Dedicated Corporate Keys

Your keys. Your rules.

Most smart card programs lock your keys inside a single vendor's ecosystem. LEAF Enterprise flips the model: Wavelynx derives a dedicated AES key profile exclusive to your organization on proven MIFARE DESFire EV3 silicon. You own the keys, and an extensive list of LEAF-compatible devices can consume them, not just Wavelynx readers. Available as a standalone symmetric credential or as a key-ownership option encoded onto LEAF Verified.

CORPORATE SECURE
KEY DERIVATION: AES-256
Enterprise Control

Take ownership of your credentials.

Retain key custody and format autonomy. Avoid proprietary locks while operating a high-security access system.

Dedicated Key Set

Wavelynx derives a unique corporate AES key profile exclusive to your system. No other customer can read your credentials, ensuring isolated cryptographic control across all sites.

No Vendor Lock-In

You retain ultimate custody of your security keys, and an extensive, growing list of LEAF-compatible devices already reads them. Transition reader hardware anytime and your credentials keep working. Your investment is protected.

See the device compatibility matrix

Configuration Autonomy

Map custom facility codes, badge ranges, and data blocks exactly according to your PACS requirements. Supported by all leading physical access software partners.

Ideal Alignment

Who is LEAF Enterprise for?

Symmetric smart credentials built for organizations that require custom control without operational overhead.

Multi-Site Corporate

Perfect for organizations running 50+ locations that need all credentials encrypted under a single, dedicated corporate key profile, fully isolated from other systems.

Government & Regulated

Designed for frameworks where compliance requires documented key custody. Enterprise provides a clear audit trail and absolute cryptographic ownership.

Systems Integrators

For integrators managing complex portfolios who need to provision isolated key profiles for multiple end-clients within a single supply chain.

Onboarding Process

Deployment roadmap

1

Define Security Profile

Work with Wavelynx engineers to document facility code mapping, card formats, and cryptographic keys.

2

Configure & Encode

Wavelynx derives your dedicated keys and encodes the secure profile onto physical cards at our manufacturing sites. Personalization is available: photo ID printing, custom branding, and specialty card formats on request.

3

Deploy & Scale

Readers decrypt your custom profile instantly. Orders are tracked under your profile ID for simple, secure re-ordering.

Looking Forward

Ready for public key?

LEAF Enterprise gives you dedicated key custody and format control that most organizations require today. Both symmetric and asymmetric profiles work on the same reader infrastructure.

When your organization is ready to eliminate shared secrets entirely, LEAF Verified offers a turnkey transition. It uses asymmetric public-key cryptography (ECC P-256) loaded at the wafer level. Your reader firmware is already capable.

A clear path forward

Symmetric profiles (LEAF Enterprise) share a secret key between card and reader, a proven, high-security model trusted across your infrastructure today.

Your LEAF Enterprise key set can be encoded directly onto LEAF Verified credentials today: public-key security and your dedicated symmetric profile on one card. Move to public key on your own timeline, no rip-and-replace.

Design your key profile.

Request an Enterprise evaluation kit or schedule a meeting with a Wavelynx security engineer to outline custom secure credentials.

Common Questions

Frequently Asked Questions

LEAF Universal is pre-configured with shared cryptographic keys for immediate plug-and-play compatibility. LEAF Enterprise derives a custom, dedicated symmetric key profile unique to your organization, ensuring isolated encryption across your entire system.
Wavelynx derives and securely injects your dedicated corporate root key onto the smart credentials during manufacturing. You retain complete custody and control over the security profile and key configuration.
Yes. Because LEAF is an open-standard format, any LEAF-compatible reader can be configured with your custom key profile to read your credentials. This prevents proprietary hardware lock-in.
LEAF Enterprise and LEAF Verified are fully compatible and can coexist on the same reader infrastructure. Your existing Wavelynx reader firmware already supports both symmetric and asymmetric credentials, allowing for a phased transition.
Each customer is assigned a unique Secure Access Profile ID. When you place a re-order, it is mapped back to your profile ID, ensuring the new badges are encoded with the identical dedicated keys and format configuration.
Yes. The LEAF Enterprise ISO Card supports standard photo printing and custom branding on both front and back surfaces, using high-definition direct-to-card dye sublimation or retransfer printers.

Trusted across the access control ecosystem

Hanwha Vision Acre Security PDQ Hirsch RF Ideas
Technical Library

Downloads & Resources

Access detailed specifications and deployment documentation for custom symmetric credentials.

LEAF Enterprise Spec Sheet

Complete technical specifications including supported IC models, communication frequencies, encryption algorithms, and physical dimension configurations.

Download PDF

Deployment Planning Guide

Step-by-step guidance on how to define facility codes, map data blocks, derive corporate root keys, and onboard with your Wavelynx PACS integration partner.

Download PDF
The LEAF Portfolio

Explore the full credential family.

LEAF Universal

Pre-configured symmetric smart credentials. Any LEAF-compatible reader, no key setup.

Learn more
LEAF FIDO

FIDO2 passwordless desktop login + MIFARE physical access in one card.

Learn more
Wavelynx Mobile

Apple & Google Wallet credentials via NFC. Aliro zero-trust support coming.

Learn more