture document: there is no threat model, no OS or platform description, no boot or update integrity section, and security content amounts to "128-bit data encryption," HTTPS, SSH and network segmentation. Extron publishes no ShareLink Pro security whitepaper reachable here, and extron.com blocks automated retrieval.Extron ShareLink Pro 2500 User Guide 68-3824-01 Rev B · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓Extron ShareLink ProExtron holds a genuine, retrievable third-party validation - NIST/CCCS CMVP certificate #4840, "Extron Secure Shield," FIPS 140-2 Level 1, Active, lab Acumen Security, with the full Security Policy downloadable. But the validated item is a software cryptographic library and the tested configurations name only the Extron Janus, Jupiter, Mercury and Saturn platforms; ShareLink Pro appears nowhere in it, and no penetration test of ShareLink Pro is published.NIST CMVP Certificate #4840 - Extron Secure Shield · read 2026-08-14independent registry
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—Extron ShareLink ProThe only third-party evaluation Extron has is CMVP #4840, and its Tested Configurations list is explicit: Extron Janus, Jupiter, Mercury and Saturn platforms plus generic Debian/FreeBSD/macOS/Ubuntu/Windows hosts. The ShareLink Pro collaboration gateway is not in scope, and no separate independent assessment of the ShareLink Pro appliance is published.NIST CMVP Certificate #4840 - Extron Secure Shield (Tested Configurations) · read 2026-08-14independent registry

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Extron ShareLink Pro has no published evidence in the reviewed sources for the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; a third-party assessment of the room device, and has qualified documentation for the TAA and NDAA 889 statement; an ungated security architecture; a retrievable independent security test.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Extron ShareLink Pro

Strengths
  • No published evidence was found for Extron ShareLink Pro on the questions in this comparison. The ratings reflect the documentation available for review.
Limitations
  • The published evidence has qualifications. For the TAA and NDAA 889 statement; an ungated security architecture; a retrievable independent security test, Extron ShareLink Pro provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; a third-party assessment of the room device in the reviewed Extron sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Extron ShareLink Pro on the hardened Linux appliance, signed firmware and verified boot, 802.1X network authentication, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed documentation identifies no SOC 2 or SOC 3 attestation for Extron and no documented route to request a Type 2 report under NDA. Its attested scope and examination period could not be confirmed from those sources.
Sources +

Every document below is Extron ShareLink Pro’s own unless the badge says otherwise.

DocumentRead forRetrieved
Extron ShareLink Pro 2500 User Guide 68-3824-01 Rev Bthe hardened Linux appliance, signed firmware and verified boot, 802.1X network authentication, and an ungated security architecture2026-08-14
Extron ShareLink Pro 1100 brochure 68-3623-01 Rev A (regulatory compliance)the TAA and NDAA 889 statement2026-08-14
NIST CMVP Certificate #4840 - Extron Secure Shield independent registrya retrievable independent security test and a third-party assessment of the room device2026-08-14

Polaris vs Airtame

Security questionPolaris ProPolaris EssentialsPolaris HostAirtame
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓✓✓AirtameThe current datasheet names the OS outright under Software Specifications: "Operating System: Airtame OS (Linux-based)." No Windows surface. Airtame publishes no hardening detail behind that name - no minimal-image, read-only-partition or attack-surface-reduction claim appears in the datasheet or the security pages.Airtame 3 + Core Data Sheet EN 2025Q4 · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—AirtameThe datasheet Security block lists only Web/Cloud Transport Encryption (TLS), Device API Security "With password (SRP)," streaming encryption, conferencing encryption (TLS, WebRTC) and "Custom tamperproofing, Kensington lock compatible." Neither it nor the Information Security Notice mentions signed firmware, secure boot, TPM, secure element or a per-device certificate. Airtame publishes no firmware-signing or verified-boot statement.Airtame 3 + Core Data Sheet EN 2025Q4 (Security block) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—AirtameNo TAA, Section 889 or country-of-manufacture statement appears on the Airtame 3 datasheet or anywhere in Airtame's security pages, which are otherwise detailed about hosting and data location. Airtame publishes no TAA or NDAA 889 claim. Related and relevant to US federal buyers: Airtame's own notice places the cloud "on Amazon Web Services... specifically in Frankfurt, Germany."Airtame 3 + Core Data Sheet EN 2025Q4 · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓AirtameAirtame publishes a full EAP-TLS deployment guide for the room device covering RADIUS/NPS policy, AD service accounts and client certificate export: "EAP-TLS uses certificates to allow the Airtame and your RADIUS server to mutually authenticate." It covers both media - "the fields will appear automatically for WiFi networks, whereas you need to toggle them manually for an ethernet connection." Caveat: this lives in a knowledge-base article last updated March 2023, and 802.1X does not appear in the Airtame 3 datasheet's Security block.Airtame Knowledge Center - Authenticating your Airtame (PEAP / EAP-TLS) · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓AirtameAirtame's security page is fully public with no form or login and carries real content - TLS 1.2 minimum, bcrypt password hashing, AES-256 database encryption, a cloud blueprint diagram, six RBAC roles, DPI firewall and IDS, a data breach policy and a vulnerability disclosure policy. The qualification: it is almost entirely cloud-side. The room device gets three short paragraphs, there is no device architecture, boot, update-integrity or hardening documentation, and Airtame states plainly that "Reports of our vulnerability management program cannot be shared due to confidential reasons."Airtame Security / Information Security Notice (Dec 2024) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site—AirtameAirtame positively excludes this in its own words: "Airtame has its both cloud platform and devices tested for security vulnerabilities internally... through quality checks, peer reviews and 'bug hunting' sessions," and "Reports of our vulnerability management program cannot be shared due to confidential reasons." No external pen test, Common Criteria, CSPN or FIPS validation is claimed; the CSA STAR entry is a self-assessment, which CSA defines as Level 1, with third-party attestation sitting at Level 2.Airtame Security page - Vulnerability management section · read 2026-08-14
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—AirtameAirtame's only registry listing is scoped to the cloud, not the appliance: the CSA STAR entry names the service as "Airtame Cloud." Device testing is described as internal only. No third-party assessment of the Airtame 2, Airtame 3, Hub or Go hardware is published.CSA STAR Registry Listing for Airtame Cloud · read 2026-08-14independent registry

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Airtame has no published evidence in the reviewed sources for signed firmware and verified boot; the TAA and NDAA 889 statement; a retrievable independent security test; a third-party assessment of the room device, and has qualified documentation for an ungated security architecture.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Airtame

Strengths
  • Publishes in full on the hardened Linux appliance and 802.1X network authentication.
Limitations
  • The published evidence has qualifications. For an ungated security architecture, Airtame provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source. Mersive publishes evidence covering these questions in full.
  • No published evidence was found for signed firmware and verified boot; the TAA and NDAA 889 statement; a retrievable independent security test; a third-party assessment of the room device in the reviewed Airtame sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Airtame on signed firmware and verified boot, the TAA and NDAA 889 statement, a retrievable independent security test, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • Airtame’s security page references SOC assurance for its hosting provider, AWS. That attestation covers the hosting infrastructure. No Airtame SOC 2 or SOC 3 was found in the reviewed documentation.
Sources +

Every document below is Airtame’s own unless the badge says otherwise.

