> For the complete documentation index, see [llms.txt](https://docs.optivalux.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.optivalux.com/product/authenticity-evidence.md).

# Authenticity Evidence

**Evidence, not guarantees.**

Optivalux does not declare products "authentic". It reports **what was checked and when**: whether the product's registered authenticator answered with fresh cryptographic evidence that matches the registered identity, and what the brand's certificate says about that product.

## The secure authenticator

Each registered product carries a **secure authenticator**: a small secure element placed in the product by the brand. It holds cryptographic keys that cannot be read out of the chip, and it produces fresh evidence each time it is checked.

The authenticator does not store the owner's identity. It identifies the product's registered authenticator, nothing more.

## Physical verification

To verify a product, a person holds their phone near the authenticator. The verification result states:

* whether the registered authenticator answered with **fresh, valid evidence**;
* whether that evidence **matches the registered identity** of the product;
* the **certificate standing** (Active, Suspended or Voided, with a reason where the brand provides one);
* **when** the check happened.

Freshness and replay checks limit reuse of previously seen evidence. Evidence that has already been used, or that is outside the accepted freshness state, is rejected.

### Verification results

| Result                                     | What it tells you                                                                                                                                            |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Authenticator verified**                 | The registered authenticator produced fresh, valid evidence that matches the registered identity. Certificate standing and ownership are shown alongside it. |
| **Does not match the registered identity** | The evidence did not match the product's registered identity.                                                                                                |
| **Couldn't read the authenticator**        | No usable evidence could be read from the authenticator.                                                                                                     |
| **Verification unavailable**               | Verification cannot be performed right now. This says nothing about the certificate's standing or ownership.                                                 |
| **QR opened this product record**          | The product's record was located from a QR code or link. **Nothing about the item in hand was verified.**                                                    |

A verified authenticator is never presented as a clean result on its own. If the certificate is **Suspended** or **Voided**, or the owner has reported the product lost or stolen, the result shows that alongside the verification, with the brand's reason where one is provided.

The protocol also recognises lower-level conditions that are not separate public result labels: evidence that has already been used, an authenticator that was replaced and permanently retired (a signal of an old or copied tag), and an authenticator with no registered certificate. None of these verifies the product. See [Lifecycle & Status](/technical/lifecycle-and-status.md) for the technical detail.

The product record separately shows **authentication availability**: Verified, Verification required, Verification unavailable, Recovery available or Recovery pending. See [Product Identity](/product/product-identity.md).

## QR codes are locators only

A product may also carry a QR code or printed link. **A QR code only opens the product's record.** It can show the certificate standing and provenance, but it is never evidence that someone is holding the product: a QR code can be copied at no cost and placed on anything.

A QR scan therefore:

* never produces "Authenticator verified";
* never satisfies a claim, a transfer or a recovery step.

To verify the product itself, tap its secure authenticator.

## Two kinds of authenticator

Optivalux is hardware-neutral and supports two families of authenticator. They have different trust properties, and Optivalux discloses which one a product uses.

**Symmetric authenticators** (for example, secure NFC tags) produce a new, single-use cryptographic message on each tap. Checking that message requires a secret key, so it is checked by the **Optivalux verification service**, which holds the keys in secure hardware. This kind of check relies on that service. It works with an ordinary phone browser, without installing an app.

**Asymmetric authenticators** (secure elements with their own key pair) sign a fresh challenge with a private key that never leaves the chip. The signature can be checked directly against the authenticator's registered public key, without relying on a verification service for that check.

Neither is universally better. Symmetric authenticators are widely available and easy to use; asymmetric authenticators remove the verification-service dependency for the possession check but can need specific device or app support. See [Physical Authentication](/trust/physical-authentication.md).

## Authentication availability is not certificate standing

These are two different facts:

* **Authentication availability** is whether the authenticator can be checked right now. It can be temporarily unavailable, for example if a verification service is offline or the authenticator is damaged.
* **Certificate standing** is the brand's statement about the certificate: Active, Suspended or Voided.

If verification is unavailable, the certificate is **not** invalid, and ownership is unaffected. Conversely, a successful verification does not change a suspended certificate back to active.

## What evidence does and does not show

A successful verification shows that the registered authenticator answered correctly and recently. It does **not** by itself show that the object the authenticator is attached to is the original product: an authenticator could be removed and attached to something else, or its responses relayed from elsewhere. Physical measures (tamper-evident placement, embedding) and monitoring reduce these risks; they are disclosed in [Claims & Limitations](/trust/claims-and-limitations.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.optivalux.com/product/authenticity-evidence.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
