Sentinel Secure

Every unit carries its own encrypted identity and returns the same one-tap verdict whichever tier it is on. What Sentinel Secure changes is where the protection sits: the chip itself computes a new cryptographic code every time it is tapped, and the server checks that the code has never been used before. It is a second layer inside the tag, on top of the record the platform already keeps.

What a counterfeiter has to defeat

Copying the tag is not enough.

A cloned tag can replay a code that has already been used. The server rejects a code it has seen.

The chip signs itself.

The code is produced inside the chip on each tap, not stored on it. Reading the tag does not reveal how to generate the next code.

A clone announces itself.

When a duplicated tag replays an old code, the platform records it as a cloned-tag signature and raises it in the monitoring centre.

When Sentinel Secure is worth it

Sentinel Secure is chosen per product, not per account. It is intended for lines where a brand wants the tag itself to resist copying as well — regulated goods, high-value consumer products, and controlled supply chains where a customer cannot inspect authenticity themselves. A standard tag carries the same unit-level identity and is monitored the same way, and the two run side by side under one brand.

How it looks to a customer

Nothing changes for the person holding the product. They tap it with a phone and get one clear verdict. Units protected by Sentinel Secure carry a Sentinel Secure badge on that verdict screen.

Chip-level NFC authentication: common questions

What is the difference between a standard NFC tag and Sentinel Secure?

Both give every unit its own encrypted identity and return the same one-tap verdict. The difference is where the protection sits. With a standard tag the platform holds the authority: it keeps the record of every scan and raises an alert when a unit’s pattern looks wrong. Sentinel Secure adds a second layer inside the chip itself, which computes a fresh cryptographic code on each tap.

What happens if someone clones a Sentinel Secure tag?

A clone can only replay a code it has already captured, and the server rejects a code it has seen before. The cloned chip cannot compute the next code, because each code is generated inside the original chip rather than stored on it. The replay is recorded as a cloned-tag signature and raised in the monitoring centre.

Which NFC chip does Sentinel Secure use?

Sentinel Secure is built on the NTAG 424 DNA chip, which produces a cryptographic message authentication code inside the chip on each tap. That is a property of the hardware rather than something added in software afterwards, which is why reading a tag does not reveal how to generate the next code.

Does the customer experience change with Sentinel Secure?

No. The person holding the product taps it with an NFC-capable smartphone and gets one verdict, exactly as with a standard tag. Units protected by Sentinel Secure carry a Sentinel Secure badge on that verdict screen, so the higher tier is visible to the customer without asking anything more of them.

Do all products need Sentinel Secure?

No, and a standard tag is not a lesser option. It carries the same unit-level identity, returns the same verdicts, and is monitored the same way. Sentinel Secure adds an on-chip layer for lines where a brand wants the tag itself to resist copying as well, and the two run side by side under one brand. The tier is chosen per product, not per account.