DocumentRead forRetrieved
Airtame 3 + Core Data Sheet EN 2025Q4the hardened Linux appliance, signed firmware and verified boot, and the TAA and NDAA 889 statement2026-08-14
Airtame Knowledge Center - Authenticating your Airtame (PEAP / EAP-TLS)802.1X network authentication2026-08-14
Airtame Security / Information Security Notice (Dec 2024)an ungated security architecture and a retrievable independent security test2026-08-14
CSA STAR Registry Listing for Airtame Cloud independent registrya third-party assessment of the room device2026-08-14

Polaris vs ScreenBeam

Security questionPolaris ProPolaris EssentialsPolaris HostScreenBeam
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site—ScreenBeamScreenBeam names no receiver operating system. The current 1100 Plus datasheet lists compatible client OSes (Windows, macOS, iOS, Chrome OS, Android) but states nothing about the receiver's own OS, and the security overview page describes only connection, session and PIN controls. ScreenBeam publishes no statement of the base-unit OS in either direction.ScreenBeam 1100 Plus data sheet, SBWD1100P (Jan 2026 posting) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—ScreenBeamNeither the 1100 Plus datasheet nor ScreenBeam's public security overview mentions signed firmware, image verification, secure boot, TPM or a hardware root of trust. The published security model is expressly three layers: 802.1x connection security, AES128 session encryption and PIN pairing. ScreenBeam publishes no firmware-signing or verified-boot claim.ScreenBeam - How Secure is Wireless Display for my Business? (modified 2025-05-02) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—ScreenBeamThe 1100 Plus datasheet's compliance line is regulatory only - "Approved: FCC, UL, IC ISED, CE RED, RoHS, and C-Tick" - with no TAA, Section 889 or country-of-manufacture statement, and the screenbeam.com footer index carries no compliance, GSA or TAA entry. ScreenBeam publishes no TAA or NDAA 889 claim. Its US domicile ("Global Headquarters, 220 Devcon Drive, San Jose, CA") is not a country-of-origin attestation.ScreenBeam 1100 Plus data sheet - Regulatory and Compliance · read 2026-08-14ScreenBeam - How Secure is Wireless Display for my Business? (modified 2025-05-02) · second source
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓ScreenBeamCertificate-based 802.1X is published for the receiver itself: "Connection level security support for using 802.1x network certificate-based security requirements. This ensures any device attempting to connect must have the authenticated certificate." The datasheet corroborates the methods - "Protocol: WPA2-PSK (AES), PEAP-MSCHAP V2, EAP-TLS."ScreenBeam - How Secure is Wireless Display for my Business? (three levels of security) · read 2026-08-14ScreenBeam 1100 Plus data sheet, SBWD1100P (Jan 2026 posting) · second source
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓ScreenBeamUngated material exists and has real content - datasheets, full receiver user manuals with 802.1x configuration, and dated firmware release notes all download without a form - and the public security page describes the three-network isolation design: "there's never a path for traffic between the Guest network and the Employee network." The qualification: ScreenBeam's actual security document, the "Wireless Collaboration in Enterprise Environments" white paper, is form-gated on that same page ("Simply fill out the form below!"), and no ungated security architecture or threat-model document exists.ScreenBeam - How Secure is Wireless Display for my Business? · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site—ScreenBeamNothing is retrievable. ScreenBeam's support portal carries an article titled 'ScreenBeam 1100 Plus 3rd Party Penetration Test' on its own domain, but the body is JavaScript-rendered and returned an empty body on two separate plain fetches (14 Aug and 15 Aug 2026); a search index dates the article to 2023 and exposes no description. No testing lab, date, scope, methodology, findings, report or certificate is published, and no CMVP, Common Criteria or CSPN entry exists for ScreenBeam. A title is an assertion, not a published test.ScreenBeam support article - ScreenBeam 1100 Plus 3rd Party Penetration Test (body does not render to a plain fetch) · read 2026-08-15 · confidence med
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site✓ScreenBeamThe article's title names the room appliance as the subject - 'ScreenBeam 1100 Plus 3rd Party Penetration Test' - not a cloud service or a client OS, which is more than most vendors in this row publish. The qualification is that the title is all that is retrievable: the page body is JavaScript-rendered and returned an empty body on two separate plain fetches, 14 Aug and 15 Aug 2026, so no assessor, date, scope or finding is published, and it names one model, not the 1000 EDU or the rest of the 1xxx range.ScreenBeam support article - ScreenBeam 1100 Plus 3rd Party Penetration Test (body does not render to a plain fetch) · read 2026-08-15 · confidence low

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. ScreenBeam has no published evidence in the reviewed sources for the hardened Linux appliance; signed firmware and verified boot; the TAA and NDAA 889 statement; a retrievable independent security test, and has qualified documentation for an ungated security architecture and a third-party assessment of the room device.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

ScreenBeam

Strengths
  • Publishes in full on 802.1X network authentication.
Limitations
  • The published evidence has qualifications. For an ungated security architecture; a third-party assessment of the room device, ScreenBeam provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source. Mersive publishes evidence covering these questions in full.
  • No published evidence was found for the hardened Linux appliance; signed firmware and verified boot; the TAA and NDAA 889 statement; a retrievable independent security test in the reviewed ScreenBeam sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for ScreenBeam on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, and a retrievable independent security test, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed documentation identifies no SOC 2 or SOC 3 attestation for ScreenBeam and no documented route to request a Type 2 report under NDA. Its attested scope and examination period could not be confirmed from those sources.
Sources +

Every document below is ScreenBeam’s own unless the badge says otherwise.

DocumentRead forRetrieved
ScreenBeam 1100 Plus data sheet, SBWD1100P (Jan 2026 posting)the hardened Linux appliance and the TAA and NDAA 889 statement2026-08-14
ScreenBeam - How Secure is Wireless Display for my Business? (modified 2025-05-02)signed firmware and verified boot, 802.1X network authentication, and an ungated security architecture2026-08-14
ScreenBeam support article - ScreenBeam 1100 Plus 3rd Party Penetration Test (body does not render to a plain fetch)a retrievable independent security test and a third-party assessment of the room device2026-08-15

Polaris vs BenQ InstaShow

Security questionPolaris ProPolaris EssentialsPolaris HostBenQ InstaShow
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓BenQ InstaShowBenQ names a non-Windows OS only inside its white papers, never on a specification page, and contradicts itself in the same document: the WDC15 white paper says "The InstaShow WDC15 uses an embedded Linux" and eleven pages later "The core operating system of the InstaShow WDC15 Receiver and Button is Linux and Android." No distribution, kernel version or hardening scheme is published.BenQ InstaShow WDC15 Security White Paper (Nov 2025) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓BenQ InstaShowOne sentence covers firmware signing and there is no verified boot chain: "firmware update is an exception as the firmware update program needs to verify the completeness and signature of the firmware encoding format." The same document lists "Bootloader access" as a component but never claims the bootloader validates the image at boot, and no BenQ page mentions secure boot, verified boot or a chain of trust.BenQ InstaShow WDC15 Security White Paper (Nov 2025) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—BenQ InstaShowBenQ publishes no TAA statement, no Section 889 statement and no country-of-origin declaration for InstaShow. Its US Policy Center enumerates the entire published legal set as five items - Privacy, Cookie, Virtual Patent Marking, Import/Export Compliance, EULA - and the Import/Export page covers sanctions and export control only. BenQ Corporation is headquartered in Taipei, Taiwan and does not appear on the FCC Covered List, but neither fact is a published origin attestation and origin must not be inferred from a press dateline.BenQ US Policy Center (full index of published legal and compliance documents) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓BenQ InstaShowThe WDC25 and VS25 specification pages carry the row "WiFi Protected Access - WPA3 enterprise", but BenQ names no EAP method and makes no 802.1X, EAP-TLS or RADIUS claim on any page, datasheet or white paper. Two further caveats: BenQ's own EU VS25 datasheet footnotes the same row "Upgrade from WPA3 to WPA3 Enterprise in Q1 2026", and the WDC15 white paper describes the radio as pre-shared key only - "WPA3 to couple with a pre-shared key (PSK) as the authentication".BenQ InstaShow WDC25 specifications · read 2026-08-14BenQ InstaShow WDC15 Security White Paper (Nov 2025) · second source
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓BenQ InstaShowA genuine architecture document is retrievable with no form from BenQ's own support CDN - 22 pages covering the OS and bootloader, per-port I/O capability, a three-layer network architecture, WPA3/SAE/CCMP detail, the pairing and MAC-verification flow, HTTPS by default and unique random default Web UI passwords. The caveat is the route: benq.com's own security-whitepaper page is a lead form reading "Please fill out this quick form to download our InstaShow Security Whitepaper", and the ungated copy is not listed in the WDC25 downloads categories. The document also omits secure boot, key management, threat model, SBOM and any vulnerability-disclosure contact.BenQ InstaShow WDC15 Security White Paper (Nov 2025) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓BenQ InstaShowA named lab and a named result, but nothing retrievable: "The InstaShow WDC15 has undergone rigorous security assessment and has achieved CVSS 4.0 certification from an ISO27001 and ISO17025 accredited laboratory... The assessment, conducted by Onward Security Corporation, confirms that no critical or high-risk vulnerabilities were identified." No report, certificate number, date or firmware version is published. CVSS is FIRST's vulnerability scoring system and no body issues a CVSS certification. The separate WDC30 claims are chip-scoped in BenQ's own words - "FIPS 140-3 and EAL6+ certified cryptographic algorithm, with the cryptographic key stored on a EAL6+ certified security chipset" - a NIST CMVP vendor search for BenQ returns no certificates, and one BenQ page prints "FIPS 140-4", a standard that does not exist.BenQ InstaShow WDC15 Security White Paper (Onward Security assessment) · read 2026-08-14BenQ 'How InstaShow Protects WPS From Data Leaks' (EAL6+/FIPS scoped to algorithm and chipset) · second source
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site✓BenQ InstaShowThe room device is named and separately in scope - BenQ states the WDC15 receiver itself was assessed by Onward Security Corporation - but no report, certificate, scope statement, methodology, date or firmware version is retrievable, so a buyer cannot see what was tested. The older EAL6+ and FIPS claims do not help this row: BenQ scopes them to the cryptographic algorithm and an embedded security chipset, not to the receiver as an evaluated product.BenQ 'How InstaShow Protects WPS From Data Leaks' (EAL6+/FIPS scoped to algorithm and chipset) · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. BenQ InstaShow has no published evidence in the reviewed sources for the TAA and NDAA 889 statement, and has qualified documentation for the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; an ungated security architecture; a retrievable independent security test; a third-party assessment of the room device.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

