Skip to main content

How TrustMarx works

From the production line to the consumer's phone: a complete verification flow in four stages, with a server-side verdict in seconds.

TrustMarx verifies a product by checking three independent things in one scan: a cryptographic signature that cannot be forged, a physical micro-structure that cannot be copied, and a scan pattern that cannot hide abuse.

  1. 1. Enroll
  2. 2. Label
  3. 3. Scan
  4. 4. Verdict
The verification flow: enrollment pairs a digital and physical identity; the scan brings both back to the server for a verdict.

1. Enrollment at the production line

As products come off the line, an enrollment station generates a high-entropy token for each unit and signs it inside a hardware security module. In the same pass, a camera captures the label's random micro-texture — the physically unclonable function — and registers its template with the server. The product now has a paired digital and physical identity.

The enrollment station is the most security-critical link in the chain — see our security model for how it is protected.

2. The label

The label carries two things: a scannable code holding the signed token, and the micro-structure that formed randomly during printing. The code can be photographed and reprinted; the structure cannot. This asymmetry is the core of the design — everything a counterfeiter can copy is worthless without the part they cannot.

3. The consumer scan

A consumer opens the verification app — no account required — points the camera at the label, and the app reads the code and captures the micro-texture in a single step. The capture is sent to the server; nothing is decided on the phone, so there is nothing on the phone worth attacking.

4. The verdict

The server verifies the cryptographic signature, matches the captured texture against the enrolled template, and evaluates the scan in context: has this label been scanned before, where, how often, through which channel? The answer comes back in seconds as one of four explicit outcomes.

The four outcomes

Every scan resolves to exactly one of these states, communicated with color, icon and message — never color alone.

Original

This product's physical signature and cryptographic identity match. It is authentic.

Suspected copy

The code is valid, but the physical signature does not fully match. This label may have been copied.

Counterfeit

The identity could not be cryptographically verified. This product is not authentic.

Undetermined

The scan could not be completed reliably. Please rescan in better lighting conditions.