Effective date: April 2, 2026 Last updated: April 2, 2026
1. Agreement to terms
By accessing or using the BrandSure platform ("Platform"), including our website, APIs, NFC verification services, and brand dashboard, you agree to be bound by these Terms of Service ("Terms"). If you do not agree, do not use the Platform.
These Terms apply to all users, including:
- Consumers — individuals who tap NFC-enabled products to verify authenticity
- Brand partners — businesses that integrate our technology into their products
- Visitors — anyone browsing our website
2. Description of service
BrandSure provides a product authentication platform using NXP NTAG 424 DNA NFC chips. Our services include:
- Tag provisioning — programming NFC chips with unique cryptographic keys and secure dynamic messaging (SDM) configurations
- Product verification — real-time cryptographic authentication when consumers tap NFC-enabled products
- Brand dashboard — provisioning management, tag diagnostics, and analytics for brand partners
- API access — programmatic integration for provisioning, verification, and product management
The Platform uses AES-128 encryption, key diversification, and rolling counters fused into silicon-level hardware to provide cryptographic authentication resistant to cloning. Each chip generates a unique, counter-incremented response per tap that supports replay detection when persistent counter tracking is enabled.
Current platform status: The Platform is in active development. Certain capabilities — including dashboard analytics, API authentication, usage tiers, and persistent verification event logging — are being built toward production readiness. Analytics displayed in the dashboard may include simulated data during the early-access period. These Terms will be updated as features mature.
3. Accounts and access
3.1 Brand partner access
Brand partners access the Platform under the terms of their individual service agreement. As the Platform matures, brand partners will be required to register for an account to access provisioning, the dashboard, and API services. When account-based access is available, you will agree to:
- Provide accurate and complete registration information
- Keep your account credentials and API keys secure
- Notify us immediately of any unauthorized access
- Accept responsibility for all activity under your account
We reserve the right to suspend or terminate access that violates these Terms or poses a security risk.
3.2 Consumer access
Consumers do not need an account to verify products. Tapping an NFC-enabled product and viewing the verification result is freely available to anyone with a compatible smartphone.
4. Acceptable use
You agree not to:
- Attempt to extract, reverse-engineer, or tamper with cryptographic keys stored on NFC chips or within the Platform
- Clone, emulate, or simulate NFC chip responses
- Use the verification system to generate fraudulent authentication results
- Access or probe the Platform's infrastructure, APIs, or WebSocket endpoints beyond the scope of your authorized use
- Interfere with or disrupt the Platform, including through denial-of-service attacks, injection attacks, or automated scraping
- Use the Platform for any illegal purpose, including counterfeiting or fraud
- Resell, redistribute, or sublicense access to the Platform without written authorization
- Remove, alter, or obscure any proprietary notices, authentication markings, or NFC chip integrations on products
5. NFC chip provisioning and ownership
5.1 Chip provisioning
When brand partners provision NFC chips through our Platform:
- Each chip is programmed with diversified AES-128 keys unique to that chip, derived from the brand's master key using AES-CMAC key diversification (per NXP AN10922)
- A provisioning record is created containing the tag's unique identifier (UID), a SHA-256 hash of the derived key (not the key itself), and a timestamp
- The chip's NDEF file is configured with a secure dynamic messaging (SDM) URL that generates a unique cryptographic response on every tap
5.2 Key ownership
- Platform keys (master keys and derived keys) are generated and managed by BrandSure on behalf of the brand partner
- Brand partners do not have direct access to raw cryptographic key material — keys are stored in AES-256-GCM encrypted form or, in production deployments, in Azure Key Vault
- Upon termination of service, key material associated with the brand's tags will be retained for a transition period (see Section 12), after which it will be securely destroyed
- BrandSure will not use a brand partner's keys for any purpose other than operating the Platform on their behalf
5.3 Chip hardware
NFC chips are physical hardware owned by the brand partner (or their customer). BrandSure does not claim ownership of chips or the products they are embedded in. Our service is limited to the cryptographic provisioning, verification, and management layer.
5.4 Tag lifecycle operations
The Platform provides the following tag lifecycle operations:
- Re-provisioning — a provisioned tag may be re-provisioned with updated keys or URL configurations, provided it has not been permanently locked
- Permanent lock — a provisioned tag may be permanently and irreversibly locked, freezing its NDEF URL and SDM configuration. Once locked, the tag cannot be re-provisioned, factory-reset, or modified in any way. This action requires explicit confirmation and cannot be undone.
- Factory reset — a provisioned tag may be reset to its factory state, removing all custom keys and SDM configuration. This renders the tag unverifiable through the Platform. Factory reset is not available for permanently locked tags.
- Diagnostics — the Platform can read a tag's current configuration, key versions, counter values, and tamper status for troubleshooting purposes
Brand partners acknowledge that improper use of lifecycle operations — particularly permanent lock and factory reset — may irreversibly affect products already in circulation. BrandSure is not liable for consequences arising from intentional use of these features.
