High-security 13.56 MHz access credential

Gallagher (Cardax) Cards Explained: Security, Site Keys & Options

A Gallagher (formerly Cardax) access card is an AES-secured 13.56 MHz contactless smart card that stores a site-specific application protected by 128-bit AES encryption. Because a correctly configured Gallagher card is bound to a non-default site key held by the customer, it cannot be cloned by a third party and is issued through Gallagher and its channel.

Last updated 2026-07-29

What is a Gallagher (Cardax) access credential?

Gallagher is a New Zealand access-control manufacturer whose card technology traces back to the Cardax brand, and many sites still call the credentials "Cardax" cards. A modern Gallagher credential is an AES-secured 13.56 MHz contactless smart card that carries a Gallagher-specific application, and it is read by Gallagher's T-Series readers into a Command Centre management system.

Gallagher describes this credential as offering "secure 128-bit AES encryption," with "card data … encrypted using 128-bit AES with an additional layer of security." That is a fundamentally different model from the 125 kHz Cardax IV proximity cards it replaces, whose identity number is broadcast in the clear. The Gallagher smart card proves its identity cryptographically before any data is exchanged.

What frequency and technology does a Gallagher card use?

A modern Gallagher card operates at 13.56 MHz over the ISO/IEC 14443-A air interface — the high-frequency band used by current contactless smart cards. Older Gallagher/Cardax IV credentials operate at 125 kHz, and many buildings run both during a migration, which is why Gallagher offers readers that handle each band.

The 13.56 MHz Gallagher credential is an AES-secured smart card. Gallagher states that its smart-card platform "represents the highest security available in access card technology currently" and is "more secure than 125kHz" and legacy contactless cards. When a card is encoded, "a site-specific application is stored securely on the tag, meaning the tag can only be used on the site it was encoded for."

How secure is a Gallagher card, and what is a "site key"?

A Gallagher card's real security comes from a site-specific AES key, not just the chip. Gallagher's long-standing hardening guidance is that each installation should be configured with its own unique, non-default encryption key. Independent research documents how this works: the per-card keys are generated by diversifying the site's master key, so every card carries a different key and recovering data from one card does not expose the rest of the system.

This is why Gallagher can say the credential has "multiple layers of security [that] prevent tag cloning." The card and reader perform a mutual-authentication exchange, and only a reader that holds the same site key can complete it. A card encoded for one site simply will not authenticate on another.

Can a Gallagher (Cardax) card be cloned or copied?

A correctly configured Gallagher card — one using a non-default, site-specific key — cannot be cloned by a third party, because a clone would need a secret AES key it can never read. The important qualifier is the word "configured."

On 22 December 2020, Gallagher published a security statement about the default Gallagher smart-card keys, noting that cards left on default keys "could be cloned or emulated." Its key line: "Customers who have followed Gallagher's long-standing hardening guide, which recommends the use of site-specific keys, are not affected by this disclosure." The practical takeaway is that clone-resistance depends on whether your site rotated off the default keys, which is a configuration and key-management task rather than a property of the plastic card.

Gallagher T-Series readers: single-tech vs Multi Tech

Gallagher's T-Series is the reader family (T10, T11, T12, T15, T20, T30, plus High Sec variants), and each model ships in two relevant flavours. Choosing the right one determines whether a site can read its legacy 125 kHz Cardax IV cards while it migrates to AES-secured smart cards.

Gallagher credential layerBandSecurityThird-party compatible card?
Cardax IV proximity (legacy)125 kHz LFFixed number, cipher-obfuscated, no live cryptoYes — supplied as an open prox format
Gallagher smart card, default keys13.56 MHz HF128-bit AES but clonable if left on default keys (2020 advisory)No
Gallagher smart card, site-specific key13.56 MHz HF128-bit AES, per-card diversified keys, clone-resistantNo — issued via Gallagher
Gallagher Mobile ConnectBluetooth / NFCEncrypted mobile credential, device biometricsNo — provisioned in-app

Can I change my Gallagher keys without re-issuing every card?

Yes. Sites that discover they are still on default or shared keys do not necessarily have to re-badge everyone. Gallagher's credential documentation states that Command Centre v8.30 lets sites change the secret keys on their AES-secured 13.56 MHz smart-card credentials "without the need to re-issue or re-encode cards."

That capability matters because the 2020 default-key advisory is only a real exposure for sites that never moved to a site-specific key. If your Gallagher system is on an older Command Centre version or has never had its keys rotated, the correct next step is a conversation with your Gallagher integrator about key migration — not a third-party card. Security ID Systems does not supply site-keyed Gallagher smart cards.

Can I buy a compatible Gallagher card from a third party?

For a site-keyed Gallagher smart card, no — and that is by design. The credential is cryptographically bound to a site key held by the customer and Gallagher, so no independent manufacturer can produce a working "compatible" AES-secured Gallagher card, and Security ID Systems does not offer one. Additional secure credentials come from Gallagher or your integrator.

Where we can help is the other end of the same migration. Many Gallagher sites still run the legacy 125 kHz Cardax IV proximity layer on some doors, gates, or older readers. That open proximity format we encode as a fully compatible credential, alongside the general 125 kHz prox formats a mixed site tends to carry.

Compatible formats we do supply

If your Gallagher site still runs 125 kHz proximity anywhere during a migration to AES-secured smart cards, these open formats are ones we encode as fully compatible credentials that read identically on your existing readers.

Sources & references

Gallagher and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Gallagher / Cardax HF — common questions

Can a Gallagher (Cardax) card be cloned?

A Gallagher smart card configured with a non-default site-specific key cannot be cloned, because a clone would need a secret AES key it can never read. Gallagher's 22 December 2020 advisory confirmed that only cards left on default keys were exposed, and that customers who followed its site-specific-key hardening guide were not affected.

What is a Gallagher site key and why does it matter?

A Gallagher site key is a unique, non-default 128-bit AES key assigned to one installation. Per-card keys are diversified from it, so every card is different and a card encoded for one site will not work on another. Clone-resistance depends on the site using its own key rather than the factory default.

Do I have to re-issue all cards to fix default Gallagher keys?

Not necessarily. Gallagher states that Command Centre v8.30 lets a site change the secret keys on its smart-card credentials without re-issuing or re-encoding cards. Sites on older software should ask their Gallagher integrator about key migration.

Can I buy a compatible Gallagher smart card?

No. A site-keyed Gallagher smart card is cryptographically bound to keys held by the customer and Gallagher, so no third party can produce a compatible AES-secured version. Additional secure credentials come from Gallagher or your integrator. Only the legacy 125 kHz Cardax IV proximity layer can be supplied as a compatible card.

What is the difference between a Gallagher single-technology reader and a Multi Tech reader?

A Gallagher single-technology (13.56 MHz) T-Series reader reads the AES-secured smart card. A Multi Tech reader also reads legacy 125 kHz proximity such as Cardax IV, which lets a site run old and new credentials side by side during a phased migration.