Fail-safe or fail-secure, decided door by door.
How the lock behaves when power is lost, what the controller contributes to a fire release, and where each of those decisions gets written down.
The two fail states
A fail-safe lock releases when power is lost. It is the usual choice for a door on an escape route, because a power failure leaves the route open.
A fail-secure lock stays locked when power is lost, and relies on a mechanical means of escape. It is the usual choice where the security of the door matters more than the convenience of a power failure release.
The choice belongs to the door's egress strategy and the local fire authority — not to the access control system. The system's job is to release the door when it is told to, reliably.
What the access control side decides
The lock relay's normally-open or normally-closed state, set by the relay jumper links and the software relay setting, so the relay matches how the lock is powered.
Whether the emergency break glass is wired in series with the electromagnetic lock, giving physical release independent of the software.
Where the fire panel's dry contact lands — IN1 and 0V on the nearest controller.
Which doors are grouped for fire release, so an alarm releases the doors in that group and the master controller (ID 00).
What happens after the alarm clears: the doors stay in Security Off until an operator sets them back to Security On.
Where each decision is recorded
| Decision | What decides it | Where it is recorded |
|---|---|---|
Lock type | Door type, frame and egress route | Door hardware schedule |
Fail state: safe or secure | Egress route and fire strategy | Door hardware schedule |
Relay state, normally open or closed | Whether the lock is powered to lock or powered to release | Controller relay jumper and software relay setting |
Egress device | Door type and local code | Push button, break glass, or both, wired back to the controller |
Release on alarm | Fire strategy for that door | Fire panel dry contact on IN1 and 0V, plus the fire alarm group |
Re-secure after alarm | Building procedure | Operator action in the software — the system does not re-lock on its own |
Two things that catch people out
A fire panel output that is not a dry contact can damage the controller input. Confirm the signal type before you land it on IN1.
A door that released on a fire signal does not re-secure itself when the panel clears. Somebody has to set it back to Security On, and on a large site that is a procedure, not an afterthought.
For the specifier
The fail state belongs in the door hardware schedule. The release behaviour — fire input, group, break glass, relay state — belongs in the access control specification.
Falco controllers carry the fire alarm release on the controller itself, so a door releases on alarm whether or not the server is reachable.
Send us the door list. We will come back with the model list for the doors you have, and the reference material your installer needs.
The fail-state decision sheet
A per-door worksheet: lock type, fail state, egress device, fire input, relay state and the commissioning signature — the sheet that makes a door list reviewable.
No form. Download it, use it on site, and send the project our way when you want the model list priced.
Where this comes from.
Every technical statement on this page is drawn from Falco documentation. Nothing here is written to fill a page.
VAULT Site support documentation — fire alarm integration: dry contact on IN1 and 0V, break glass in series with the electromagnetic lock, group release, Security Off state and the manual re-secure step.
Falco S32 and CF PoE controller datasheets — fire alarm fail-safe door release held on the controller, independent of server availability.
Falco controller wiring diagrams — relay jumper links and lock relay settings.
Falco's published tender guidance for specifiers — fail-safe and fail-secure are set by the architect and the local fire authority.