BenQ InstaShow

Strengths
  • No published evidence was found for BenQ InstaShow on the questions in this comparison. The ratings reflect the documentation available for review.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; an ungated security architecture; a retrievable independent security test; a third-party assessment of the room device, BenQ InstaShow provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for the TAA and NDAA 889 statement in the reviewed BenQ sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for BenQ InstaShow on the TAA and NDAA 889 statement, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed documentation identifies no SOC 2 or SOC 3 attestation for BenQ and no documented route to request a Type 2 report under NDA. Its attested scope and examination period could not be confirmed from those sources.
Sources +

Every document below is BenQ InstaShow’s own unless the badge says otherwise.

DocumentRead forRetrieved
BenQ InstaShow WDC15 Security White Paper (Nov 2025)the hardened Linux appliance, signed firmware and verified boot, an ungated security architecture, and a retrievable independent security test2026-08-14
BenQ US Policy Center (full index of published legal and compliance documents)the TAA and NDAA 889 statement2026-08-14
BenQ InstaShow WDC25 specifications802.1X network authentication2026-08-14
BenQ 'How InstaShow Protects WPS From Data Leaks' (EAL6+/FIPS scoped to algorithm and chipset)a third-party assessment of the room device2026-08-14

Polaris vs Yealink RoomCast

Security questionPolaris ProPolaris EssentialsPolaris HostYealink RoomCast
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓✓✓Yealink RoomCastAndroid, not a Linux distribution, and Yealink says so plainly. The product page reads "Upgraded to Android 14", and the security white paper whose "Applicable Models" line names RoomCast E2 describes the hardening: "A highly customized Android system is adopted... Yealink has removed unnecessary native system services and applications from the Android OS to minimize the attack surface", plus SELinux mandatory access control, ASLR Level 2, stack protection and binary stripping. No Windows anywhere in the range. The legacy RoomCast (end of sale 28 Feb 2025) had no published OS.Yealink RoomPanel Series and RoomCast E2 Security White Paper (Dec 2025) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓Yealink RoomCastA full verified boot chain is published for RoomCast E2: "During the boot process, the system verifies the integrity of the device using a signature public key. At every stage of startup - including the bootloader, kernel, and partition integrity - integrity verification is required. Only systems that pass the integrity check can boot normally." Firmware updates are separately signed and verified - SHA-256 digest with public-private key signature - and keys are held in an HSM and TrustZone TEE. The document is a direct, ungated PDF.Yealink RoomPanel Series and RoomCast E2 Security White Paper, s.2.2 Secure Boot · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—Yealink RoomCastYealink's Trust Center compliance register contains no TAA, Trade Agreements Act, NDAA, Section 889, country-of-origin, GSA or US federal procurement content of any kind; the single Americas entry is Canada's PIPEDA. Searched the Trust Center, the RoomCast product pages and the security white paper: nothing addresses US federal procurement eligibility either way, so a buyer with a TAA or Section 889 requirement has no published statement to rely on.Yealink Trust Center - Compliance register (full list of published statements) · read 2026-08-14Yealink RoomPanel Series and RoomCast E2 Security White Paper (Dec 2025) · second source
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Yealink RoomCastEAP-TLS is named explicitly for the room device, wired and wireless. The RoomCast E2 white paper lists wired 802.1X modes "EAP-MD5, EAP-TLS, EAP-PEAP/MSCHAPv2, EAP-TTLS/EAP-MSCHAPv2" and wireless 802.1X modes "EAP-TTLS, EAP-PEAP, EAP-TLS, EAP-PWD", stating the device requires authentication before switch-port or AP access. Yealink also publishes a standalone guide, "802.1X Authentication for Video Conferencing Endpoints". Worth noting the claim appears only in the white paper - the RoomCast E2 product page does not mention 802.1X.Yealink RoomPanel Series and RoomCast E2 Security White Paper, s.4.1-4.2 802.1X · read 2026-08-14Yealink Trust Center - Resources register (security white papers and test reports) · second source
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓Yealink RoomCastA direct-download PDF, no form and no login, naming "Applicable Models: RoomPanel E2, RoomPanelPlus E2, RoomCast E2" and running to real architecture: disabled UART/ADB/Telnet, secure boot, TrustZone TEE and HSM key custody with Shamir secret sharing, SELinux, flash encryption, wired and wireless 802.1X, TLS 1.3 with an enumerated cipher list, a SUDI X.509 per-device identity, a table of every preconfigured domain the device contacts, and the SDLC and incident-response process. Dated 18 December 2025.Yealink RoomPanel Series and RoomCast E2 Security White Paper (ungated PDF) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓Yealink RoomCastYealink publishes third-party test attestations as direct, ungated PDFs across its room portfolio - Kudelski, NetSPI, Miercom, BDO, Fox IT and Spirent are all named, with dates - so the retrievability half of this row is satisfied. Two caveats. None of them names RoomCast: the RoomPanel/RoomCast section of the register carries a Kudelski report for RoomPanel E2 only. And what is retrievable is a one-page attestation letter, not a report - it states the engagement, the lab and the dates but no findings, no severity counts and no firmware version, because "Kudelski provided Yealink with a written report" privately.Yealink Trust Center - Resources register (security white papers and test reports) · read 2026-08-14Yealink RoomPanel E2 Security Test Report by Kudelski (scope excludes RoomCast) · second source
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—Yealink RoomCastNo third-party assessment of RoomCast exists. The nearest published artifact is scoped to a different device: "Kudelski Labs... was engaged to evaluate the security of the Yealink RoomPanel E2 under attacks at user level on the hardware, software, and communication aspects", evaluated 14 March to 25 July 2025. RoomPanel E2 is a scheduling panel; RoomCast E2 is never mentioned in the letter. Yealink is unusual in publishing device-scoped rather than cloud-scoped assessments - RoomPanel E2, MeetingBar A40 and A50, MeetingBoard, DeskVision A24 all have one - which makes RoomCast's absence a real gap rather than an artifact of gating.Yealink RoomPanel E2 Security Test Report by Kudelski (scope excludes RoomCast) · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Yealink RoomCast has no published evidence in the reviewed sources for the TAA and NDAA 889 statement; a third-party assessment of the room device, and has qualified documentation for a retrievable independent security test.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Yealink RoomCast

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, 802.1X network authentication, and an ungated security architecture.
Limitations
  • The published evidence has qualifications. For a retrievable independent security test, Yealink RoomCast provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for the TAA and NDAA 889 statement; a third-party assessment of the room device in the reviewed Yealink sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Yealink RoomCast on the TAA and NDAA 889 statement and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • Yealink’s Trust Center lists a SOC 2 Type 2 dated 07/07/2025, available to existing clients through a sales representative. No request route for prospective buyers is documented. Its scope is the Yealink Management Cloud Service; the listing does not disclose the audit firm, examination period, or Trust Services Criteria. A SOC 3 is also listed, with access through a captcha form.
Sources +

Every document below is Yealink RoomCast’s own unless the badge says otherwise.

