Alert EnterpriseWiki

LEGIC Orbit

Key Materiallegic

LEGIC's HSM-backed key management service. Generates "never-visible" random keys inside LEGIC HSMs — the keys never leave the HSM in plaintext form. Recommended by LEGIC over customer-supplied master keys.

Combined with LEGIC's installed base of secure-module-based access reader/lock hardware, Orbit lets wallet-credential encryption keys reach access hardware without ever appearing in plaintext outside an HSM. Required for encryption key rotation: rotation is supported only when Orbit is the key management path.

Orbit is co-located with both LEGIC's Apple-side service (Apple Credential Provider & Orbit Service) and Google-side service (Google Access Hub & Orbit Service) — the same Orbit backend serves both wallet platforms. The keyset is configured once at project onboarding (step 2 of both the Apple and Google provisioning flows) and applies to all credentials issued under that project.

Architecturally distinct from Wavelynx and HID: LEGIC's mobile- credential encryption keys are INDEPENDENT of physical card encryption keys. Wavelynx and HID both diversify per-credential keys from a master that's also used for physical-card encryption; LEGIC isolates the wallet key from the physical card key entirely.

What other systems call it

Per-vendor / per-standard terminology for this same concept.

SystemTerm / Notes
AlertEnterpriseAlertEnterpriseLEGIC Orbit
Source
  • src/LEGIC/email-john-harvey-2026-05-13.md Q2, Q4 — Orbit recommended path, key rotation
Verifying access
Desktop only

The AE Mobile Wiki needs a bigger screen.

The diagrams, comparisons, and animated flows aren't built for phones. Open this link on your laptop or desktop browser and you'll see the full reference.

wiki.alertenterprise.app

Same Google sign-in as the AE App Hub — you'll be in once you open it on a larger screen.