SealTrust links a physical product to a cryptographically verified record you can check yourself. Tap the NTAG 424 DNA chip with a phone, and its authenticity is confirmed against proof anchored on a public blockchain.
This page walks through it as one story, in five short chapters, each with a two-minute video and a plain-language explanation.
The app, filmed end to end. No voiceover, nothing staged.
A SealTrust-protected product carries an NTAG 424 DNA chip, a serialised QR code, or both. With the chip, tapping it with any NFC phone (no app required) sends a one-time cryptographic code that our service verifies in seconds.
A successful check means the carrier is genuine and the item matches its on-chain record: a tamper-resistant entry written to the Base blockchain when the product was first registered. Anyone can re-run the verification independently, at any time.
One tap turns a physical product into a record you can verify independently.
How SealTrust works: a two-minute overview
A convincing fake can copy a label, but copying the chip's cryptographic behaviour is far harder. SealTrust watches the pattern of scans to spot tags that don't add up.
When the same identity appears in two distant places at once, when a scan counter rolls backwards, or when a previous code is replayed, the system flags it and folds the signal into a live trust score, so suspicious activity surfaces instead of slipping through.
Cloned and replayed tags are detected automatically and scored into a live trust signal.
Clone detection: catching counterfeits
Authenticity is one half of the story; what a product is made of is the other. SealTrust gathers materials, suppliers, lifecycle events and compliance details into a Digital Product Passport aligned with the EU's ESPR regulation.
The passport travels with the item and is exportable as structured, interoperable data. Each audience reads what its trade requires, and nothing more: public data stays open to everyone, a repairer gets the bill of materials and repair information, a recycler the materials and substances of concern, manufacturing and supply-chain data stays with the brand, and only the market surveillance authority sees the whole record.
Materials, suppliers and compliance, gathered into an ESPR-aligned passport that travels with the product.
The Digital Product Passport, explained
The trust starts in the hardware. The NTAG 424 DNA chip leaves the factory with a public default key. At encoding time we write keys derived from a master key that is kept encrypted at rest, under a key held in AWS KMS, and is never stored in plaintext. Once written, they are never exposed and can no longer be read back off the chip.
On every tap, the chip generates a fresh, single-use code derived from those keys. A captured code can't be reused, and an attacker who can't recover the keys can't produce a valid one, which is what makes the chip clone-resistant rather than simply hard to copy.
Keys we write ourselves, never readable afterwards, and a fresh code on every tap make the chip clone-resistant.
NTAG 424 DNA security, explained
Issuing or retiring a product on-chain is a sensitive action. For these operations, SealTrust offers multi-signature governance through a Gnosis Safe, a multi-signature wallet that requires several approvals before anything executes.
Brands that set a threshold of two signers or more apply an M-of-N policy: a quorum of authorised signers has to sign, every signature is recorded against its signer, and execution only goes on-chain once the quorum is met. Inside that Safe, no single signature is enough on its own: the mint or burn it proposes stays pending until the quorum is reached.
Optional Gnosis Safe: a brand can place its critical on-chain actions behind a quorum of approvals. By default, minting and burning execute without a quorum.
Multi-signature governance, explained
SealTrust is built on open standards, not proprietary technology. Here, in five short videos, are the building blocks that make our passports verifiable by anyone, offline, with standard tools and no proprietary API.
A QR code or an NFC chip links every product to its data: authenticity, origin, materials, carbon footprint, repairability. The EU ESPR regulation will make it mandatory group by group, one delegated act per product group; the first firm date comes from another text, the EU Batteries Regulation (EU) 2023/1542: 18 February 2027 for batteries.
One signed passport, six reading profiles. The three trades are peers: the repairer does not see the recycler's materials, nor the reverse. Asking for a trade profile without signing in returns 401; signed in but without the matching accreditation, 403.
Three independent public proofs behind every passport: a SHA-256 fingerprint, an immutable copy on IPFS, a timestamped anchor on Base (Ethereum L2). No cryptocurrency, no speculative token: the chain carries the product's certificate, its owner and the timestamp of its proof.
Every passport is signed with did:web, an open W3C standard: the signature verifies offline, with any SD-JWT-VC library, without going through SealTrust's API. And a brand can publish its key on its own domain (did:web:its-brand.com): its proof of authenticity is its own, with no vendor lock-in.
The GS1 Digital Link turns the product identifier (GTIN and serial number) into a standard web address, readable by every system. A single QR leads to the right passport, with no proprietary format.
The fastest way to understand SealTrust is to use it. Verify a product, open a sample Digital Product Passport, or talk to us about your catalog.