What is a Gallagher (Cardax) access credential?
Gallagher is a New Zealand access-control manufacturer whose card technology traces back to the Cardax brand, and many sites still call the credentials "Cardax" cards. A modern Gallagher credential is an AES-secured 13.56 MHz contactless smart card that carries a Gallagher-specific application, and it is read by Gallagher's T-Series readers into a Command Centre management system.
Gallagher describes this credential as offering "secure 128-bit AES encryption," with "card data … encrypted using 128-bit AES with an additional layer of security." That is a fundamentally different model from the 125 kHz Cardax IV proximity cards it replaces, whose identity number is broadcast in the clear. The Gallagher smart card proves its identity cryptographically before any data is exchanged.
What frequency and technology does a Gallagher card use?
A modern Gallagher card operates at 13.56 MHz over the ISO/IEC 14443-A air interface — the high-frequency band used by current contactless smart cards. Older Gallagher/Cardax IV credentials operate at 125 kHz, and many buildings run both during a migration, which is why Gallagher offers readers that handle each band.
The 13.56 MHz Gallagher credential is an AES-secured smart card. Gallagher states that its smart-card platform "represents the highest security available in access card technology currently" and is "more secure than 125kHz" and legacy contactless cards. When a card is encoded, "a site-specific application is stored securely on the tag, meaning the tag can only be used on the site it was encoded for."
How secure is a Gallagher card, and what is a "site key"?
A Gallagher card's real security comes from a site-specific AES key, not just the chip. Gallagher's long-standing hardening guidance is that each installation should be configured with its own unique, non-default encryption key. Independent research documents how this works: the per-card keys are generated by diversifying the site's master key, so every card carries a different key and recovering data from one card does not expose the rest of the system.
This is why Gallagher can say the credential has "multiple layers of security [that] prevent tag cloning." The card and reader perform a mutual-authentication exchange, and only a reader that holds the same site key can complete it. A card encoded for one site simply will not authenticate on another.
Can a Gallagher (Cardax) card be cloned or copied?
A correctly configured Gallagher card — one using a non-default, site-specific key — cannot be cloned by a third party, because a clone would need a secret AES key it can never read. The important qualifier is the word "configured."
On 22 December 2020, Gallagher published a security statement about the default Gallagher smart-card keys, noting that cards left on default keys "could be cloned or emulated." Its key line: "Customers who have followed Gallagher's long-standing hardening guide, which recommends the use of site-specific keys, are not affected by this disclosure." The practical takeaway is that clone-resistance depends on whether your site rotated off the default keys, which is a configuration and key-management task rather than a property of the plastic card.
Gallagher T-Series readers: single-tech vs Multi Tech
Gallagher's T-Series is the reader family (T10, T11, T12, T15, T20, T30, plus High Sec variants), and each model ships in two relevant flavours. Choosing the right one determines whether a site can read its legacy 125 kHz Cardax IV cards while it migrates to AES-secured smart cards.
| Gallagher credential layer | Band | Security | Third-party compatible card? |
|---|---|---|---|
| Cardax IV proximity (legacy) | 125 kHz LF | Fixed number, cipher-obfuscated, no live crypto | Yes — supplied as an open prox format |
| Gallagher smart card, default keys | 13.56 MHz HF | 128-bit AES but clonable if left on default keys (2020 advisory) | No |
| Gallagher smart card, site-specific key | 13.56 MHz HF | 128-bit AES, per-card diversified keys, clone-resistant | No — issued via Gallagher |
| Gallagher Mobile Connect | Bluetooth / NFC | Encrypted mobile credential, device biometrics | No — provisioned in-app |
Can I change my Gallagher keys without re-issuing every card?
Yes. Sites that discover they are still on default or shared keys do not necessarily have to re-badge everyone. Gallagher's credential documentation states that Command Centre v8.30 lets sites change the secret keys on their AES-secured 13.56 MHz smart-card credentials "without the need to re-issue or re-encode cards."
That capability matters because the 2020 default-key advisory is only a real exposure for sites that never moved to a site-specific key. If your Gallagher system is on an older Command Centre version or has never had its keys rotated, the correct next step is a conversation with your Gallagher integrator about key migration — not a third-party card. Security ID Systems does not supply site-keyed Gallagher smart cards.
Can I buy a compatible Gallagher card from a third party?
For a site-keyed Gallagher smart card, no — and that is by design. The credential is cryptographically bound to a site key held by the customer and Gallagher, so no independent manufacturer can produce a working "compatible" AES-secured Gallagher card, and Security ID Systems does not offer one. Additional secure credentials come from Gallagher or your integrator.
Where we can help is the other end of the same migration. Many Gallagher sites still run the legacy 125 kHz Cardax IV proximity layer on some doors, gates, or older readers. That open proximity format we encode as a fully compatible credential, alongside the general 125 kHz prox formats a mixed site tends to carry.
Compatible formats we do supply
If your Gallagher site still runs 125 kHz proximity anywhere during a migration to AES-secured smart cards, these open formats are ones we encode as fully compatible credentials that read identically on your existing readers.
Sources & references
- Gallagher SMB — credentials and site-specific encoding ("highest security available", "more secure than 125kHz")
- Gallagher Security — statement on disclosed default-key vulnerability (22 Dec 2020)
- Gallagher — Credential Solutions datasheet (Command Centre v8.30 key change)
- Gallagher — T-Series readers and terminals
- Gallagher — Mobile Connect (encrypted mobile credentials)
Gallagher and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.