Trust
How Optivalux earns trust.
This page describes the designed Optivalux architecture. Production V2 (the production implementation) is in development; physical pilot: preparing.
- 01
Physical authentication
Each product carries a secure authenticator registered by the brand. Verification sends a fresh challenge; the authenticator answers with a signed response that is checked against the registered identity. A result states what was verified and when.
Technical detail
Challenge–response: a fresh challenge is issued for each check and the signed response is compared with the registered identity. Users see the evidence as “signed response · time”.
- 02
Product certificate
The brand issues a certificate for the specific product. Its standing is Active, Suspended or Voided. Suspension is reversible; voiding is permanent.
Technical detail
Standing is an independent field on the certificate record. VOID is terminal in the state model.
- 04
Recipient acceptance and possession
The recipient must accept, and the product must be verified in the recipient’s possession, before ownership moves. Nobody receives a product they did not agree to take.
Technical detail
Acceptance and a fresh physical-possession verification are both required to complete a normal transfer.
- 05
Controlled recovery
If an authenticator is lost or damaged, access can be restored through brand-assisted recovery or with the owner’s own Recovery Authenticator. Recovery restores access; it never changes ownership, and a suspended certificate stays suspended.
Technical detail
Recovery Authenticator recovery has a 14-day maturation period during which the request can be challenged.
- 06
Protocol evolution
Ownership is designed so later protocol software cannot silently reassign an already-owned certificate. Software can improve; what you own stays yours.
Technical detail
Upgrades are constrained so they cannot change the owner of an existing certificate without the owner’s participation.
- 07
Protection Mode
If the software or verification a certificate depends on stops working, the owner can start Protection Mode. After 14 days the certificate moves to a safe, non-operational state. Ownership does not change.
Technical detail
A 14-day owner-initiated protection process moves the certificate to a protected, non-operational state.
- 08
Security restrictions
Sensitive actions are limited to the parties entitled to take them: brands manage certificate standing; owners manage transfer, recovery and protection. Optivalux never asks users for recovery phrases.
Technical detail
Role separation between issuer actions (standing) and owner actions (transfer, recovery, protection).
- 09
Long-term ownership continuity
The record is designed to outlast any single application, including ours. Authentication availability and certificate ownership are separate concepts: if verification is temporarily unavailable, ownership and certificate standing are unaffected.
Technical detail
Ownership and standing are recorded independently of the verification service that reports authentication availability.
Language we use, and language we don’t.
Optivalux is infrastructure that provides verifiable evidence. It does not make impossible guarantees.
We say
- verified
- registered
- certificate active
- authenticity evidence
- authenticator verified
- matches the registered identity
- ownership history
We don’t say
- Avoided:
guaranteed genuine - Avoided:
100% authentic - Avoided:
unclonable - Avoided:
counterfeit-proof - Avoided:
tamper-proof - Avoided:
guaranteed value - Avoided:
fully trustless
Review the architecture with us.
We are happy to walk technical partners through the model in more depth.