Now Shipping

Deploy in Minutes. Secure by Design. Open by Default.

LEAF Verified is the first physical credential built on public key infrastructure. No hidden fees. No forced migrations. No lock-in. Enrollment takes under a minute.

3 steps Tap. Verify. Enrolled.
EAL 6+ government-grade hardware security
100% open standards, documentation, ecosystem
LEAF Verified
No vendor lock-in
Graduated security
Open standards
Trusted across the access control ecosystem
Platforms
Hanwha Vision Acre Security
Devices
Wavelynx PDQ Hirsch RF Ideas

Tap. Verify. Enrolled.

Every badge is an NFC-enabled enrollment device. No app required.

LEAF Verified Credential
9:41
Link Your Badge Badge #31064771703
|
Verify & Enroll
Enrolled Badge #31064771703
Identity linked · Access granted
Any NFC Phone
1 Tap
2 Verify
3 Enrolled

Native NFC · No app required · Works on iOS & Android

No platform integration yet?

Scan the QR code on any LEAF pack to instantly access your credential manifest. Import the CSV into your access control platform.

Try a Live Manifest Preview

See How LEAF Verified Works for You

Select your role to see the capabilities that matter most to your deployment.

Enterprise Security

One Credential. Every Reader. No Lock-in.

LEAF Verified breaks the proprietary cycle. You own your keys, choose your hardware, and move between platforms freely.

Absolute Credential Ownership

Stop being painted into a corner by proprietary systems and hidden contractual pitfalls. You fully own your cryptographic keys, eliminating the mountains of IT overhead previously required for true security independence.

Ultimate Hardware Freedom

Mix and match readers from any compatible manufacturer. Your credentials work universally, preserving your CapEx.

Future-Proof to Aliro

Built on the exact same ECC P-256 foundation as Aliro. The physical credentials you deploy today are ready for the mobile wallet future.

Platforms

Every Badge Tap Opens Your Platform.

Configure the tap-to-phone URL to power self-enrollment, support, or any custom workflow, straight from the physical credential.

Zero-Friction Bulk Enrollment

Use the Credential Manifest to ingest hundreds of badges instantly. Provide your users with a magical, one-click onboarding experience.

Drive Users to Your App

Every credential is a physical touchpoint. Configure the NFC tap-to-phone URL to redirect straight into your mobile app or help desk.

Zero Integration Red Tape

Same certificate structure across every LEAF Verified credential. No proprietary middleware and no tedious software validation programs. Just open interoperability that works out of the box.

NFC
Tap
Self-Enrollment
Help Desk
Your App
Device Manufacturers

One Firmware. LEAF and Aliro.

The cryptographic building blocks are identical. Implement ECC P-256 once, support both physical credentials and mobile wallets.

Slash R&D Overhead

Implement ECC P-256 and X.509 verification once. Use it to support both physical LEAF credentials and digital Aliro wallets.

No NDAs, No Black Boxes

Integration documentation is open-source and publicly available. Your firmware engineers can start evaluating the protocol today.

Zero Proprietary Middleware

Built purely on ISO 14443 and ISO 7816-4. No hidden licensing fees or mandated secure elements required on the reader side.

ECC P-256 / X.509 Crypto Engine
LEAF Verified
Aliro
Integrators & Installers

Mount. Import. Done.

Universal interoperability and tap-to-phone enrollment mean one site visit, zero callbacks.

The Death of Key Ceremonies

No SAM cards. No config apps. No site visits to rotate keys. Every credential carries its own certificate and authenticates natively.

Out-of-the-Box Compatibility

Because LEAF Verified relies on standard open protocols, readers work immediately without complex device profiling.

Instant Panel Provisioning

Provide the digital manifest to the end-user. They click "Import," and the entire site is provisioned. You get off-site faster.

Mount Any compatible reader
Import Bulk credential manifest
Done One site visit

Two Security Tiers.
One Credential.

Every LEAF Verified credential carries its own cryptographic identity and ships with two security tiers built in. The reader at each door determines which one runs.

Cryptographic Foundation

Cryptographic Independence

Every credential carries its own mathematically verified PKI identity. No shared secrets. No master keys. Total hardware freedom.

Revoke one badge instantly. The rest stay untouched.
Most Doors

Open Application

Unilateral PKI · Zero Key Management

  • Mount the reader. Walk away. It works.
  • No key ceremonies, no SAM cards, no config apps
  • Lobbies, stairwells, parking, common areas
Select Doors

Enterprise Application

Mutual Auth · Reader Certificates Required

  • Credential and reader mutually verify each other
  • Deploy only on the doors that demand it
  • Server rooms, executive suites, restricted zones
Silicon Foundation NXP MIFARE DUOX · EAL 6+

The LEAF Verified Ecosystem

A growing ecosystem of platforms, readers, and integrations, all built on open standards. No hidden licensing fees, no mandated secure elements. You choose the software. You choose the hardware.

Native Platform Integrations

Compatible Readers & Hardware

Supported
Wavelynx
Supported
PDQ
In Development
Hirsch
In Development
RF Ideas

Integrate Your Devices

View open-source onboarding docs

Frequently Asked Questions

Traditional credentials lock you into a single vendor's ecosystem by copying one proprietary master key across every reader you own. LEAF Verified breaks this cycle. By giving every credential its own unique cryptographic identity based on open standards, you eliminate vendor lock-in, preserve your CapEx, and gain the freedom to mix and match compatible hardware without asking for permission.

Credentials communicate natively with readers, not software. As long as your readers support standard open protocols (ISO 14443, ISO 7816-4) and ECC P-256 public key cryptography, they can support LEAF Verified. Many modern readers from LEAF-compatible manufacturers support this natively or via a simple firmware update.

At the door, absolutely nothing. Your workforce taps their badge exactly as they do today. The transformation happens entirely under the hood, giving your administrative and security teams a friction-free enrollment experience without requiring users to change their habits or download new apps.

The Credential Manifest eliminates the tedious, error-prone process of manually typing in badge numbers one at a time. Every order includes a secure digital inventory of your credentials. You can download the full list as a CSV and import it directly into your access control platform, enrolling hundreds of badges in seconds, or utilize the API for automated provisioning.

They solve two sides of the same equation. LEAF Verified secures the physical credentials your workforce carries today, while Aliro is working to bring that same open standard of security to digital wallets on smartphones. Because LEAF Verified is built on the exact same ECC P-256 cryptographic foundation, deploying it today ensures your physical reader infrastructure is already future-proofed for the mobile wallet transition.

The Public Key Era:
Why LEAF Verified and Aliro Are Stronger Together

A technical overview of the industry's shift from symmetric to public key access control, and how physical and digital credentials fit together.

What's Inside
The Public Key Revolution Is Here
Chip, Credential, and Community
What Is Aliro, and What It Isn't
Better Together: The Complementary Model
Common Questions
leaf_verified_whitepaper.pdf
The Public Key Era
Why LEAF Verified and Aliro Are Stronger Together
1 / 8