Skip to content
VeriV.

How a batch proves itself

VeriV turns a physical batch of material into something a stranger can check. This page explains how, in plain language — what a signed record actually is, why the tag cannot be copied, and who is accountable at each step. No engineering background needed.

What a signed record is

A signed record is a piece of information — an assay result, a custody handover, a shipping manifest — with a mathematical seal attached to it.

The seal is called a digital signature (in VeriV's case, ECDSA-P256, a widely used and well-studied signature method). It works like a wax seal on a letter, with two useful differences: it identifies exactly who applied it, and it breaks visibly if even one character of the record changes.

Anyone can check the seal. Checking does not require access to VeriV's systems, permission from us, or trust in us. That is the whole point: your customer verifies the record, not our promise about the record.

VeriV signs its records to ISO/IEC 20248:2022 — an international standard for signed data on physical items, such as tags and barcodes. VeriV's records are conformant with that standard and have been independently reviewed. There is no certification scheme for ISO/IEC 20248, so nobody can honestly claim to be "certified" against it; what matters is conformance you can inspect. The platform was built from co-research and testing with a co-author of the standard, ongoing since 2017.

Sample record
Batch
TH-VN-2568-014
Purity
V₂O₅ 99.4%
Signer
P-gate · named
DigSig

Signature verifies

Record unaltered since signing

ECDSA-P256 · ISO/IEC 20248

The chip

Each batch carries an NFC tag built around the NXP NTAG 424 DNA — a secure chip that follows ISO/IEC 14443-A, the same contactless standard used by transit cards and payment cards. It has a small cryptographic processor built into it, running AES-128 encryption. That processor holds a secret key that never leaves the chip.

Tap the tag with a phone and the chip generates a SUN message — a Secure Unique NFC code. Two things make it useful:

  • It is different every single time.

    The chip includes an internal tap counter and encrypts it, so no two taps ever produce the same code.

  • It is one-time.

    Once a code has been presented, presenting it again is a red flag rather than a success.

This is why a copied QR code does not work here. A QR code is a picture: photograph it, reprint it, and the copy scans identically to the original. A SUN code is generated fresh by a chip that holds a secret. You cannot photograph a secret, and a printed copy of one tap's code is dead on arrival the second time it is used.

Reading a tag needs nothing special — any modern smartphone with built-in NFC will do it, with no app installed.

The four security gates

Every tap passes through four independent checks. Any one of them can stop a batch.

The cryptographic gate — is this a real tag?

The code from the tag is decrypted using the AES-128 key on file for that tag. A genuine chip produces a code that decrypts cleanly. Anything else — a guess, a replay, a fake tag — fails immediately and the batch is flagged on the spot.

The counter rule — is this tap newer than the last one?

The chip counts its own taps. VeriV accepts a scan only if its counter is higher than the last one recorded, up to a sensible jump limit. This tolerates real-world conditions: a tag scanned several times in a warehouse with no signal will still verify when connectivity returns, because the counter only ever moves forward.

The single-use trap — has this exact code been seen before?

If the same code and counter combination turns up twice, that is the signature of a cloned tag: someone captured one tap and is replaying it. VeriV locks the batch rather than quietly accepting the second scan.

Impossible travel — could the material actually be where it was scanned?

Each scan's location is compared against the logistics manifest. A batch that was scanned in one port and then, an hour later, on another continent has not travelled — it has been duplicated. The mismatch is raised for investigation.

The pipeline, and who signs it

Material moves through defined stages. Each stage produces signed records, and each gate is signed by a named human being who is accountable for that decision.

The stages run from batch initiation (the batch is created and given its unique identity), through source assay, processing, final purity certification (a Certificate of Analysis issued against the same batch identity), and logistics (waybill, NFC seal and transit records captured as the batch travels), to an end-of-life audit. That final stage closes the loop: recovery becomes new circular feedstock, and the next batch begins where the last one ended.

Along the way, AI assists analysis — for example, comparing a submission against a baseline and surfacing differences worth a second look. It is assistive only: it produces analysis, never approvals.

The division of labour is deliberate and never blurred. AI assists analysis. Humans sign. Every gate carries a name, and that name stays attached to the record permanently.

The append-only ledger and the dispute clock

VeriV's records live in an append-only ledger — new entries are added, and nothing is ever overwritten or deleted. Hardware keys, assay records and custody history all accumulate. If something changes, you see the correction and the original, in order.

That raises a fair question: what if a record is wrong?

Any record can be formally disputed within a defined window of being entered. The window counts working days against the local holiday calendar. Extensions are possible but bounded, so a dispute cannot be stalled indefinitely. And where a conflict of interest exists — the party raising the dispute is the same party that signed the record — the dispute goes straight to independent arbitration rather than back to the person who created it. The exact parameters are agreed with each deployment.

Corrections are handled openly. Errors get fixed; history does not get rewritten.

What happens when a check fails

A failure is not a silent decline.

  • The person tapping sees an unambiguous result — not a vague error, but a statement that this batch did not verify and why the check stopped.

  • The event is written to the ledger, with the time and the location of the scan.

  • Depending on which gate failed, the batch may be flagged for review or locked outright. A repeated code — the clone signature — locks it.

  • The counterparty is notified, and the record can be disputed under the same formal dispute process.

A failed check does not mean the material is worthless. It means the chain of evidence has a break in it, and the break is now visible to everyone who needs to see it — which is exactly what an unverifiable supply chain never gave you.

See it against a real record

The fastest way to understand a signed record is to check one yourself.

Try the verification demo