DocumentRead forRetrieved
Yealink RoomPanel Series and RoomCast E2 Security White Paper (Dec 2025)the hardened Linux appliance, signed firmware and verified boot, 802.1X network authentication, and an ungated security architecture2026-08-14
Yealink Trust Center - Compliance register (full list of published statements)the TAA and NDAA 889 statement2026-08-14
Yealink Trust Center - Resources register (security white papers and test reports)a retrievable independent security test2026-08-14
Yealink RoomPanel E2 Security Test Report by Kudelski (scope excludes RoomCast)a third-party assessment of the room device2026-08-14

Polaris vs DisplayNote Montage

Security questionPolaris ProPolaris EssentialsPolaris HostDisplayNote Montage
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓DisplayNote MontageMontage is software, so the room device is whatever host the customer supplies and DisplayNote does not control the OS. DisplayNote publishes two receivers: a Windows 10/11 receiver (i5 4th gen, 8 GB minimum) and an Android receiver (Android 8 minimum, 11 recommended, Rockchip RK3399 class). The Windows deployment therefore carries a full Windows attack surface and its patching burden, the Android deployment does not, and the companion Launcher product is Windows-only - "Install Launcher on any Windows meeting room PC". No hardening guidance is published for either host.DisplayNote Montage Android receiver system requirements · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—DisplayNote MontageThere is no firmware and no boot chain to sign, because there is no DisplayNote appliance: the room device is the customer's own Windows PC or Android panel, whose boot integrity is the hardware OEM's to attest, not DisplayNote's. The nearest equivalent artifact for a software vendor is installer code signing, and DisplayNote publishes no Authenticode or APK signing statement, no certificate subject and no checksums; the Windows and Android installers on the downloads page are served from personal OneDrive and SharePoint links.DisplayNote downloads page (installers, no signing or checksum statement) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—DisplayNote MontageDisplayNote publishes no TAA, Section 889, Buy American or country-of-origin statement. Its legal index lists only Terms and Conditions, Accessibility Statement, Privacy Policy and Cookies Policy. Montage is software and TAA place-of-manufacture rules attach to end products, so where Montage or Launcher runs on a room PC or OPS module the host hardware's status is the panel or PC OEM's to answer. DisplayNote Technologies Ltd is based in Belfast, Northern Ireland and is part of Canada's Volaris Group. (The linked page renders its content with script, so a plain fetch returns an empty body — open it in a browser.)DisplayNote legal index (full list of published legal documents) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site—DisplayNote MontageDisplayNote publishes no 802.1X, EAP, EAP-TLS, RADIUS or NAC statement. Its network requirements article is otherwise detailed - it enumerates egress ports including two full ephemeral ranges, the required FQDNs, and the application-layer allow-list "HTTP, HTTPS, DTLS, XMPP, Bonjour protocols, SRTP, DNS, STUN, TURN, and ICE" - and documents HTTP, SOCKS 5 and PAC proxy support, but never a supplicant. Network authentication of the host machine is left to the customer's own endpoint build.DisplayNote 'Network requirements, Firewalls and Proxies' support article · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓DisplayNote MontageOpen with no form or login, and specific about cryptography: "All clients and receivers are authenticated on our servers using a 4-step authentication process with SASL" and "All data transferred between the user's device and Montage is peer-to-peer (P2P) and is over TLS or DTLS with 2048-bit asymmetric encryption and 256-bit symmetric encryption. If a P2P connection fails... the software will relay the data via our TURN server over TLS TCP port 443." Three caveats: the article was last updated 17 February 2021, it states no TLS version floor, cipher suites, key management or encryption-at-rest position, and the only document actually titled a Montage security whitepaper is hosted by an integrator and describes a discontinued CentOS 7.1 appliance rather than the current software. DisplayNote's own security page is positioning, not architecture.DisplayNote 'Montage security' support article · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site—DisplayNote MontageNo third-party penetration test, security assessment, Cyber Essentials, IASME or CREST result is published, and DisplayNote does not claim one was performed. The only third-party security artifact on the site is a SecurityScorecard badge in the footer, which is an automated outside-in scan of externally observable attack surface, not an audit of controls - and the score itself is not public, since following the badge leads to a signup wall.DisplayNote 'Security and governance' page · read 2026-08-14
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—DisplayNote MontageNot applicable rather than withheld, and the distinction matters: Montage is a receiver application for Windows and Android, so there is no DisplayNote room device to assess - the appliance in the room is the customer's PC or the OEM's panel, and its assurance is Dell's, Avocor's, Newline's or Samsung's to publish. DisplayNote publishes no third-party assessment of the Montage application either, and the one Montage security whitepaper in circulation describes a long-discontinued CentOS 7.1 'Montage box' hosted on an integrator's server, not the software sold today.DisplayNote 'Security and governance' page · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. DisplayNote Montage has no published evidence in the reviewed sources for signed firmware and verified boot; the TAA and NDAA 889 statement; 802.1X network authentication; a retrievable independent security test; a third-party assessment of the room device, and has qualified documentation for the hardened Linux appliance and an ungated security architecture.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

DisplayNote Montage

Strengths
  • No published evidence was found for DisplayNote Montage on the questions in this comparison. The ratings reflect the documentation available for review.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; an ungated security architecture, DisplayNote Montage provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source. Mersive publishes evidence covering these questions in full.
  • No published evidence was found for signed firmware and verified boot; the TAA and NDAA 889 statement; 802.1X network authentication; a retrievable independent security test; a third-party assessment of the room device in the reviewed DisplayNote sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for DisplayNote Montage on signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, a retrievable independent security test, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed documentation identifies no SOC 2 or SOC 3 attestation for DisplayNote and no documented route to request a Type 2 report under NDA. Its attested scope and examination period could not be confirmed from those sources.
Sources +

Every document below is DisplayNote Montage’s own unless the badge says otherwise.

DocumentRead forRetrieved
DisplayNote Montage Android receiver system requirementsthe hardened Linux appliance2026-08-14
DisplayNote downloads page (installers, no signing or checksum statement)signed firmware and verified boot2026-08-14
DisplayNote legal index (full list of published legal documents)the TAA and NDAA 889 statement2026-08-14
DisplayNote 'Network requirements, Firewalls and Proxies' support article802.1X network authentication2026-08-14
DisplayNote 'Montage security' support articlean ungated security architecture2026-08-14
DisplayNote 'Security and governance' pagea retrievable independent security test and a third-party assessment of the room device2026-08-14

