How it works

From the code on the label to the result on screen

Traza follows a simple principle: each unit has a signed identity, each moment of its lifecycle leaves an event and anyone can check both. This is how it happens, step by step.

Five steps

From the moment a unit receives its identity until someone checks it in front of a shelf, the process passes through five moments.

  1. Identity issuance

    The manufacturer or importer requests an issuance and the platform derives and signs a unique identifier per unit, with the keys in its custody. That identifier carries the four fields of the story: who issues it, what the product is, which lot it came from and when it expires.

  2. Labeling

    The signed identifier is printed as a code on the label, using the plant’s own infrastructure and after a press proof is approved. From then on, the physical unit and its digital identity travel together.

  3. Event recording

    When the lot closes, the issuer completes the record — lot and expiry date, or serial — and at that moment the codes become active. A code that is looked up before activation does not say “verified”: it says “under review”.

  4. Public verification

    Whoever has the unit in front of them scans the code or types it on the verification page. The service evaluates four signals and returns an explained result.

  5. Control and inspection

    Regulators and companies follow anomalies and discrepancy reports, prioritize field inspections and record what is observed on site.

The chain, node by node

The history of a unit is built from the events at these nodes. Not every deployment uses all of them; each tenant defines the ones that matter to it.

  1. Issuance

    The platform derives and signs each unit’s identifier, within the order that was requested.

  2. Labelling

    The signed code is printed and applied to the unit, using the plant’s own infrastructure.

  3. Activation

    When the lot closes, the record is completed — lot and expiry, or serial — and the codes become active.

  4. Public lookup

    Anyone checks the unit from the browser and compares what they see with the registry.

  5. Signals

    Every lookup adds context: when the first one happened, how many there have been, and whether the pattern is impossible for a single unit.

  6. Closure

    When activation ends, the sequence numbers that were never used are voided by range.

See the interactive journey

What happens when you verify

The result of a verification is not a single word. It is built from four independent signals, each with its own explanation.

  • Signature

    Checks that the identity was issued by the expected issuer and has not been altered since.

  • Registry status

    Looks up whether the identity is active, suspended or revoked, and which events are recorded in its history.

  • Data match

    Compares the data on the label with the data in the registry: product, presentation, lot and expiry date.

  • Anomalies

    Looks for patterns worth reviewing: the same code looked up in different places, events out of sequence or inconsistent locations.

  • Signature issued and data match

    The identity was issued by the expected issuer, is active in the registry, its data matches the label and there are no anomalies. It is a solid signal; checking against the physical unit remains the complement.

  • With warnings

    The signature is valid, but the registry shows something worth reviewing: for example, the same code looked up from places a single unit cannot travel between in that time. The next step is to check against the unit and, if appropriate, report.

  • Invalid signature or unrecognized identity

    The code does not correspond to an issued identity, or the registry indicates it was revoked. Do not treat the unit as verified and use the discrepancy report.

  • Could not verify

    It was not possible to consult the registry — for example, without a connection — or the code could not be read. This is not a verdict on the unit: try again when possible.

A valid signature indicates that the identity was issued; it does not describe the physical content or prevent a label from being copied. That is why the result always explains what was checked, how much confidence it provides and what the next step is.

What you need to verify

Very little. Public verification was designed to work at the point of sale with what anyone already carries.

  • A current browser

    Verification opens as a web page on a phone or a desktop computer.

  • No installation, no account

    There is nothing to download or sign up for. No personal data is requested to verify either.

  • A connection to consult the registry

    Registry status and anomalies require a connection. Without one, the result is marked as unverifiable and can be retried.

  • A readable code

    The code on the label is scanned with the camera or typed by hand if it is damaged.

See it with a sample code

Public verification includes sample codes that show each of the possible results.