Technology

Security that resists replication

TrueTap is built on challenge-response cryptography anchored to provisioned hardware. The architecture is designed to remain secure when chip data is observable - duplication of chip data does not reproduce authentication capability.

Architecture model

Credential authentication. Holder authentication. Policy validation.

Trust at the point of verification is built from three separate decisions. Each must be answerable independently, auditably and at scale. The TrueTap architecture never collapses them into a single signal.

Physical credential authenticity

The card, label or asset taps the reader. Challenge-response cryptography confirms the embedded secure element carries the unique key material bound at provisioning. A clone cannot answer correctly.

Credential authenticity

Person verification

A live biometric capture - fingerprint, face or iris depending on the device - confirms the person presenting the credential is the legitimate holder, not someone holding a borrowed or stolen token.

Holder match

Identity binding

The credential identity is linked to the enrolled biometric identity in the registry or on the secure card. The cryptographic chain of trust from issuance to tap is verified end-to-end.

Policy decision

Status & policy validation

Even a genuine credential held by the right person may be suspended, revoked or out of scope for the requested action. Status and policy checks return the authorization outcome.

Audit event

Verified

Credential genuine, holder confirmed, status active, policy satisfied. The authorization outcome is granted and the full event is logged.

Rejected

Any of the three signals fails. The reason is captured in the audit trail; no sensitive key material is exposed in the rejection path.

Escalated

Ambiguous or partial results - for example, a credential flagged for review or a borderline biometric score - are routed to a supervisor or adjudication workflow rather than silently accepted.

Biometric matching

Two paths for holder verification.

The right matching architecture depends on programme topology, connectivity and privacy posture. TrueTap supports both, and they can coexist within a single programme.

Path A

Sovereign registry match

The live biometric capture is compared against the central or sovereign identity registry. Maximum deduplication power and the strongest protection against issuance-stage fraud. Requires connectivity or a cached subset at the point of verification.

Path B

Privacy-preserving secure-card architecture

Where programme requirements demand offline operation or minimal biometric exposure, comparison may be performed against a secure-card implementation designed to minimize exposure of biometric templates. Match-on-card availability is configuration-dependent and not universal - the secure element and credential architecture must explicitly support it.

Do not assume ordinary NFC labels store fingerprints. Biometric-template storage requires a credential architecture specifically engineered for it.

Hardware security

Security anchored in hardware, not just software.

Cryptographic operations are protected at multiple layers. No single layer is sufficient on its own; defence in depth is the baseline posture.

Hardware & secure-element encryption

Encryption at hardware and secure-element level where supported by the selected chip family and credential architecture. Key material is written at provisioning and not retrievable in cleartext.

HSM-backed key operations

Programme root keys and issuing keys are operated inside hardware security modules. Signing operations never expose the private key outside the HSM boundary.

Encrypted biometric transport

Biometric captures are encrypted in transit from the capture device to the matching subsystem. The plaintext biometric does not traverse general-purpose networks.

Role-based data access

Administrators, operators, officers and auditors see only the data their role permits. Privileged operations require step-up authentication and are logged.

Audit logging

Comprehensive audit logging of every verification, administrative action and policy change. Exportable to SIEM and oversight systems.

Sovereign deployment

The full stack can be deployed inside a national, departmental or organizational perimeter. Air-gapped deployment configurations can be supported subject to programme architecture.

Architecture

Technology stack

Four integrated layers from silicon to application - each designed with explicit security and operational properties.

Layer 01 - Hardware

Provisioned NFC silicon

Standard and secure NFC chip families with on-chip secure element. Unique key material is written at provisioning and cannot be read back in cleartext. Physical tamper response is supported on relevant form factors.

Layer 02 - Protocol

Challenge?response authentication

Each tap initiates a fresh cryptographic challenge from the verification service. The chip responds using on-chip key material. The response is valid for a single session; replay attacks are structurally prevented.

The protocol does not require the chip to be online, but the reader or device must reach the verification service to complete authentication.

Layer 03 - Services

Verification and key management services

Server-side key operations are performed in hardware security modules (HSMs). Verification events are logged with cryptographic integrity guarantees. The service tier is stateless for verification and supports horizontal scaling for high-throughput deployment contexts.

Layer 04 - Integration

APIs, SDKs, and programme management

REST verification API and mobile SDKs (iOS, Android) for integration with existing systems. Programme administration portal for lifecycle management, analytics, and audit access. Webhook delivery for real-time event integration.

Security properties

Non-negotiable security properties

The TrueTap architecture guarantees specific security properties regardless of deployment context. These properties hold even if an attacker captures NFC traffic or obtains a legitimate chip for analysis.

Anti-cloning

Key material cannot be extracted from provisioned chips. A physical duplicate does not yield a chip that passes verification.

Anti-replay

Challenge freshness means intercepted NFC sessions cannot be replayed to obtain a subsequent verification.

Non-repudiable logging

Every verification event is logged with a tamper-evident signature. Event records cannot be modified without detection.

Revocation

Programme operators can revoke chip identities in real time. Revoked chips return a deterministic negative result on verification.

Offline verification (constrained mode)

For field environments, verification can operate against cached validation data with defined staleness bounds.

Deployment topology

Infrastructure configurations

The platform topology is selected based on data residency requirements, operational independence, and programme scale.

Cloud

Managed multi-tenant

Fastest deployment path. Platform infrastructure operated by HSA with programme-level data segregation. Suitable for commercial programmes without specific residency constraints.

Private

Dedicated cloud tenancy

Isolated infrastructure within a defined cloud region. Addresses data residency requirements for regulated programmes while retaining managed operations.

On-prem

On-premises sovereign deployment

Platform deployed within the programme operator's infrastructure perimeter. Key management infrastructure transferred to programme control. Required for classified environments and for air-gapped deployment configurations, which can be supported subject to programme architecture.

Hybrid

Hybrid edge deployment

Verification edge nodes deployed within the programme perimeter; key management and audit infrastructure retained in a controlled zone. Common for border and enforcement contexts.

Technical briefing

Request an architecture review

The TrueTap technical team is available for structured architecture briefings with programme security officers and integration engineers.