Skip to content
FaceOff Technologies

QuantumSafeQR

Issues and verifies identity credentials stored in a QR code that cannot be copied or forged. It proves a code is genuine before revealing anything inside it, works with or without an internet connection, and is built with encryption designed to hold up even against future quantum computers

Product Walkthrough
0:000:00

What it is

It proves a code is genuine before it reveals anything

QuantumSafeQR issues and verifies identity credentials stored in a QR code that cannot be copied or forged. Every code is signed with elliptic-curve cryptography before it is encrypted, and its authenticity is proven against the root issuer before anything is decrypted — so a tampered or counterfeit code is rejected up front and no forged data is ever read.

Master credentials and PINs are isolated through environment injection with no hard-coded secrets, and cryptographic keys are wrapped inside a hardware security module (HSM) that keeps them safe across system restarts. Signing and decryption keys are compartmentalised by separation of duties.

It works with or without an internet connection, and is built with encryption designed to hold up even against future quantum computers — protecting identities for the long life a national ID needs to have.

Cryptographic foundations designed to withstand next-generation and post-quantum computing

Post-quantum

Cryptographic foundations designed to withstand next-generation and post-quantum computing

Authenticity proven against the root issuer before anything is decrypted

Signature-first

Authenticity proven against the root issuer before anything is decrypted

Verification works in low-connectivity environments — no signal, no problem

Online & offline

Verification works in low-connectivity environments — no signal, no problem

Keys wrapped in a hardware security module, aligned with FIPS 140-2 and QSCD practices

FIPS 140-2 · EN 419241

Keys wrapped in a hardware security module, aligned with FIPS 140-2 and QSCD practices

How it works

From issuance through verification to a tamper-proof audit trail

  1. 01

    Issue

    Admin Suite mints credentials; keys held in HSM

  2. 02

    Sign, then encrypt

    Elliptic-curve signature applied before encryption

  3. 03

    Citizen wallet

    Held in a web or native app

  4. 04

    Verify

    Signature checked first, online or offline

  5. 05

    Audit ledger

    Every action logged, tamper-evident

What sets it apart

Ordered by impact, most decisive first

  1. Post-quantum-secure infrastructure

    QuantumSafeQR is built on cryptographic foundations designed to withstand next-generation and post-quantum computing. Credentials issued today stay trustworthy as that threat arrives — protecting identities for the long life a national ID needs to have.

    Flagship capability · post-quantum ready

  2. Signature-first verification

    Every QR code is signed with elliptic-curve cryptography before it is encrypted, and its authenticity is proven against the root issuer before anything is decrypted. A tampered or counterfeit code is rejected up front, so no forged data is ever read.

    Signed before encrypted · proven before read

  3. Hardware-backed key security

    Master credentials and PINs are isolated through environment injection with no hard-coded secrets, and cryptographic keys are wrapped inside a hardware security module (HSM) that keeps them safe across system restarts. Signing and decryption keys are compartmentalised by separation of duties.

    HSM-wrapped keys · separation of duties

  4. Online & offline verification

    The platform handles both connected and fully offline verification flows, so an identity can be checked reliably even in low-connectivity environments — no signal, no problem.

    Connected or fully offline

  5. Scan limits & anti-brute-force throttling

    Hard limits and velocity checks cap how often a single QR code can be scanned, blocking mass-scan and enumeration attacks that try to harvest or guess identities at scale.

    Hard limits · velocity checks

  6. Location anomaly detection

    AI-driven checks flag impossible scanning patterns — such as the same identity being verified in two distant parts of the world at once — surfacing misuse that a simple validity check would miss.

    Impossible scanning patterns, flagged

  7. Privacy & GDPR by design

    Built-in data portability (export), right-to-erasure (deletion) and automatic anonymisation of expired data enforce retention limits — keeping the system compliant and respectful of the people it serves (GDPR Articles 17 and 20).

    GDPR Articles 17 and 20

  8. Tamper-proof audit ledger

    A centralised, tamper-evident ledger records every issuance, verification attempt and administrative action, giving a complete and trustworthy history for oversight and investigation.

