Your keys. Your rules.
Most smart card programs lock your keys inside a single vendor's ecosystem. LEAF Enterprise flips the model: Wavelynx derives a dedicated AES key profile exclusive to your organization on proven MIFARE DESFire EV3 silicon. You own the keys, and an extensive list of LEAF-compatible devices can consume them, not just Wavelynx readers. Available as a standalone symmetric credential or as a key-ownership option encoded onto LEAF Verified.
Take ownership of your credentials.
Retain key custody and format autonomy. Avoid proprietary locks while operating a high-security access system.
Dedicated Key Set
Wavelynx derives a unique corporate AES key profile exclusive to your system. No other customer can read your credentials, ensuring isolated cryptographic control across all sites.
No Vendor Lock-In
You retain ultimate custody of your security keys, and an extensive, growing list of LEAF-compatible devices already reads them. Transition reader hardware anytime and your credentials keep working. Your investment is protected.
See the device compatibility matrixConfiguration Autonomy
Map custom facility codes, badge ranges, and data blocks exactly according to your PACS requirements. Supported by all leading physical access software partners.
Who is LEAF Enterprise for?
Symmetric smart credentials built for organizations that require custom control without operational overhead.
Multi-Site Corporate
Perfect for organizations running 50+ locations that need all credentials encrypted under a single, dedicated corporate key profile, fully isolated from other systems.
Government & Regulated
Designed for frameworks where compliance requires documented key custody. Enterprise provides a clear audit trail and absolute cryptographic ownership.
Systems Integrators
For integrators managing complex portfolios who need to provision isolated key profiles for multiple end-clients within a single supply chain.
Deployment roadmap
Define Security Profile
Work with Wavelynx engineers to document facility code mapping, card formats, and cryptographic keys.
Configure & Encode
Wavelynx derives your dedicated keys and encodes the secure profile onto physical cards at our manufacturing sites. Personalization is available: photo ID printing, custom branding, and specialty card formats on request.
Deploy & Scale
Readers decrypt your custom profile instantly. Orders are tracked under your profile ID for simple, secure re-ordering.
Ready for public key?
LEAF Enterprise gives you dedicated key custody and format control that most organizations require today. Both symmetric and asymmetric profiles work on the same reader infrastructure.
When your organization is ready to eliminate shared secrets entirely, LEAF Verified offers a turnkey transition. It uses asymmetric public-key cryptography (ECC P-256) loaded at the wafer level. Your reader firmware is already capable.
A clear path forward
Symmetric profiles (LEAF Enterprise) share a secret key between card and reader, a proven, high-security model trusted across your infrastructure today.
Your LEAF Enterprise key set can be encoded directly onto LEAF Verified credentials today: public-key security and your dedicated symmetric profile on one card. Move to public key on your own timeline, no rip-and-replace.
Design your key profile.
Request an Enterprise evaluation kit or schedule a meeting with a Wavelynx security engineer to outline custom secure credentials.
Frequently Asked Questions
Trusted across the access control ecosystem
Downloads & Resources
Access detailed specifications and deployment documentation for custom symmetric credentials.
LEAF Enterprise Spec Sheet
Complete technical specifications including supported IC models, communication frequencies, encryption algorithms, and physical dimension configurations.
Deployment Planning Guide
Step-by-step guidance on how to define facility codes, map data blocks, derive corporate root keys, and onboard with your Wavelynx PACS integration partner.
Explore the full credential family.
Pre-configured symmetric smart credentials. Any LEAF-compatible reader, no key setup.
Learn moreThe first turnkey public-key credential. Unclonable by design. Carries your MIFARE apps and custom key sets.
Learn moreApple & Google Wallet credentials via NFC. Aliro zero-trust support coming.
Learn more