Own Your Keys. Skip the Lock-In.

Most smart card programs lock your encryption keys inside one vendor's system. LEAF Enterprise gives you a key of your own, on proven high-security chips, with a growing list of LEAF-compatible readers that can already read it. Order it standalone, or add it to a LEAF Verified card.

A white LEAF Enterprise smart card.

Take ownership of your Enterprise credentials.

Keep control of your keys and how your cards are set up, without getting locked into one vendor's system. Wavelynx handles the complex parts (key creation, protection, and management) at no extra cost.

Dedicated Key Set

Wavelynx creates a unique encryption key just for your organization. No other customer can read your cards, so every site you run stays completely separate and secure.

Learn more about key management

Infrastructure Freedom

You keep full control of your keys, and a growing list of LEAF-compatible readers can already read them. Switch reader brands whenever you want and your cards keep working. Your investment stays protected.

See reader compatibility

Configuration Autonomy

Set up your own facility codes, badge number ranges, and card data exactly the way your access control system needs. Works with all major access control software.

Discuss your needs with an expert

Who is LEAF Enterprise for?

Built for organizations that need full control over their credentials, without the extra hassle of managing it themselves.

Multi-Site Corporate

Great for companies with 50 or more locations that want every badge protected by one dedicated key, completely separate from any other organization's system.

Government & Regulated

Built for industries where compliance rules require you to document exactly who controls your security keys. Enterprise gives you a clear paper trail and full ownership.

Add the technologies your sites already run on.

Enterprise credentials can carry legacy and long range technology alongside the dedicated key set you own. One card, one issuance, no second badge to manage.

FIDO2

An open standard for phishing-resistant, passwordless login using public-key cryptography, replacing passwords with secure, local authentication for multi-factor scenarios. Available with LEAF Universal and LEAF Enterprise.

UHF (RAIN)

Embed a standard RAIN UHF chip alongside the credential. One card handles door access at 13.56 MHz and long range reads at UHF, so parking, gates, and asset tracking run on the badge people already carry.

Prox (Legacy)

Add 125 kHz Prox functionality to your card for continued support on legacy readers while you move to modern, secure credential technology.

Magstripe (Legacy)

A blank magstripe to support legacy installations transitioning to modern, secure technology.

See the full add-on compatibility grid →

Deployment roadmap

1

Define Security Profile

Work with Wavelynx engineers to document facility code mapping, card formats, and cryptographic keys.

2

Configure & Encode

Wavelynx creates your keys and loads them onto physical cards. We can also add photo ID printing, your branding, or specialty card formats if you need them.

3

Deploy & Scale

Your readers recognize your cards instantly. Every reorder is tracked under your own profile ID, so getting more cards later is quick and secure.

Thinking about your next step?

LEAF Enterprise gives you the key ownership and control most organizations need right now. And because both credential types work on the same readers, you're not locked into one path.

When you're ready to remove shared keys from the picture entirely, LEAF Verified is a ready-made next step. It uses a more advanced method called public-key cryptography, built directly into the card, and LEAF-compatible readers like Wavelynx APEX already support it.

A clear path forward

LEAF Enterprise cards and readers share a secret key to verify each other: a proven, high-security approach already trusted across your buildings today.

Your LEAF Enterprise key can be loaded directly onto a LEAF Verified card, so you get both security types on one credential. That means you can move to the newer technology on your own schedule, with no need to replace all your cards and readers at once.

Design your Enterprise key profile.

Schedule time with a Wavelynx security engineer to design your organization's key profile.

Frequently Asked Questions

What's the difference between LEAF Universal and LEAF Enterprise?+

LEAF Universal is pre-configured with shared cryptographic keys for immediate plug-and-play compatibility. LEAF Enterprise derives a custom, dedicated symmetric key profile unique to your organization, keeping encryption isolated across your entire system.

Who manages the cryptographic keys for LEAF Enterprise?+

Wavelynx derives and securely injects your organization's dedicated encryption key onto the smart credentials during manufacturing. You retain complete custody and control over the security profile and key configuration.

Can I use Enterprise credentials with third-party readers?+

In most cases, yes. Because LEAF is an open standard, your custom key profile can typically be configured on other LEAF-compatible readers, not just Wavelynx's. This is designed to reduce dependence on any single reader vendor. Exact compatibility varies by device and firmware, so we recommend checking our compatibility matrix or talking with a Wavelynx engineer to confirm your specific hardware.

What happens if I want to switch from Enterprise to Verified later?+

LEAF Enterprise and LEAF Verified are designed to work together and can coexist on the same reader infrastructure. Most existing Wavelynx readers already support both symmetric and asymmetric credentials, so you can move to Verified on your own timeline without replacing your hardware. If you're running older firmware, check with your Wavelynx contact to confirm your specific readers are up to date.

How are Enterprise credentials ordered and re-ordered?+

Each customer is assigned a unique Secure Access Profile ID. When you place a re-order, it is mapped back to your profile ID, ensuring the new badges are encoded with the identical dedicated keys and format configuration.

Can I print photos and logos on Enterprise cards?+

Yes. The LEAF Enterprise ISO Card supports standard photo printing and custom branding on both front and back surfaces, using high-definition direct-to-card dye sublimation or retransfer printers.

You Trust Them. They Trust Us.

Cove.is
Groove Identification Solutions
TradeID
PSA
Wesco
CIE
MyDoorView
Nedap
Hartmann Controls
Smart Spaces
RightCrowd
ELATEC
RFIDeas
SWIFTCONNECT
SPLAN
Soloinsight
SHARRY
COHESION
B-LINE
ALERT ENTERPRISE
SPECTRUM
YOURSIX
TYCO
SMARTRENT
SIELOX
SICUNET
REALPAGE
PDK
PCSC
MAXXESS
LIFTMASTER
LIBERTY
ISONAS
HONEYWELL
GENETEC
GENEA
GATEWISE
BUTTERFLYMX
DIGITAL MONITORING PRODUCTS
BRIVO
ALARM.COM
AMAG TECHNOLOGY
ACRE

Explore the full credential family.

LEAF Verified

The first ready-to-deploy public-key credential. Cryptographically resistant to cloning. Carries your MIFARE apps and custom key sets.

Learn more
LEAF Universal

Pre-configured symmetric smart credentials. Any LEAF-compatible reader, no key setup.

Learn more
Mobile Access

Apple & Google Wallet credentials via NFC. Aliro zero-trust support coming.

Learn more
Credential Add-ons

FIDO2, UHF, Prox or magstripe on the same LEAF card.

Learn more