Most smart card programs lock your encryption keys inside one vendor's system. LEAF Enterprise gives you a key of your own, on proven high-security chips, with a growing list of LEAF-compatible readers that can already read it. Order it standalone, or add it to a LEAF Verified card.

Keep control of your keys and how your cards are set up, without getting locked into one vendor's system. Wavelynx handles the complex parts (key creation, protection, and management) at no extra cost.
Wavelynx creates a unique encryption key just for your organization. No other customer can read your cards, so every site you run stays completely separate and secure.
Learn more about key managementYou keep full control of your keys, and a growing list of LEAF-compatible readers can already read them. Switch reader brands whenever you want and your cards keep working. Your investment stays protected.
See reader compatibilitySet up your own facility codes, badge number ranges, and card data exactly the way your access control system needs. Works with all major access control software.
Discuss your needs with an expertBuilt for organizations that need full control over their credentials, without the extra hassle of managing it themselves.
Great for companies with 50 or more locations that want every badge protected by one dedicated key, completely separate from any other organization's system.
Built for industries where compliance rules require you to document exactly who controls your security keys. Enterprise gives you a clear paper trail and full ownership.
Enterprise credentials can carry legacy and long range technology alongside the dedicated key set you own. One card, one issuance, no second badge to manage.
An open standard for phishing-resistant, passwordless login using public-key cryptography, replacing passwords with secure, local authentication for multi-factor scenarios. Available with LEAF Universal and LEAF Enterprise.
Embed a standard RAIN UHF chip alongside the credential. One card handles door access at 13.56 MHz and long range reads at UHF, so parking, gates, and asset tracking run on the badge people already carry.
Add 125 kHz Prox functionality to your card for continued support on legacy readers while you move to modern, secure credential technology.
A blank magstripe to support legacy installations transitioning to modern, secure technology.
Work with Wavelynx engineers to document facility code mapping, card formats, and cryptographic keys.
Wavelynx creates your keys and loads them onto physical cards. We can also add photo ID printing, your branding, or specialty card formats if you need them.
Your readers recognize your cards instantly. Every reorder is tracked under your own profile ID, so getting more cards later is quick and secure.
LEAF Enterprise gives you the key ownership and control most organizations need right now. And because both credential types work on the same readers, you're not locked into one path.
When you're ready to remove shared keys from the picture entirely, LEAF Verified is a ready-made next step. It uses a more advanced method called public-key cryptography, built directly into the card, and LEAF-compatible readers like Wavelynx APEX already support it.
LEAF Enterprise cards and readers share a secret key to verify each other: a proven, high-security approach already trusted across your buildings today.
Your LEAF Enterprise key can be loaded directly onto a LEAF Verified card, so you get both security types on one credential. That means you can move to the newer technology on your own schedule, with no need to replace all your cards and readers at once.
Schedule time with a Wavelynx security engineer to design your organization's key profile.
LEAF Universal is pre-configured with shared cryptographic keys for immediate plug-and-play compatibility. LEAF Enterprise derives a custom, dedicated symmetric key profile unique to your organization, keeping encryption isolated across your entire system.
Wavelynx derives and securely injects your organization's dedicated encryption key onto the smart credentials during manufacturing. You retain complete custody and control over the security profile and key configuration.
In most cases, yes. Because LEAF is an open standard, your custom key profile can typically be configured on other LEAF-compatible readers, not just Wavelynx's. This is designed to reduce dependence on any single reader vendor. Exact compatibility varies by device and firmware, so we recommend checking our compatibility matrix or talking with a Wavelynx engineer to confirm your specific hardware.
LEAF Enterprise and LEAF Verified are designed to work together and can coexist on the same reader infrastructure. Most existing Wavelynx readers already support both symmetric and asymmetric credentials, so you can move to Verified on your own timeline without replacing your hardware. If you're running older firmware, check with your Wavelynx contact to confirm your specific readers are up to date.
Each customer is assigned a unique Secure Access Profile ID. When you place a re-order, it is mapped back to your profile ID, ensuring the new badges are encoded with the identical dedicated keys and format configuration.
Yes. The LEAF Enterprise ISO Card supports standard photo printing and custom branding on both front and back surfaces, using high-definition direct-to-card dye sublimation or retransfer printers.











































The first ready-to-deploy public-key credential. Cryptographically resistant to cloning. Carries your MIFARE apps and custom key sets.
Learn morePre-configured symmetric smart credentials. Any LEAF-compatible reader, no key setup.
Learn more