6. Verification results
6.1 Accuracy
BrandSure verifies the cryptographic authenticity of NFC chip responses. A successful verification confirms that:
- The chip contains a valid AES-128 key provisioned through our Platform
- The CMAC signature is correct for the given encrypted PICC data and rolling counter
- The cryptographic response is consistent with expectations for that tag
A successful verification does not guarantee:
- The physical product's quality, condition, or safety
- That the product has not been physically altered after the chip was embedded
- The accuracy of product metadata or descriptions provided by the brand partner
6.2 Limitations
While our cryptographic verification is designed to be highly reliable, no system is infallible. BrandSure is not liable for:
- Chips that are physically damaged, deactivated, or removed from products
- Verification failures caused by incompatible devices, network issues, or user error
- Any loss arising from reliance on verification results for high-stakes decisions
- Replay of a previously captured verification URL in deployment configurations where persistent counter tracking is not enabled
7. Intellectual property
7.1 Our property
The Platform, including its software, algorithms, user interfaces, documentation, and branding, is the property of BrandSure Technologies, Inc. and is protected by applicable intellectual property laws.
Brand partners are granted a limited, non-exclusive, non-transferable license to use the Platform for the duration of their service agreement.
7.2 Your content
Brand partners retain ownership of their product data, brand assets, and any content they upload to the Platform. By uploading content, you grant us a limited license to use it solely for operating the Platform on your behalf (e.g., displaying product information on verification pages).
8. Fees and payment
8.1 Pricing
Access to the Platform for brand partners is subject to fees as set out in your individual service agreement. Pricing is based on a per-chip provisioning model — details, volume tiers, and any applicable platform fees will be specified in your agreement.
8.2 Payment terms
- Fees are billed in accordance with your service agreement
- Late payments may result in suspension of provisioning capabilities
- Refund terms, if any, will be specified in your service agreement
8.3 Free tier
Consumer product verification is free and does not require payment or account creation.
9. Data and privacy
Our collection and use of data is governed by our Privacy Policy. Key points:
- Consumer verification is currently processed statelessly — we do not persistently store individual verification events
- Provisioning records (tag UIDs, key hashes, timestamps) are stored for the operation of the Platform
- We do not sell personal data
- Brand partners may receive aggregated analytics; individual consumer identities are never shared
10. Disclaimers
THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, BRANDSURE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO:
- MERCHANTABILITY — fitness for a particular purpose
- NON-INFRINGEMENT — that the Platform does not infringe on third-party rights
- UNINTERRUPTED SERVICE — that the Platform will be available at all times without errors or downtime
BrandSure does not warrant that verification results will be 100% accurate in all circumstances or that the NFC chips will function indefinitely.
11. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
- BrandSure's total liability arising from or related to these Terms or the Platform shall not exceed the fees paid by you in the twelve (12) months preceding the claim
- BrandSure shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including lost profits, lost revenue, or loss of data
- This limitation applies regardless of the theory of liability (contract, tort, negligence, strict liability, or otherwise)
These limitations do not apply where prohibited by applicable law.
12. Term and termination
12.1 Term
These Terms are effective as of your first use of the Platform and remain in effect until terminated.
12.2 Termination by you
Brand partners may terminate their account at any time by contacting us. Upon termination:
- Access to the dashboard, APIs, and provisioning tools will be revoked
- Existing provisioned tags will continue to generate cryptographic responses, but verification will depend on key availability (see 12.4)
- Outstanding fees remain payable
12.3 Termination by us
We may suspend or terminate your access if you:
- Violate these Terms
- Engage in activity that threatens the security or integrity of the Platform
- Fail to pay outstanding fees after notice
12.4 Post-termination transition
Upon termination of a brand partner account:
- We will retain cryptographic keys for a 90-day transition period to allow continued verification of products already in circulation
- During this period, brand partners may request transfer of their provisioning records. Key export capabilities and procedures will be documented separately as they become available.
- After the transition period, all keys associated with the account will be securely destroyed
- Provisioning records will be anonymized or deleted in accordance with our Privacy Policy
13. Indemnification
Brand partners agree to indemnify and hold harmless BrandSure, its officers, directors, employees, and agents from any claims, damages, or expenses (including reasonable legal fees) arising from:
- Your use of the Platform in violation of these Terms
- Your products, including product defects, misrepresentation, or consumer harm unrelated to our verification service
- Any third-party claims related to your misuse of the Platform
14. Governing law and disputes
These Terms are governed by and construed in accordance with the laws of the jurisdiction in which BrandSure Technologies, Inc. is incorporated, without regard to conflict of law principles.
Any disputes arising from these Terms or the Platform shall be resolved through:
- Good faith negotiation — 30-day period to resolve informally
- Mediation — if negotiation fails, non-binding mediation
- Arbitration or litigation — as a final resort, in accordance with applicable law
15. Changes to these terms
We may update these Terms from time to time. When we make material changes:
- We will update the "Last updated" date at the top of this page
- Brand partners will be notified by email at least 30 days before changes take effect
- Continued use of the Platform after the effective date constitutes acceptance
If you disagree with updated Terms, you may terminate your account before they take effect.
16. Miscellaneous
- Entire agreement — these Terms, together with our Privacy Policy and any service agreement, constitute the entire agreement between you and BrandSure
- Severability — if any provision is found unenforceable, the remaining provisions continue in full force
- Waiver — failure to enforce any provision does not constitute a waiver of that provision
- Assignment — you may not assign your rights under these Terms without our written consent; we may assign our rights in connection with a merger, acquisition, or sale of assets
17. Contact us
If you have questions about these Terms:
- Email: legal@brandsure.io
- Address: BrandSure Technologies, Inc.
These terms are designed to be read alongside our Privacy Policy.