Why authenticity has been unprovable until now
Counterfeiting is fundamentally an information problem. A product's value depends on claims — where it was made, what is inside it, who handled it, whether it has been opened — and the person holding the product has historically had no way to check any of them. Every traditional control tries to close that gap by adding a marker to the packaging: a hologram, a printed code, a serial number, a tamper strip, a certificate.
They all share one failure mode. Each protects a representation of the product rather than the product itself, and a representation can be copied onto a counterfeit unit at a cost far below the value of the fake. A printed QR code is the clearest example: anyone with a camera can duplicate it perfectly, so it can carry information but can never prove authenticity.
Per-item cryptographic identity
DPT™ starts by giving each unit an identity that cannot be copied. A secure NFC chip in the seal holds a key that never leaves the chip, and on every tap it generates a fresh, single-use cryptographic response. Cerfinity checks that response against the item's record: a genuine chip produces a valid response that has never been used before, while a photographed, printed, or replayed tag fails immediately.
Verification requires no app. The customer taps with a standard smartphone and gets a plain-language result — genuine or not, opened or sealed, and where the item has been. Where NFC is impractical, Cerfinity layers covert micro-mark authentication and QR verification as second and third tiers, but the tap remains the flagship because it is the only tier that is inherently uncopyable.
Tamper-evident physical binding and first-opening detection
An identity is only useful if it is attached to the product in a way that cannot be transferred. Cerfinity seals span the closure — a bottle neck, a carton flap, a slab seam, a jar lid — so opening the package physically breaks the seal's circuit and changes its electrical signature permanently. That change is recorded in the provenance ledger.
This produces first-opening detection: the ability to tell a buyer whether they are the first person to open this specific unit. For spirits, pharmaceuticals, cosmetics, specialty food, and graded collectibles, that is frequently more valuable than authenticity alone, because refilling and repackaging genuine containers is the dominant attack.
Chain of custody as an append-only record
Chain of custody is the unbroken, ordered record of who handled a product and when. Cerfinity captures a signed entry at each authorised checkpoint — producer, distributor, logistics partner, retailer, and in secondary markets the auction house or marketplace — and appends it to that specific item's record. Because the record is append-only and time-stamped, missing or out-of-sequence entries are visible rather than silently overwritten. Brands get a forensic view of where diversion and fakes concentrate; consumers get a readable summary of the item's journey.
Compliance: Digital Product Passport, EUDR, FSMA 204
The EU Digital Product Passport requires many goods to carry a machine-readable data carrier linked to structured lifecycle information. EUDR requires geolocated deforestation due diligence, and FSMA Rule 204 requires food traceability records within tight time limits. All three need the same underlying capability: a persistent, queryable record attached to a specific unit. Brands that deploy DPT™ for authenticity already have that record, and map their regulatory attributes onto it rather than running a second programme.