Skip to main content

Frequently asked questions

Direct answers, no marketing. If yours is missing, ask us directly.

What is a PUF (physically unclonable function)?

A PUF is a physical structure whose fine details arise from uncontrollable randomness during manufacturing, so it cannot be reproduced — not even by the original manufacturer. On a TrustMarx label, this random micro-texture acts as the product's physical fingerprint: a photocopy reproduces the printed data but never the structure.

How is this different from a QR code?

A QR code is data, and data can be copied perfectly — a photocopied QR code scans identically to the original. TrustMarx pairs the code with a physical micro-structure that cannot be copied and a cryptographic signature that cannot be forged, so a copied label fails verification.

Does the consumer need to install an app or create an account?

No account is ever required, and verification runs as a lightweight web app (PWA) — the consumer points their phone camera at the label and gets a verdict in seconds.

What happens when a scan can't decide?

The system returns an explicit 'undetermined' outcome and asks for a rescan under better conditions. It never silently guesses: every scan ends in one of four explicit states — original, suspected copy, counterfeit, or undetermined.

Can a counterfeiter who knows exactly how the system works beat it?

Knowing the design does not help. Forging an identity requires a private key that is generated and used only inside an HSM and cannot be exported. Copying a label requires reproducing random physical micro-structure, which is infeasible by construction. And large-scale abuse patterns are caught server-side by scan intelligence.

What is the weakest link, honestly?

The enrollment station — the point where identities are created. An attacker controlling a legitimate station could enroll products that verify as genuine. That is why stations use hardware-bound authentication, tamper-evident audit logs, bounded batch volumes and anomaly review. We document this openly in our security model.

Does verification collect personal data from consumers?

No. Verification needs no account and no personal identifiers. Coarse geo signals are used in aggregate for anomaly detection, in line with GDPR and KVKK. Raw IP addresses are not stored for language detection on this site either.

How does this integrate with our production line?

Enrollment stations connect to existing lines through a documented API, and ERP/commissioning connectors map batches, SKUs and channels. Typical pilots start on one line with one SKU family and scale from there.

Does it work offline?

The verdict is always computed server-side — physical fingerprint matching requires the enrolled template, which never leaves the server. The scan itself needs a normal mobile data connection; no special hardware is involved.

How fast is a verification?

The target end-to-end experience is under five seconds from scan to verdict, including signature verification, physical matching and anomaly evaluation.