Polaris vs Vivi

Security questionPolaris ProPolaris EssentialsPolaris HostVivi
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓ViviNo Windows anywhere in Vivi's material, but Vivi never names the receiver's operating system. The FAQ describes only two deployment paths - the "Vivi Display Box (hardware receiver)" and the "Vivi Display App (software-only on supported panels)" running on "most Android-based IFPs and many Promethean ActivPanels" - so Android is the stated platform for the app path and the box OS is left unstated. No hardening, minimal-image or read-only-partition claim is published anywhere on vivi.io or in the Support Hub.Vivi FAQ, Network & Security section (page modified 18 Mar 2026) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site—ViviAsked directly what security standards it meets, Vivi's FAQ says only that "the platform and receiver are built to enterprise security standards, with secure firmware/software update practices." That is the closest published statement and it names no code signing, no signature verification and no verified boot chain. The firmware-update FAQ describes scheduling and manual upload via the device web console with no integrity claim.Vivi FAQ, Network & Security section (page modified 18 Mar 2026) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—ViviVivi publishes no TAA statement, no Section 889 statement and no country-of-origin declaration on vivi.io, in the Support Hub or on the VWP-200 datasheet. The corporate entity is Vivi International Pty Ltd (South Yarra, Victoria, Australia); Australia is a TAA-designated country, but a corporate address is not a place of manufacture and Vivi asserts nothing either way.Vivi FAQ, Network & Security section (page modified 18 Mar 2026) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓ViviVivi does publish this, in the Support Hub rather than on the marketing site, and it is stronger than the FAQ implies. The Wi-Fi Configuration page lists the supported security methods as "Enterprise (WPA2-Enterprise, 802.11X, RADIUS)", and the Wi-Fi Certificate Support page states the prerequisite as a "Wi-Fi network utilizing PEAP-MSCHAPv2 or EAP-TLS for enterprise authentication" on firmware 3.8.0 or higher, with PKCS12 user certificates and optional CA validation. Three caveats: it is documented for the Wi-Fi interface only, with no wired 802.1X supplicant described for the Ethernet/PoE port; server certificate validation is off unless a CA is uploaded ("If not uploaded, server certificate validation will not be performed"); and bulk certificate deployment requires Vivi Support to enable a feature flag per school.Vivi Support Hub - Wi-Fi Certificate Support (updated 25 Jul 2024) · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓ViviThe Vivi Support Hub is genuinely ungated - it renders with "You're viewing this with anonymous access", no form and no login - and the IT Admin Guide carries real deployment content: network configuration, firewall exceptions and port lists, proxy and SSL settings, Wi-Fi certificate handling and logging. What is absent is a security architecture document: no trust boundaries, no key management, no threat model, and no cipher or protocol specification. Vivi's only published cryptographic statement is the FAQ line "All transmissions are encrypted in transit", with no claim of encryption at rest for the media path.Vivi Support Hub - IT Admin Guide (ungated Confluence space) · read 2026-08-14Frequently Asked Questions - Vivi (page modified 18 Mar 2026) · second source
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓ViviVivi holds the Safer Technologies 4 Schools (ST4S) Product Badge, announced 19 September 2024 - a real independent scheme run by Education Services Australia and assessed across five pillars: Security, Privacy, Functionality, Online Safety and Integrations. But no report, certificate or assessment summary is published: the evidence is an announcement blog post and a badge image. The ST4S public register at st4s.edu.au/verify-a-badge renders its product list client-side and returned no readable entry, so the listing could not be independently confirmed and no expiry could be read. ST4S is also a renewable readiness review, not a penetration test.Vivi - 'Vivi Earns Safer Technologies 4 Schools Product Badge' (19 Sep 2024) · read 2026-08-14
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—ViviVivi ships a physical receiver, so the row applies, but no hardware or firmware assessment of the Vivi box is published. ST4S is a product privacy-and-security review of the platform assessed against five pillars, not a device-level test - Vivi's own description of the Security pillar is that it "focuses on ensuring that digital platforms protect against unauthorised access, data breaches, and other cybersecurity risks", with the supporting evidence given as "robust encryption and secure data handling protocols". No pen-test summary, firmware audit or hardware assessment for the VWP-200 or VWP-210 appears anywhere on vivi.io.Vivi - ST4S Product Badge announcement, five-pillar description · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Vivi has no published evidence in the reviewed sources for signed firmware and verified boot; the TAA and NDAA 889 statement; a third-party assessment of the room device, and has qualified documentation for the hardened Linux appliance, 802.1X network authentication, an ungated security architecture, and a retrievable independent security test.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Vivi

Strengths
  • No published evidence was found for Vivi on the questions in this comparison. The ratings reflect the documentation available for review.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; 802.1X network authentication; an ungated security architecture; a retrievable independent security test, Vivi provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for signed firmware and verified boot; the TAA and NDAA 889 statement; a third-party assessment of the room device in the reviewed Vivi sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Vivi on signed firmware and verified boot, the TAA and NDAA 889 statement, and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The reviewed documentation identifies no SOC 2 or SOC 3 attestation for Vivi and no documented route to request a Type 2 report under NDA. Its attested scope and examination period could not be confirmed from those sources.
Sources +

Every document below is Vivi’s own unless the badge says otherwise.

DocumentRead forRetrieved
Vivi FAQ, Network & Security section (page modified 18 Mar 2026)the hardened Linux appliance, signed firmware and verified boot, and the TAA and NDAA 889 statement2026-08-14
Vivi Support Hub - Wi-Fi Certificate Support (updated 25 Jul 2024)802.1X network authentication2026-08-14
Vivi Support Hub - IT Admin Guide (ungated Confluence space)an ungated security architecture2026-08-14
Vivi - 'Vivi Earns Safer Technologies 4 Schools Product Badge' (19 Sep 2024)a retrievable independent security test and a third-party assessment of the room device2026-08-14

Polaris vs Cisco Room Bar

Security questionPolaris ProPolaris EssentialsPolaris HostCisco Room Bar
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓Cisco Room BarCisco names the device OS - the Room Bar data sheet lists software compatibility as "RoomOS 11 or later" - and there is no Windows component in the RoomOS path. Two qualifiers. Cisco publishes no identification of the base OS or kernel underneath RoomOS and no hardening baseline or benchmark for it; and the same hardware can be ordered or reconfigured to run "Microsoft Teams Rooms on Android", so the OS on a given Room Bar depends on how it was provisioned.Cisco Room Bar data sheet (software compatibility and ordering tables) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓Cisco Room BarStated unambiguously in Cisco's ungated device security paper: when new software is loaded the device "performs an integrity check and verifies the file's signature before installing it", it is "not possible to install software if it is not signed by Cisco", and devices "reverify the software's signature during boot". That is signing plus verification at boot, published without a form or a login.Cisco Collaboration Video Device Security technical paper, May 2023 (ungated PDF) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site✓Cisco Room BarCisco publishes TAA part numbers on its own domain, which is better than the integrator-only evidence previously on file. The Room Bar data sheet ordering tables list "Cisco Room Bar TAA bundles" - CS-BAR-K9++ (TAA Radio) and CS-BAR-NR-K9++ (TAA No Radio) - plus TAA variants of Room Bar BYOD. The caveats: TAA applies only to these distinct ++ part numbers, not to the standard -K9 SKUs; and the data sheet carries no Section 889 statement and no country-of-origin declaration, so a designated country is implied but never named.Cisco Room Bar data sheet (software compatibility and ordering tables) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Cisco Room BarFully documented and ungated for Room Series devices, which includes the Room Bar. Cisco states that certificates are used for "HTTPS server, SIP, IEEE 802.1X, and audit logging", documents wired 802.1X with selectable EAP methods ("TLS: User name and password are not used. PEAP: Certificates are not used. TTLS: Both..."), SCEP enrollment and automatic renewal, CSR generation from Control Hub, DHCP Option 43 delivery of SCEP parameters, and Wi-Fi EAP-TLS. From RoomOS 26.7.1.7 the device's factory-installed SUDI certificate can be activated for wireless 802.1X - a hardware identity, not an operator-issued credential.Certificates on Board, Desk, and Room Series devices (help.webex.com, updated 10 Aug 2026) · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓Cisco Room BarA 31-page technical paper on cisco.com/c/dam, no form and no login, with genuine architecture content: RoomOS software and signing, secure data storage, onboarding and connection to Webex services, secure media, device configuration, the RoomOS WebEngine, enterprise network security, pairing with Webex apps, and physical security. The one qualifier worth recording is its age - the document is dated May 2023 and predates RoomOS 11.23, 26 and the Room Bar Pro BYOD SKUs.Cisco Collaboration Video Device Security technical paper, May 2023 (ungated PDF) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓Cisco Room BarCisco publishes a signed, directly downloadable FIPS letter dated 13 October 2025 that names Cisco Room Bar and Cisco Room Bar NR among the platforms running RoomOS 11.32 and cites FIPS 140-3 Cisco FIPS Object Module 7.3a, Cert. #4747. But the letter is Cisco's own compliance review, not a validation of the product: it states "The CMVP has not independently reviewed this analysis, testing or the results", and the validated item is Cisco's cryptographic library, not the Room Bar. No Common Criteria or NIAP certificate naming Room Bar or RoomOS was located on the Common Criteria portal or in Cisco's certification collateral.Cisco Webex RoomOS 11.32 FIPS compliance letter, signed 13 Oct 2025 · read 2026-08-14
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site✓Cisco Room BarCisco is the only vendor in this cohort with room hardware named in a public federal registry: the DoDIN APL entry behind JITC memo TN 2104001 covers a family of Webex endpoints into which Webex Room Bar and Room Bar NR were added, with Room Bar Pro and Room Bar Pro NR added later at RoomOS 11.5. Four qualifiers. The endpoints were added 'via analysis and similarity to previously certified endpoints' rather than separately tested; a joint interoperability certification is not a cybersecurity assessment and the assessment report behind an APL listing is not published; the certification PDF at jitc.fhu.disa.mil returned an empty body on two separate fetches (14 Aug and 15 Aug 2026); and the DISA APL search tool at aplits.disa.mil redirects anonymous users to a logout error, so neither the memo nor the registry entry is retrievable by a member of the public. The model list therefore rests on a search-engine index of the document, not on the document.JITC certification memo 2104001, Cisco Room Bar family on RoomOS 11.24 · read 2026-08-31independent registry

