Indala 125 kHz Technology explainer

Indala® ASP / FlexSecur

Indala's site-key-encrypted 125 kHz tier — a facility guide to why FlexSecur credentials are site-paired and un-reproducible, and where the open Indala formats we supply differ.

Can you buy third-party Indala ASP / FlexSecur cards?

Indala ASP / FlexSecur is the encrypted tier of the Indala 125 kHz platform: the credential payload is encrypted with a site-specific key before programming, and only matched ASP+ readers can decrypt it — so a FlexSecur credential is site-paired and can only be ordered through HID with your site's key. The open, non-FlexSecur Indala formats (FlexPass, 27-bit) are what American Key Cards supplies.

125 kHz
Frequency
125 kHz prox with FlexSecur site-specific encryption (PSK air interface)
Technology
1
Bit format
2+
OEM part nos.
Brand channel
Order from

FlexSecur is the exception in the Indala family: where standard Indala FlexPass and 27-bit are open formats we supply, FlexSecur adds a site-specific encryption layer that makes credentials un-reproducible by anyone without the site key. This page explains how FlexSecur works, why it's ordered through HID, and how it differs from the open Indala formats we do supply.

What FlexSecur adds to Indala

Standard Indala credentials — FlexPass 26-bit, Indala 27-bit — carry their data in the open, which is why we can supply compatible versions of them. FlexSecur changes that fundamentally: before a card is programmed, its entire data payload is encrypted with a key unique to your site, and only a FlexSecur-configured ASP+ reader holding the matching key can decrypt it and pass the credential to the panel.

The consequence is strict site pairing. A FlexSecur card from one building will not work at another FlexSecur building even if the facility code and card number are identical, because the encryption key differs. That's the entire security proposition — the credential is meaningless without its site's key.

Why FlexSecur can't be third-party supplied

Because the site key is required to produce a credential that a given ASP+ reader will decrypt, and that key lives within HID's controlled process for your site, no outside supplier can manufacture a working FlexSecur credential. This isn't a limitation we work around — it's the point of the format, and we're explicit that FlexSecur credentials come through HID with your site's FlexSecur configuration.

Standard Indala readers won't even read FlexSecur cards; the format requires the matched ASP+ readers. So a FlexSecur deployment is a closed loop by design: site-keyed cards, site-keyed readers, HID-controlled provisioning.

The open Indala formats we do supply

If your Indala system is not FlexSecur — that is, it runs standard FlexPass 26-bit or Indala 27-bit — those are open formats, and we supply compatible credentials for them directly, programmed to your facility code and card-number range. See our Indala FlexPass 26-bit and Indala 27-bit pages for those.

The practical first step is determining which you have. FlexSecur requires ASP+ readers; standard FlexPass runs on the ordinary Indala 603/610 reader family. Your reader models tell the story, and a photo of a working card plus your reader lets us confirm whether you're in the open-format world we supply or the FlexSecur world that goes through HID.

Indala ASP / FlexSecur specifications

System brand
HID Global (Indala line)
Technology
125 kHz proximity with FlexSecur site-specific encryption (PSK air interface)
Frequency
125 kHz
Credential platform
Indala-family 125 kHz transponder with FlexSecur site-specific encryption applied before programming; readable only by matched FlexSecur-configured ASP+ readers
Bit formats
FlexSecur site-key-encrypted payload (site-paired; a card from one FlexSecur site will not work at another even with identical numbering)
OEM part numbers
FPCRD / FPISO (FlexSecur variants, ordered with the FlexSecur option through HID), Indala ASP+ reader series

Specifications reviewed August 2026

How to order Indala ASP / FlexSecur credentials

FlexSecur encrypts the credential payload with a site-specific key before programming, and only the matched ASP+ readers can decrypt it, so credentials must be ordered through HID with your site's FlexSecur key — an outside supplier cannot reproduce a site-keyed FlexSecur credential. For the open, non-FlexSecur Indala formats, see the standard Indala FlexPass and Indala 27-bit pages, which we do supply.

Editorial reference page. American Key Cards is an independent credential supplier and is not affiliated with, endorsed by, or sponsored by Indala. We do not sell Indala's secured credentials; brand and product names appear only to identify the technology discussed, and all trademarks remain the property of their respective owners.

Readers in this ecosystem

HID Indala ASP+ readers (FlexSecur-configured only)HID Indala 610 ASP mid-range readerStandard Indala readers will not read FlexSecur-encrypted credentials

Indala ASP / FlexSecur — FAQ

Can a FlexSecur credential be supplied by a third party?

No. FlexSecur encrypts the credential payload with a site-specific key before programming, and only matched ASP+ readers holding that key can decrypt it. Without the site key — which lives in HID's controlled process — no outside supplier can produce a working FlexSecur credential.

Will a standard Indala card work in a FlexSecur reader?

No — FlexSecur ASP+ readers require the site-key-encrypted credential and won't accept a standard open Indala card. Conversely, standard Indala readers won't read FlexSecur cards. The two are deliberately incompatible tiers.

How do I know if my Indala system is FlexSecur or standard?

Check your readers: FlexSecur requires Indala ASP+ readers, while standard FlexPass runs on the ordinary Indala 603/610 family. Send us your reader model and a photo of a working card and we'll confirm which tier you're on.

What Indala credentials can American Key Cards supply?

The open Indala formats — standard FlexPass 26-bit and Indala 27-bit — which we program to your facility code and card-number range. FlexSecur is the encrypted, site-keyed exception that comes through HID; we'll point you there if that's what your ASP+ readers require.