The LEAF Platform

Stop choosing between security and disruption.

The LEAF portfolio gives you a clear upgrade path, from insecure to secure smart credentials, without replacing your infrastructure overnight. Move at your pace.

LEAF VERIFIED
CHIP ID: DUOX-8F92-C0
LEAF ENTERPRISE
KEY SET: CUSTOM SECURE
Upgrade Paths

Transition without forklift upgrades.

You shouldn't have to replace every reader on every door just to upgrade your security. Wavelynx specializes in transition strategies.

Our smart cards can be ordered as dual-technology credentials, combining high-security MIFARE smart chips with legacy 125 kHz Prox coils.

Your employees use the same badge while you upgrade readers door-by-door.

The Migration Path

  • 1 Identify IT's requirements for digital access and FIDO applications
  • 2 Deploy APEX or other LEAF-compatible readers on high-security doors
  • 3 Issue Dual-Tech credentials to your employee base
  • 4 Run high-security smart mode at upgraded doors
  • 5 Run fallback legacy Prox mode at un-upgraded doors
  • 6 Complete the transition: every door is now high-security
Good & Best

Choose your level of security.

Every environment has different security needs. The LEAF portfolio provides a clear roadmap to step up your security without changing your reader base.

Good

Secure Out of the Box

LEAF Universal

AES-encrypted credentials on MIFARE DESFire EV3, pre-configured and guaranteed unique. No key ceremonies. No databases. No waiting. The right start for moving off legacy Prox.

Explore LEAF Universal

Plug-and-play on any LEAF-compatible reader

Need to own your keys?

LEAF Enterprise gives your organization a dedicated AES key profile, exclusive to you. Order it as a standalone credential or encoded onto LEAF Verified.

Learn about LEAF Enterprise

On the horizon: full zero-trust mutual authentication and Aliro wallet credentials, built on the same foundation as LEAF Verified. See what's coming →

How We Build Differently

Not all "open" is created equal.

Every vendor claims openness. Here is how Wavelynx actually delivers it, and why it matters to your bottom line.

Multi-Vendor Freedom

Your badge works on any compatible reader, not just ours.

LEAF is backed by a multi-vendor ecosystem. No single-vendor lock-in.

See the device compatibility matrix

Key Ownership

Your keys, your rules. Upgrade on your timeline.

Other vendors force rip-and-replace when they change key models. You never will.

Proven Silicon

Built on NXP MIFARE: billions of credentials deployed worldwide.

Standardized cryptography on a global platform trusted by transit and governments. No black boxes.

Find Your Fit

Which LEAF credential is right for you?

Every environment is different. Match your operational needs to the right credential.

LEAF Universal

Pre-configured symmetric smart credentials. Any LEAF-compatible reader, no key setup.

Learn more
LEAF Enterprise

Custom key ownership: a dedicated AES key profile exclusive to your organization. Standalone or encoded onto LEAF Verified.

Learn more
LEAF FIDO

FIDO2 passwordless desktop login + MIFARE physical access in one card.

Learn more
Wavelynx Mobile

Apple & Google Wallet credentials via NFC. Aliro zero-trust support coming.

Learn more

Trusted across the access control ecosystem

Hanwha Vision Acre Security PDQ Hirsch RF Ideas

Map your migration path.

Our engineers will design a phased credential upgrade plan for your environment, no forklift required. Or request a physical sample kit to test LEAF credentials yourself.

Common Questions

Frequently Asked Questions

LEAF is an open-standard cryptographic format for physical access credentials, governed by the LEAF Community. It was created to break vendor lock-in by enabling multiple reader manufacturers to decrypt the same secure card format. Wavelynx credentials are built strictly on the LEAF standard.
Universal is the plug-and-play symmetric credential: secure out of the box for organizations that want simplicity. Verified is our flagship: a turnkey public-key credential that's just as easy to deploy but unclonable by design, and it can carry existing MIFARE applications and custom key sets on the same card. Enterprise is the key-ownership option: a dedicated symmetric key profile exclusive to your organization, available standalone or on a Verified credential.
Not necessarily. Dual-technology cards contain legacy 125 kHz Prox coils so they work with your existing readers. As you replace old readers with modern smart-capable readers (like Wavelynx APEX or Ethos), those doors will read the high-security smart chip instead. You can transition door-by-door without ever leaving employees without access.
Yes. Wavelynx Wallet supports NFC mobile credentials loaded into Apple Wallet and Google Wallet. We also actively support the Aliro mobile credential standard developed by Apple, Google, Samsung, and the CSA, allowing public-key zero trust mobile access using the same trust model as LEAF Verified physical cards.
LEAF credentials are built on an open standard, meaning the same card works with readers from multiple manufacturers. HID iCLASS SE and SEOS credentials are proprietary formats that only work with HID readers. LEAF also offers a public-key credential tier (LEAF Verified) that eliminates shared secrets entirely: a security model that proprietary symmetric platforms cannot match.
Absolutely. LEAF Universal, Enterprise, and Verified credentials all use the same LEAF data format and can coexist in the same facility on the same reader infrastructure. Many organizations start with Universal for general population access and deploy Verified for high-security zones, all on the same readers.
LEAF credentials are built on NXP MIFARE DESFire EV3 and MIFARE DUOX silicon, which are rated for a minimum of 500,000 read/write cycles. Under normal daily use, a physical smart card will last well beyond 10 years. The underlying cryptographic standards (AES, ECC P-256) are expected to remain secure for decades.
"Open standard" means the LEAF credential data format specification is published and available to any reader manufacturer or PACS vendor who wants to support it. This is governed by the LEAF Community, not by a single company. If Wavelynx disappeared tomorrow, your credentials would still work with any LEAF-compatible reader on the market. Your investment is protected by the standard, not by a vendor relationship.