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Cisco Room Bar has qualified documentation for the hardened Linux appliance; the TAA and NDAA 889 statement; a retrievable independent security test; a third-party assessment of the room device.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Cisco Room Bar

Strengths
  • Publishes in full on signed firmware and verified boot, 802.1X network authentication, and an ungated security architecture.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; the TAA and NDAA 889 statement; a retrievable independent security test; a third-party assessment of the room device, Cisco Room Bar provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • Cisco states that Webex Suite is SOC 2 Type II audited and SOC 3 certified. The detailed SOC 2 report is distributed through Cisco’s trust process; the SOC 3 claim is public. Both describe the Webex cloud/service, not the Room Bar appliance, so neither is counted here as independent room-device testing.
Sources +

Every document below is Cisco Room Bar’s own unless the badge says otherwise.

DocumentRead forRetrieved
Cisco Room Bar data sheet (software compatibility and ordering tables)the hardened Linux appliance and the TAA and NDAA 889 statement2026-08-14
Cisco Collaboration Video Device Security technical paper, May 2023 (ungated PDF)signed firmware and verified boot and an ungated security architecture2026-08-14
Certificates on Board, Desk, and Room Series devices (help.webex.com, updated 10 Aug 2026)802.1X network authentication2026-08-14
Cisco Webex RoomOS 11.32 FIPS compliance letter, signed 13 Oct 2025a retrievable independent security test2026-08-14
JITC certification memo 2104001, Cisco Room Bar family on RoomOS 11.24 independent registrya third-party assessment of the room device2026-08-31

Polaris vs Microsoft MTR

Security questionPolaris ProPolaris EssentialsPolaris HostMicrosoft MTR
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓Microsoft MTRBoth are software platforms on third-party OEM hardware, so the honest answer depends on which device, and for a large part of the certified range it is Windows. Microsoft's own security document says of Teams Rooms on Windows: "there's a central compute module that runs Windows 10 or 11 IoT Enterprise edition", and the mitigation offered is lockdown rather than removal - Assigned Access single-app kiosk mode replacing explorer.exe, keyboard filtering, HVCI and Credential Guard, Kernel DMA Protection, Defender enabled out of the box. The other half of the range is Android: MDEP-based bars from Yealink, Jabra, MAXHUB and DTEN. Zoom Rooms likewise runs on Windows, macOS and Linux-based appliances from Neat, Poly, DTEN and others. A buyer cannot answer this row from the platform vendor; only from the specific OEM SKU.Microsoft Teams Rooms on Windows and Teams Android device security (Microsoft Learn, updated 5 Aug 2026) · read 2026-08-14
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓Microsoft MTRMicrosoft publishes a real hardware requirement for the Windows path: "Every certified compute module must ship with Trusted Platform Module (TPM) 2.0 compliant technology enabled by default" and "Secure boot is enabled by default", with the firmware checking "the signature of each piece of boot software" against OEM trust. That is an OEM-anchored UEFI Secure Boot chain, not platform-vendor-signed appliance firmware, and the signing authority is the hardware manufacturer. On the Android path Microsoft's MDEP is described as providing verified boot, attestation and anti-rollback, but again on MDEP OEM silicon. Which OEM you buy decides this row.Microsoft Teams Rooms on Windows and Teams Android device security (Microsoft Learn, updated 5 Aug 2026) · read 2026-08-14
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—Microsoft MTRNeither platform vendor publishes a TAA statement, a Section 889 statement or a country-of-origin declaration for room systems, and neither could plausibly do so: they ship software, and the hardware in the room comes from Crestron, Logitech, Poly, Neat, Yealink, Jabra or others. Microsoft's room-device security documentation, which is where a buyer would look, contains no supply-chain, TAA or 889 content at all. The country-of-origin question falls entirely to the OEM SKU.Microsoft Teams Rooms on Windows and Teams Android device security (Microsoft Learn, updated 5 Aug 2026) · read 2026-08-14
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓Microsoft MTRMicrosoft documents 802.1X and publishes a dedicated page for it, but with two explicit limits that make this less than a clean yes. First, platform coverage: 802.1X is supported on Teams Rooms on Windows using Intune-deployed device certificates and machine authentication, and is not supported on Teams Rooms for Android, where Microsoft directs customers to check with the device OEM. Second, Microsoft's own hedge on the Windows side: "Teams Rooms devices work with most 802.1X or other network-based security protocols. However, we're not able to test Teams Rooms against all possible network security configurations. Therefore, if performance issues arise that can be traced to network performance issues, you may need to disable these protocols."Microsoft Teams Rooms on Windows and Teams Android device security (Microsoft Learn, updated 5 Aug 2026) · read 2026-08-14
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓Microsoft MTRGenuinely open on both sides. Microsoft's Teams Rooms security article is on Microsoft Learn with no form and no sign-in, runs to roughly 3,800 words, was last updated 5 August 2026, and covers hardware security, software lockdown, account security and network security with separate tabs for Windows and Android - including specifics such as the Assigned Access kiosk model, Kernel DMA Protection, the passwordless local Skype account, the resource-account MFA limitation, and the Bluetooth beacon PDU type used for Proximity Join. This is architecture, not marketing.Microsoft Teams Rooms on Windows and Teams Android device security (Microsoft Learn, updated 5 Aug 2026) · read 2026-08-14
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓Microsoft MTRCertificates are published and are fully retrievable - but not for the room system. Microsoft's comparable evidence - NIAP evaluations and CMVP validations - targets Windows and Windows cryptographic modules. In every case the certified article is a client application or an operating system, not a room device.Pen Test and Security Assessments (Microsoft Service Trust Portal) · read 2026-08-30
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—Microsoft MTRNo third-party security assessment of a room appliance is published by either platform vendor, and the honest reason is structural: neither makes the appliance. Zoom's Common Criteria target is the client software with the backend excluded; Microsoft's certifications target Windows and its cryptographic modules. Microsoft goes further and puts the assessment burden on the customer - "we recommend that you run external penetration tests against Teams Rooms devices instead of running local scans" - which is a customer activity, not a published third-party report. Any device-level assessment would have to come from the OEM (Neat, Poly, Logitech, Crestron, Yealink, DTEN), and it would be that OEM's document, not Microsoft's or Zoom's.Microsoft Teams Rooms on Windows and Teams Android device security (Microsoft Learn, updated 5 Aug 2026) · read 2026-08-14

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Microsoft MTR has no published evidence in the reviewed sources for the TAA and NDAA 889 statement; a third-party assessment of the room device, and has qualified documentation for the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; a retrievable independent security test.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Microsoft MTR

Strengths
  • Publishes in full on an ungated security architecture.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; a retrievable independent security test, Microsoft MTR provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for the TAA and NDAA 889 statement; a third-party assessment of the room device in the reviewed Microsoft sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Microsoft MTR on the TAA and NDAA 889 statement and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • A current SOC 2 Type 2 exists for Microsoft 365, but it downloads only from the Service Trust Portal, which requires a subscription sign-in, and the report is marked Microsoft Confidential under NDA terms that forbid redistribution. Its scope is the cloud service, not the room appliance, and the ISO certificate names Teams without naming Teams Rooms. No SOC 3 was found.
Sources +

Every document below is Microsoft MTR’s own unless the badge says otherwise.

