Skip to content
zHezarFoundation / Public release

Foundation / Authenticity and Scan Tags

A scan opens the record. The server decides what is verified.

The zHezar scan tag is intended to use secure NFC technology to connect a physical product to its official Product Identity. A copied link, browser effect, visible code, or physical possession cannot replace a live server-validated interaction.

Reference only. No NFC scan, live verification, authenticity result, product record, Claim, Ownership, transfer, replacement, support case, or protected action exists here.

  1. 01Physical interactionSupported device near the zHezar scan tag
  2. 02Secure verification requestFresh scan context reaches the approved server boundary
  3. 03Authoritative resultPrivacy-safe Product Identity state—or no claim

Physical product / secure NFC / server authority

Current evidence

The local callable refuses to guess. Production verification is not configured.

Bounded input, privacy-safe logging, and a temporarily unverifiable result demonstrate fail-closed behavior. They do not show that a product is counterfeit.

Verified locally

Bounded request and explicit refusal.

  • Strict token-input shape and size validation
  • Nonidentifying fingerprint instead of raw input
  • Temporarily unavailable verification state
  • Temporarily unverifiable authenticity state
  • No client or callable success claim
Not production-ready

Cryptography, physical operations, and authoritative records.

  • Approved token vendor and configuration
  • Protected keys, provisioning, and UID binding
  • Dynamic verification and replay defense
  • Garment assignment, token lifecycle, and Product Identity
  • Monitoring, support, recovery, and validation

Five authority layers

One layer cannot impersonate the next.

The physical piece stays central. Its credential, live verification, permanent Product Identity, and current Ownership authority remain related but distinct.

01

Physical product

The garment and its approved physical configuration.

02

zHezar scan tag

A secure NFC credential associated through controlled production.

03

Server verification

The authoritative decision about the current live scan and token state.

04

Product Identity

The permanent official product, artist, Edition, configuration, and history.

05

Ownership

Separate canonical account authority created only through an approved process.

High-level verification flow

A valid result requires every step to agree.

This explanation stops before keys, values, counters, thresholds, provider configuration, and other sensitive implementation details.

  1. 01

    Physical scan

    A supported device interacts with the scan tag.

  2. 02

    Approved destination

    The request reaches the official verification boundary.

  3. 03

    Fresh secure data

    A live interaction is distinguishable from a copied static link.

  4. 04

    Server validation

    Approved cryptography, freshness, and token rules are checked.

  5. 05

    Authoritative state

    Product Identity, token, Claim, and Ownership states remain separate.

  6. 06

    Safe result

    Only approved public information and separately authorized next actions appear.

Six customer-safe states

A failed scan is not one universal conclusion.

Device behavior, connectivity, damage, unsupported technology, copied links, retired credentials, outages, malformed requests, and security failures require different language and recovery.

Future verified result

Valid live secure verification

The server recognizes an authentic registered token and may return safe Product Identity information.

Public viewing only

Valid public identifier without live scan

Public information may be readable, but it cannot prove current physical interaction or authorize a protected action.

No current claim

Verification unavailable

The service could not confirm authenticity now. Protected actions fail closed and static-link bypass is prohibited.

Historical authenticity preserved

Inactive, retired, replaced, or reissued

The current credential cannot authorize protected actions while approved identity and token history remain distinct.

Reviewed exception needed

Damaged or unreadable tag

The product may still be authentic. Evidence and any remedy require an approved protected process.

Safe technical distinction

Unsupported, unrecognized, or invalid

State what could not be verified without automatically publishing a counterfeit finding.

Information boundary

Useful public identity. Protected operational detail.

A public result should explain the official product and current safe state without exposing another person, weakening security, or turning telemetry into surveillance.

Potential public information

Approved product identity and history.

  • Authenticity result when server-confirmed
  • Artist, Artwork, Album, Drop, Product, and Edition
  • Public identity, token, Claim, and provenance state
  • Privacy-approved ownership information
  • Safe support guidance and eligible next step
Never ordinary public output

Secrets, private records, and security signals.

  • Keys, cryptographic values, raw identifiers, and counters
  • Owner identity, order, payment, address, or scan location
  • Fraud signals, scores, thresholds, and internal rules
  • Private support, replacement, inspection, and dispute evidence
  • Infrastructure, provider, and incident detail

Product Identity ≠ Ownership

Verification identifies the product. It does not decide every right to it.

Platform Ownership is created only by an authorized first Claim, completed approved transfer, or another approved ownership process. A public scan cannot perform those actions.

These facts do not independently create platform Ownership

  • Payment
  • Order creation
  • Shipping
  • Delivery
  • Physical possession
  • Public scan
  • Receipt
  • Static URL
  • Last-scanner or device identity
  • Support statement

Hardware and support

The product record should survive a credential problem.

A scan tag can be damaged, unreadable, inactive, retired, replaced, unsupported, or temporarily unreachable. Safe status and continuity must preserve history.

Damage

Unreadable does not mean counterfeit.

Approved review may distinguish the authentic product from current tag functionality.

Retirement

Inactive credentials keep their history.

Protected actions stop while the prior token remains connected to the official record.

Device

Unsupported hardware gets a clear limit.

Essential explanation and Help remain available without pretending every device scans identically.

Outage

No static-link success fallback.

Cached public information must be labelled unverified or previously known; protected actions remain blocked.

Public-promise limits

Secure NFC supports trust. It does not make risk disappear.

Public language must distinguish a strong system, one scan result, token functionality, platform Ownership, legal title, and financial value.

  1. 01

    Counterfeiting is impossible.

  2. 02

    NFC can never fail.

  3. 03

    Every device scans identically.

  4. 04

    A copied URL proves physical possession.

  5. 05

    Public verification establishes Ownership.

  6. 06

    A scan resolves every legal title dispute.

  7. 07

    A retired authentic token is counterfeit.

  8. 08

    The system guarantees resale value.

Readiness / July 2026

Represented honestly. No production-active classification.

This table records repository evidence and unresolved gates. It is not a verification service, registry, token inventory, ownership ledger, support system, or production dashboard.

AreaStateMeaning
Public Authenticity and Scan Tags referencePublic reference

Static education only; no scan, product result, or protected action.

Framework-neutral tag callableLocally verified fail-closed

Input is bounded and verification returns temporarily unavailable with no authenticity claim.

Token vendor, encoding, and key operationsOD-009 unresolved

Production token, configuration, keys, custody, reconciliation, and migration are unapproved.

Physical scan-tag constructionValidation required

Attachment, comfort, wash, durability, read range, placement, and production testing remain incomplete.

Live cryptographic verificationSecurity validation required

Dynamic verification, UID binding, replay defense, monitoring, and production domains are not configured.

Product Identity, Claim, and Ownership recordsProduction implementation required

No live product, token, Claim, Ownership, provenance, or protected action exists.

Damage, retirement, replacement, and supportOD-010 and workflow review required

Evidence, inspection, remedy, successor, history, privacy, and support operations remain unresolved.

Current public route

Learn the system. Do not infer a product result.

How It Works provides the broader sequence. Legal & Trust shows document readiness. Help provides general routing without a scan-tag case.