Allegion AES-secured smart credentials

Schlage aptiQ & NDE/LE Cards Explained: Security & Compatibility

Schlage aptiQ is Allegion's family of AES-secured 13.56 MHz contactless smart credentials, used on Schlage NDE and LE wireless locks and aptiQ multi-technology readers. aptiQ credentials use AES-128 for authenticity, confidentiality and integrity, and can be configured with customer-owned custom keys through the Schlage Custom Encryption Key Service (SCEKS).

Last updated 2026-07-29

What is Schlage aptiQ?

Schlage aptiQ is Allegion's brand for 13.56 MHz contactless smart credentials — the secure card technology that replaced 125 kHz proximity and magnetic-stripe cards across the Schlage line. An aptiQ credential is an AES-secured smart card, meaning the card and reader authenticate cryptographically rather than the card simply broadcasting a fixed number. Allegion's own credential documentation describes its high-security smart cards as using "128 AES encryption used for authenticity, confidentiality and integrity," and states that Allegion is standardizing on the current smart-card generation.

aptiQ is offered across a range of secure 13.56 MHz smart-card types, from earlier smart cards through the current high-security generation. The security-relevant point for a buyer is the family it belongs to: aptiQ is an encrypted smart credential, not a copyable proximity card, and that changes how additional cards are sourced.

What are Schlage NDE and LE locks, and how do they use aptiQ?

Schlage NDE and LE are Allegion's wireless electronic locks, managed through the ENGAGE platform. They read aptiQ 13.56 MHz smart credentials at the door — as well as mobile credentials — so the same secure card can work on wired aptiQ readers and on wireless NDE/LE openings across a building. This is what lets an organisation extend electronic access to interior and remote doors without running wiring to each one.

Because NDE and LE are credential-agnostic within the aptiQ family, the security of the door comes from the credential and key configuration, not the lock hardware alone. A site standardising on aptiQ smart cards and, where wanted, Schlage Mobile credentials via ENGAGE can cover openings from main entrances to individual offices on one credential model.

How secure are aptiQ credentials?

Schlage aptiQ high-security credentials are secured with AES-128, which Allegion's documentation says is "used for authenticity, confidentiality and integrity." In practice that means the card proves it is genuine (authenticity), its data is encrypted over the air (confidentiality), and it cannot be silently altered (integrity) — the three properties a copyable proximity card lacks entirely. Allegion describes this generation as offering the highest tier of its card security and is standardising on it.

That AES-secured model is why an aptiQ smart card is not clonable the way a 125 kHz proximity card is: there is no fixed number to copy, and the reader exchange is cryptographically authenticated. As with any smart-card system, the real-world strength also depends on key management — which is where Allegion's custom-key service comes in.

What is SCEKS (custom encryption keys)?

The Schlage Custom Encryption Key Service (SCEKS) lets an organisation use its own custom encryption keys on aptiQ credentials instead of the default key. Allegion states that its smart credentials can be "configured with our default encryption key or with a custom key developed by SCEKS." A custom key means a card encoded for one organisation will not authenticate on another organisation's readers, even if both use aptiQ.

This matters because a default shared key is the single biggest weakness in any smart-card deployment — it is what makes cards interchangeable between sites. Moving to SCEKS custom keys is the step that turns aptiQ from "secure chip, shared key" into a credential genuinely bound to your installation. It also means additional cards must be encoded with your key, which is why they come through Allegion or your integrator rather than an open aftermarket.

How do I migrate from 125 kHz prox to aptiQ?

Allegion designed aptiQ multi-technology readers specifically to bridge the move from 125 kHz proximity to secure 13.56 MHz smart cards. Its reader documentation describes them as a way to "transition your system from proximity to smart card technology at your own pace," reading "125kHz proximity and 13.56MHz contactless smart cards in a single unit." That lets a site keep existing prox cards working while it issues aptiQ smart cards.

CredentialFrequencySecurityThird-party compatible?
Legacy 125 kHz proximity125 kHz LFFixed number, no encryptionYes — openly supplied
aptiQ smart card (default key)13.56 MHz HFAES-128, shared default keyLimited — via Allegion
aptiQ smart card (SCEKS key)13.56 MHz HFAES-128, custom site keyNo — via Allegion / integrator

Which compatible cards we supply for aptiQ sites

Custom-keyed aptiQ smart cards are bound to your SCEKS key and come through Allegion or your integrator — Security ID Systems does not produce a compatible aptiQ smart card, and that is inherent to how the encryption works. Where we help is the 125 kHz proximity side of a migration, which is an open technology.

aptiQ multi-technology readers accept 125 kHz proximity from the common families — Schlage, XceedID, HID, and AWID — during a transition. Those open proximity formats we encode as fully compatible credentials that read identically on your existing readers, covering the doors still on prox while your secure aptiQ rollout finishes.

Compatible formats we do supply

Custom-keyed aptiQ smart cards come from Allegion — but the 125 kHz proximity formats an aptiQ multi-technology reader accepts during migration are ones we encode as fully compatible credentials.

Sources & references

Allegion and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Schlage aptiQ (Allegion) — common questions

What is Schlage aptiQ?

Schlage aptiQ is Allegion's family of AES-secured 13.56 MHz contactless smart credentials, used on Schlage readers and NDE/LE wireless locks. Unlike a 125 kHz proximity card, an aptiQ credential authenticates cryptographically with AES-128 rather than broadcasting a fixed number, which is why it is not clonable the way a proximity card is.

Do Schlage NDE and LE locks use aptiQ smart cards?

Yes. Schlage NDE and LE wireless locks, managed through the ENGAGE platform, read aptiQ 13.56 MHz smart credentials as well as mobile credentials. The same secure aptiQ card can work on wired aptiQ readers and on wireless NDE/LE openings across a building.

Are aptiQ credentials secure or can they be cloned?

aptiQ high-security credentials use AES-128 for authenticity, confidentiality and integrity, so there is no fixed number to copy and the reader exchange is cryptographically authenticated. With custom SCEKS keys, a card is bound to your site and cannot be cloned the way an unencrypted 125 kHz proximity card can.

What is SCEKS?

SCEKS is the Schlage Custom Encryption Key Service. It lets an organisation use its own custom encryption key on aptiQ credentials instead of the default key, so cards encoded for one site will not authenticate at another. Moving to SCEKS custom keys is the step that binds aptiQ credentials to your specific installation.

Can I switch from prox to aptiQ without replacing everything?

Yes. Allegion's aptiQ multi-technology readers read 125 kHz proximity and 13.56 MHz smart cards in one unit, so a site can install them, keep existing prox cards working, and issue aptiQ smart cards over time. Dual-technology cards can also bridge the two during rollout.