DocumentRead forRetrieved
Microsoft Teams Rooms on Windows and Teams Android device security (Microsoft Learn, updated 5 Aug 2026)the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device2026-08-14
Pen Test and Security Assessments (Microsoft Service Trust Portal)a retrievable independent security test2026-08-30

Polaris vs Zoom Rooms

Security questionPolaris ProPolaris EssentialsPolaris HostZoom Rooms
Linux-hardened OS: no Windows attack surfacedevice✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site✓✓✓PolarisPolaris Pro and Essentials run a hardened Linux appliance image: secure boot is mandatory on production firmware, the device's own identity keys are sealed into an NXP SE050 secure element, USB is allowlisted, and updates are signed with no downgrade path and a dual-partition rollback. Polaris Host is the exception on this page: Host is a Windows tablet we supply rather than the Linux appliance the Pods run, so the row is not ours to claim for it.Pro security architecture · on this site—Polaris HostPolaris Host is a Windows tablet, not the Linux appliance the Pods run, so the hardened-image row is not ours to claim for it. This is a real difference between Host and the Pods rather than a gap in what we know about it.Pro security architecture · on this site✓Zoom RoomsZoom Rooms likewise runs on Windows, macOS and Linux-based appliances from Neat, Poly, DTEN and others. A buyer cannot answer this row from the platform vendor; only from the specific OEM SKU.Zoom Security Guide / white paper (Zoom, PDF) · read 2026-08-30
Signed firmware / verified boot chaindevice✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓✓✓PolarisSecure boot is designed to verify trusted firmware before the device starts, and it is mandatory on production firmware rather than an option a room can turn off. Updates are signed, cannot be downgraded, and land on a dual partition so a bad update rolls back instead of bricking a room.How the platform is built · on this site✓Zoom RoomsZoom publishes no equivalent secure-boot or firmware-signing statement for Zoom Rooms - that is left entirely to the appliance maker. Which OEM you buy decides this row.Enabling Automatically Update OS/Firmware for Zoom Rooms (Zoom Support) · read 2026-08-30
TAA / NDAA 889 statement publisheddevice✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site✓✓✓PolarisPolaris Pro and Polaris Essentials are built TAA compliant, and the country-of-origin attestation is re-issued whenever a radio or SoC changes rather than being written once. Polaris Host will not be TAA compliant. It is Mersive-supplied hardware, so the statement is ours to make, and we are making it here rather than leaving it to be inferred from the Pod's.Pro specifications · on this site—Polaris HostPolaris Host will not be TAA compliant. It is Mersive-supplied hardware, so this is our statement to make and we are making it: Host will not carry a TAA country-of-origin attestation. Polaris Pro and Polaris Essentials are built TAA compliant, and their attestation is re-issued whenever a radio or SoC changes.Pro specifications · on this site—Zoom RoomsNeither platform vendor publishes a TAA statement, a Section 889 statement or a country-of-origin declaration for room systems, and neither could plausibly do so: they ship software, and the hardware in the room comes from Crestron, Logitech, Poly, Neat, Yealink, Jabra or others. The country-of-origin question falls entirely to the OEM SKU.Zoom Rooms Appliances (Zoom, PDF) · read 2026-08-30
802.1x / EAP-TLS network authdevice✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓✓✓Polaris802.1X with EAP-TLS is supported on both Polaris Pro and Polaris Essentials, so a Pod authenticates onto a corporate network the way any other managed endpoint does rather than needing a network exception written for it. On custody, because it is the claim a network team will actually check: your certificate is written to the device's certificate store and the 802.1X private-key password is a NetworkManager secret. The secure element holds the device's OWN identity and firmware-verification keys. It does not hold your network credentials, and we are not going to imply that it does.Pro security architecture · on this site✓Zoom RoomsZoom publishes 802.1X for managed Zoom Rooms devices in its Device Management network profile, and names EAP-TLS explicitly alongside PEAP, with an optional identity certificate and an upload for trusted server certificates. The qualification is platform coverage, stated in Zoom's own article: the Ethernet setting is "Network Type (only available for Windows devices)", the Wi-Fi setting is "Encryption Type (Only available for Windows)", and PEAP's "Outer Identity" is "Available only for macOS and iOS devices". The Android appliance, which is how most Zoom Rooms ship, is covered by none of them.Configuring Zoom Device Management network profile (Zoom Support, KB0065385) · read 2026-08-30
Security architecture documented in the open, ungateddevice✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓PolarisThe architecture is on this page: no form, no NDA, no sales conversation between a reviewer and the detail. That is a deliberate position rather than an oversight, because a security reviewer who cannot read how a thing works before a meeting will assume the worst about it.How the platform is built · on this site✓✓✓Zoom RoomsGenuinely open on both sides. Zoom publishes an ungated security white paper and an ungated trust center alongside it. This is architecture, not marketing.Zoom Security Guide / white paper (Zoom, PDF) · read 2026-08-30
Independent security test published, and the report or certificate is retrievabledevice✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓PolarisPsicurity assessed the platform in July 2026 against OWASP ASVS 5.0.0, every Level 1 control and a subset of Level 2, returning 0 critical, 0 high, 2 medium and 4 low findings. The public Trust Center gives the assessor, scope, date and severity result; the full engagement report is available under NDA rather than publicly retrievable. Partial is therefore the accurate grade for this row as written.What the testing found · on this site✓Zoom RoomsCertificates are published and are fully retrievable - but not for the room system. Zoom's Common Criteria page links the BSI certificate, Security Target, guidance document and certification report as direct PDFs, and states the target plainly: "The Zoom client (v5.6.6) for Windows, macOS, Android, and iOS is currently certified to Common Criteria (v3.1 rev 5)", certificate BSI-DSZ-CC-1173-2021, evaluated at EAL2, with the Zoom Backend outside the Target of Evaluation. Zoom itself advises users to run "the latest available (non-certified) version". In every case the certified article is a client application or an operating system, not a room device.Zoom Common Criteria Certification (BSI-DSZ-CC-1173-2021, certificate and report linked) · read 2026-08-14
Third-party security assessment of the room device itself, not the cloud or the OSdevice✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site✓✓✓PolarisA physical device assessment of the Gen 4 Pod and Pod Mini with the hardware in hand: debug interfaces, an attempt to lift the firmware off the flash, and a lab man-in-the-middle. No vulnerabilities at any severity. The assessor’s own caveat — that this does not make compromise impossible — is published alongside the result.What the testing found · on this site—Polaris HostPolaris Host has not been assessed by a third party. One is scheduled for the first half of 2027. Published as a no rather than left to inherit the Pod assessment, which was performed on Gen 4 Pod and Pod Mini hardware with the devices in hand and says nothing about a different device.What the testing found · on this site—Zoom RoomsNo third-party security assessment of a room appliance is published by either platform vendor, and the honest reason is structural: neither makes the appliance. Zoom's Common Criteria target is the client software with the backend excluded; Microsoft's certifications target Windows and its cryptographic modules. Any device-level assessment would have to come from the OEM (Neat, Poly, Logitech, Crestron, Yealink, DTEN), and it would be that OEM's document, not Microsoft's or Zoom's.Security Framework (Zoom Technical Library) · read 2026-08-30

Published evidence at a glance

Mersive publishes the ISO/IEC 27001 certificate and the SOC 3 openly. The SOC 2 Type 2 and the Psicurity penetration-test report are available under NDA. Request the reports. Zoom Rooms has no published evidence in the reviewed sources for the TAA and NDAA 889 statement; a third-party assessment of the room device, and has qualified documentation for the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; a retrievable independent security test.

