> For the complete documentation index, see [llms.txt](https://docs.optivalux.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.optivalux.com/for-partners/manufacturers-and-hardware.md).

# Manufacturers & Hardware

The physical authenticator is where a product's digital identity meets the object itself. Manufacturers and secure-hardware companies determine how well that connection holds up in the real world.

This page describes roles and requirements. It does not describe existing partnerships.

## Manufacturers

A manufacturer can:

* **place authenticators** in products during production or finishing;
* **register products at source**, acting as an operator for the brand.

Registration is designed for the factory floor with limited trust:

* Each registration requires **fresh evidence from the authenticator being registered**, bound to that specific registration. An identifier alone is never accepted.
* Registration happens within batches whose **size limits are set by the brand**, not by the operator.
* An authenticator can be registered **only once**, to one product.
* Operators **cannot** suspend, void, change ownership, authorize claims or replace authenticators.

A compromised operator station can therefore at most register products within the brand's batch limits. This is a disclosed residual risk: a genuine authenticator attached to a non-original item within those limits cannot be detected cryptographically, which is why placement and process controls matter.

## Secure hardware

Optivalux is **hardware-neutral**. The protocol works with any authenticator that fits one of two families:

|                             | Symmetric authenticators                                                       | Asymmetric authenticators                                             |
| --------------------------- | ------------------------------------------------------------------------------ | --------------------------------------------------------------------- |
| **Examples**                | Secure NFC tags that produce a new cryptographic message per tap               | Secure elements that hold their own key pair                          |
| **How evidence is checked** | By the Optivalux verification service, which holds the keys in secure hardware | Directly, against the authenticator's registered public key           |
| **Phone support**           | Works in an ordinary phone browser, no app required                            | Depends on vendor tooling; may need an app or specific device support |
| **Typical fit**             | Broad product ranges; cost-sensitive categories                                | High-value categories where the unit cost is justified                |

More than one family can be used side by side, and hardware generations can change without changing existing certificates.

### Recovery Authenticator

For the pilot profile, each product also carries a **Recovery Authenticator**: an asymmetric authenticator whose evidence can be checked without the brand or a verification service. It must be physically distinct from the primary authenticator, so that a single component failure does not disable both. The protocol does not prescribe the packaging; this is a design question for each category.

### Placement and physical protection

Cryptography protects the authenticator's evidence. It cannot by itself protect the link between the authenticator and the object. Two physical risks matter:

* **Transplant**: a real authenticator removed from an original product and attached to another item.
* **Relay**: responses from a real authenticator, held elsewhere, forwarded to a phone near a different item.

Mitigations are physical and operational: embedded placement, tamper-evident or destructive-on-removal inlays (including variants that report a broken seal, relevant for sealed goods), and monitoring for unusual verification patterns. Hardware partners play a central role in getting this right for each category.

## Key custody (symmetric authenticators)

Symmetric authenticators rely on secret keys that must never appear in product software, public records or logs. They are held only in secure hardware operated by the verification service. The key-custody model (including per-brand key separation) must be established before real authenticators are registered for a pilot. It is not yet finalised.

## Get involved

Hardware and manufacturing conversations go through **Infrastructure partnership** on [Contact & Partnerships](/company/contact-and-partnerships.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.optivalux.com/for-partners/manufacturers-and-hardware.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