    Every issuance, verification and admin action

How it compares

How it compares to other QR approaches

  • Resistant to future quantum attacks

    Standard QR codes
    NoNo
    Classically-signed QR
    NoClassical only
    QuantumSafeQR
    YesPost-quantum ready
  • Proves authenticity before revealing data

    Standard QR codes
    NoData in the open
    Classically-signed QR
    PartlySigned but readable
    QuantumSafeQR
    YesSignature-first
  • Tamper & forgery protection

    Standard QR codes
    NoTrivially copied
    Classically-signed QR
    PartlySigned, not encrypted
    QuantumSafeQR
    YesSigned + encrypted
  • Works fully offline

    Standard QR codes
    PartlyData only, no trust
    Classically-signed QR
    PartlyDepends
    QuantumSafeQR
    YesYes
  • Hardware-backed key storage (HSM)

    Standard QR codes
    NoNo
    Classically-signed QR
    PartlyVaries
    QuantumSafeQR
    YesFIPS-aligned HSM
  • Brute-force & mass-scan limits

    Standard QR codes
    NoNo
    Classically-signed QR
    NoNo
    QuantumSafeQR
    YesThrottling & limits
  • Location anomaly detection

    Standard QR codes
    NoNo
    Classically-signed QR
    NoNo
    QuantumSafeQR
    YesYes
  • Privacy controls (export, erasure, anonymisation)

    Standard QR codes
    NoNo
    Classically-signed QR
    PartlyVaries
    QuantumSafeQR
    YesGDPR by design

The architecture

Signed before it is encrypted — proven before it is read

One boundary, and nothing is decrypted until the signature checks out

  • Administrative Suite
  • HSM-held keys
  • Separation of duties

At issuance

Sign, then encrypt

Elliptic-curve signature applied before encryption

Issued

With the citizen

Citizen wallet

Held in a web or native app

Signature first

Authenticity is proven against the root issuer before anything is decrypted. A tampered or counterfeit code is rejected up front.

At the point of check

Verify, online or offline

Scan-limit and location-anomaly checks applied

Logged
Audit ledger · tamper-evident

Use cases by sector

Use cases across sectors

Government & national ID

Issue and verify citizen credentials that resist forgery and future quantum attacks.

How the sector deploys it

Healthcare

Give patients a secure, verifiable health identity that works offline.

How the sector deploys it

Education

Issue tamper-proof diplomas and certificates anyone can verify.

How the sector deploys it

Border control & travel

Validate travel and visa credentials at checkpoints, online or offline.

How the sector deploys it

Banking & finance

Bind accounts to a cryptographically verifiable identity.

How the sector deploys it

Utilities & subsidies

Confirm eligibility for benefits and services while detecting misuse.

Deployment strategy

Issue centrally, verify anywhere, log everything

  1. Issue from the Administrative Suite

    A central suite drives key issuance and security wrapping; signing keys are generated and protected inside the hardware security module, with strict separation of duties.

  2. Sign, then encrypt each QR

    Each credential is signed with elliptic-curve cryptography and then encrypted, so its authenticity can be proven against the root issuer before any decryption takes place.

  3. Distribute to citizen portals

    Citizens hold and present their identity through web and native wallet apps, interacting with their credential securely from their own device.

  4. Verify online or offline

    At the point of check, the signature is validated against the issuer first. Verification works with or without connectivity, with scan-limit and location-anomaly checks applied.

  5. Log to the audit ledger

    Every issuance, verification attempt and administrative action is written to a centralised, tamper-proof ledger for oversight and investigation.

Four things a national credential has to get right

What runs, how the keys are held, which standards it maps to, and what a citizen can ask of it.

System modules
Three integrated parts: an Administrative Suite for issuance and monitoring, Citizen Portals as web and native wallet apps, and a tamper-proof Audit Ledger.
Key management
Signing and decryption keys are compartmentalised by separation of duties and wrapped inside a hardware security module, persisting safely across system cycles with no hard-coded secrets.
Standards & compliance
Uses NIST-approved elliptic-curve cryptography, hardware security modules aligned with FIPS 140-2, and EN 419241 (Qualified Signature Creation Device) practices.
Privacy operations
Dedicated flows for data export (portability), erasure, and automatic anonymisation of expired data enforce retention limits — GDPR Articles 17 and 20 in practice.

Frequently Asked Questions

Each QR code is signed with elliptic-curve cryptography and then encrypted — signature first. On scanning, authenticity is proven against the root issuer before anything is decrypted, so tampered or counterfeit codes are rejected up front. Scan limits and velocity checks cap how often a code can be scanned to block mass-scan and enumeration attacks, and AI-driven location-anomaly detection flags impossible patterns, such as the same identity being verified in distant places at once.

Book a technical walkthrough

45 minutes with a solutions engineer. No slide deck unless you ask for one.

We use this to schedule the call. It does not enter a marketing sequence.

The rest of the line

More in Zero-Trust Identity

Issue an identity that stays trustworthy

Have a solutions engineer walk your team through issuance, offline verification and how the keys are held in the HSM.