Mersive Polaris

Strengths
  • Publishes in full on the hardened Linux appliance, signed firmware and verified boot, the TAA and NDAA 889 statement, 802.1X network authentication, an ungated security architecture, and a third-party assessment of the room device, with certificate numbers, issuing bodies and dates readable without a form.
  • Psicurity assessed the platform against OWASP ASVS 5.0.0 in July 2026. The findings summary records 0 critical · 0 high · 2 medium · 4 low · 0 informational.
  • An independent firm conducted a physical assessment of the Gen 4 Pod and Pod Mini, with direct access to the hardware.
  • The security architecture is publicly available without registration.
  • The SOC 3 report is publicly available, with no NDA or registration required.
Limitations
  • Access to the full SOC 2 Type 2 and the Psicurity penetration-test report requires an NDA. Both are available on request.
  • The ISO/IEC 27001 certificate covers the information security management system supporting the cloud service. It is a management-system certification, not a device certification.
  • The SOC 2 Type 2 scopes the Polaris cloud management console and excludes Mersive SMART, Mersive Essentials and Mersive Pro by name: those products sit outside the attested boundary, though the entity-level controls behind them are audited.
  • The SOC 2 results summarized here cover 1 March – 31 May 2025, with an opinion dated 15 July 2025. The examination recorded a single exception, on the HR control covering annual performance evaluations.
  • Polaris Host has separate ratings for the hardened Linux appliance, the TAA and NDAA 889 statement, and a third-party assessment of the room device. It is a Windows tablet running native meeting clients, with security managed through the customer’s endpoint policy. Device ratings for Pro and Essentials are shown in their respective columns.
  • Published evidence has qualifications for a retrievable independent security test. Select a cell to read the details.

Zoom Rooms

Strengths
  • Publishes in full on an ungated security architecture.
  • Publishes the SOC 2 period and scope ungated, October 2024 to October 2025, with “Zoom Rooms” named in the covered-product list. The full report requires registration.
Limitations
  • The published evidence has qualifications. For the hardened Linux appliance; signed firmware and verified boot; 802.1X network authentication; a retrievable independent security test, Zoom Rooms provides a stated position without the supporting document, or a document with a narrower scope than the room device. Each cell explains the qualification and links to the source.
  • No published evidence was found for the TAA and NDAA 889 statement; a third-party assessment of the room device in the reviewed Zoom sources. The available documentation therefore does not establish the scope, date, or issuing body for those items. This does not establish whether the capability is present.
  • Every scope question this page asks of Mersive, what a certificate actually covers, what an audit excluded by name and how old the examination is, is unanswerable for Zoom Rooms on the TAA and NDAA 889 statement and a third-party assessment of the room device, because there is no document to read it from. An undisclosed scope is not a narrower limitation than a disclosed one; it is a wider one.
  • The SOC 2 Type 2 itself sits behind trust.zoom.com and requires registration rather than an NDA, and its scope is the cloud service, not the room appliance. No SOC 3 was found, so the ungated disclosure stops at the period and the product list.
Sources +

Every document below is Zoom Rooms’s own unless the badge says otherwise.

DocumentRead forRetrieved
Zoom Security Guide / white paper (Zoom, PDF)the hardened Linux appliance and an ungated security architecture2026-08-30
Enabling Automatically Update OS/Firmware for Zoom Rooms (Zoom Support)signed firmware and verified boot2026-08-30
Zoom Rooms Appliances (Zoom, PDF)the TAA and NDAA 889 statement2026-08-30
Configuring Zoom Device Management network profile (Zoom Support, KB0065385)802.1X network authentication2026-08-30
Zoom Common Criteria Certification (BSI-DSZ-CC-1173-2021, certificate and report linked)a retrievable independent security test2026-08-14
Security Framework (Zoom Technical Library)a third-party assessment of the room device2026-08-30

Choose from 15 product comparisons. A dash means no published evidence was found for that question; it does not establish that a capability is absent.

Reading the comparison.✓✓✓ published evidence covers the question.✓ published evidence has qualifications.— no published evidence found.The marks describe documentation and scope, not a security score. A missing document does not establish that a capability is absent. Rows labeled company cover the organization; rows labeled device cover the room product. Hover over a tinted cell to preview its source, or click to keep the source card open.

The same rows, alongside every other capability and all fourteen competitors, are on thefull comparison matrix.

Security documents

Documents for your security review.

Browse public certificates, assessment summaries, and technical references. Request detailed reports under NDA or contact Mersive for help with your review.

Public summaries and technical references

Open the public certificates, assessment summaries, and deployment guidance below. For help finding a document, contact Mersive.

ISO 27001 certificate and scope

Certificate 011964-03, issued by BARR Certifications LLC on 30 June 2026 and valid through 26 June 2028. Review the certified management-system scope and statement of applicability.

Read certificate summary →Download the 2026 certificate (PDF) ↗Download the 2025 certificate (PDF) ↗

Surveillance audit summary, June 2026

The second annual surveillance audit closed with no nonconformities. Read the summary and scope here, or request access to the confidential full report below.

Read audit summary →

SOC 3 report overview

Review the audit context and system scope for the general-distribution report. It covers the Polaris cloud management console; room appliances are outside the report's system boundary.

Read report summary →Download the 2025 SOC 3 report (PDF) ↗

Independent testing record

Review the application assessment results and the May 2025 physical assessment of the Gen 4 Pod and Pod Mini, including the tested scope, findings, and assessment limits.

Read testing results →

Framework mappings

The SOC 2 report includes mappings to NIST SP 800-171 Rev. 2 and HITRUST CSF v11.5, and addresses HIPAA Security Rule administrative safeguards. These are mappings and audit coverage, not separate certifications. Detailed mappings are available in the SOC 2 report under NDA.

Read framework overview →

Security architecture

Read how the boot chain, device identity keys, network connections, and cloud services fit together, including the distinction between device keys and customer network credentials.

Read security architecture →

Data paths, ports, and endpoints

Review Polaris network requirements, endpoint and port tables, and recommended VLAN architecture.

Read network requirements →

Firmware releases & updates

Review release notes and update behavior. The device refuses a downgrade to an earlier version. The pod keeps two firmware partitions: a new image installs beside the running one, and a pod that fails to come up on the new version returns to the last known-good one.

Read firmware updates →

Security comparisons and sources

Compare published security evidence across products and vendors. Open a source to check the document and assessment date behind a comparison.

View security comparisons →

Detailed reports under NDA

Request these reports for your security review. An NDA is required for access to the detailed testing information.

SOC 2 Type 2 2026 (MCS)

The current Type 2 examination of the Polaris cloud management console, covering security, confidentiality and availability. The report does not attest the room appliances: Mersive SMART, Mersive Essentials and Mersive Pro are outside its system boundary.

NDA required
Request this report ↗

SOC 2 Type 2 Report 2025 (MCS)

The prior-year examination by BARR Advisory, P.A., covering 1 March – 31 May 2025 with an opinion dated 15 July 2025. 46 controls across 11 families, with one exception in the entire examination.

NDA required
Request this report ↗

SOC 2 Type 2 Engagement Summary Letter 2026

A letter from BARR Advisory, P.A. confirming the 2026 engagement and its scope.

NDA required
Request this letter ↗

ISO/IEC 27001:2022 Surveillance Audit Report 2026

The full June 2026 surveillance audit report from BARR Certifications LLC. Access to this confidential report is subject to Mersive approval; the summary and scope are public above.

NDA required
Request this report ↗

ISO/IEC 27001:2022 Surveillance Audit Report 2025

The full prior-year surveillance audit report, available for comparison with the current audit.

NDA required
Request this report ↗

Polaris MCS 2026 WAVA Penetration Test

Psicurity's July 2026 web application vulnerability assessment of the cloud platform, tested against OWASP ASVS 5.0.0. The full report defines tested scope, findings, and limitations; the result summary is public above.

NDA required
Request this report ↗

Polaris MCS 2025 WAVA Penetration Test

The prior-year application assessment of the cloud platform by Psicurity, available for comparison with the 2026 assessment.

NDA required
Request this report ↗

Polaris MCS 2025 WAVA Penetration Test Summary

A summary of the 2025 application assessment, including its results and scope.

NDA required
Request this summary ↗

Polaris Pod 2025 PAVA Penetration Test

Psicurity's May 2025 physical assessment of the Gen 4 Pod and Pod Mini. The full report documents the tested hardware, findings, and assessment limits.

NDA required
Request this report ↗

Other documentation and security questions

Contact Mersive for guidance specific to your product or deployment.

The document library

Browse the current Trust Center document library. Public documents are available to download directly.

See the platform live.

Hardware trials ship for every product, direct from Mersive. When the rooms prove it, we introduce your regional partner for the rollout.

Start a trial Watch on YouTube ↗