Documentation for every role Use your browser's Print command to save this guide as a PDF.
AuthPlus

Administrator guide

Users, global settings, moderation, control verifiers and server installation.

Generated from the online documentation on August 30, 2026 · https://authenticity-plus.com/docs/

Contents

  1. Introduction
  2. Core concepts
  3. Ownership
  4. Roles & permissions
  5. Creating an account
  6. Signing in
  7. Managing your profile
  8. Getting started
  9. Requirements
  10. Installation & access
  11. Dashboard tour
  12. Brands
  13. Products
  14. Assets
  15. Contents
  16. Issuing codes
  17. Labels & exports
  18. Managing verifiers
  19. Operations
  20. Warnings
  21. Getting started
  22. Server requirements
  23. Installing the server
  24. Administrator overview
  25. The owner filter
  26. User management
  27. Global settings
  28. Prohibited names
  29. Brand verification
  30. Control verifiers
  31. Moderation
  32. Platform configuration
  33. Security
  34. Data & privacy
  35. Notifications
  36. Troubleshooting
  37. Frequently asked questions
  38. Glossary
  39. Support

Introduction

Counterfeiting works because a buyer cannot tell a real item from a convincing copy. AuthPlus closes that gap. A brand registers what it produces, and AuthPlus mints a unique, tamper-proof code for every unit. The code is printed on the product, its label or its certificate. Anyone holding the item can scan that code and receive an immediate, unambiguous answer: Authentic, Authentic with a warning, or Non Authentic.

Every scan is recorded, so the brand sees where and when its products are being checked, and unusual patterns — the same code verified far more often than a single physical item ever could be — surface automatically as warnings.

Protect

Register brands, products, valuables and documents, then issue unique authenticity codes for them.

Verify

Anyone can confirm authenticity in seconds with the mobile app or a web browser — no account required.

Monitor

Follow every verification and transfer on a live audit trail and map, with automatic alerts on abuse.

AuthPlus is delivered as two connected experiences that share one account system:

  • The dashboard (/dash) — a web workspace where brand owners register their catalogue, issue codes, print labels and monitor activity.
  • The verification app (/verify) — a deliberately simple scanning experience, available as an Android app and in any web browser, used in shops, at customs, or by end customers.
  • Names of on-screen elements appear like this: Issue Codes. They match the English interface exactly; in French or Arabic the label is translated but the position is identical.
  • Sequences of navigation are written ProductsNew.
  • Technical values — addresses, file names, settings — appear as code.
  • Numbered procedures always follow the same shape: purpose, prerequisites, the steps, then the expected result.
  • A role badge next to a heading means the feature is limited to that role: Standard user Admin Superadmin Verifier

Three kinds of callout are used:

Core concepts

Everything you protect in AuthPlus follows the same five-level chain. Understanding it makes every screen in the dashboard predictable, because each level is simply a list of the level below it.

LevelWhat it isExample
1. BrandThe name behind your items. Everything you register belongs to a brand.Aurora Watches
2. Subject
Product · Asset · Content
The thing you protect, or a category of them. Its type decides how it is verified.Aurora Chrono 42
3. ItemA concrete unit: a production batch, one individual valuable, or one document entry.Batch AC42-2026-A
4. IssuanceOne act of minting codes for an item. An item can have several issuances over time.10 Public codes, 30 July 2026
5. CodeA single unique authenticity code, printed as text and as a QR code.2H7KLM4GUEXDVM

In the dashboard you walk down this chain by clicking: a brand’s products, a product’s batches, a batch’s issuances, an issuance’s codes. Breadcrumbs at the top of each screen show you where you are and let you climb back up.

A subject’s type is chosen when you create it and cannot be changed afterwards. It determines which section of the dashboard the subject lives in, how codes are issued for it, and what a verifier sees when it is scanned.

ProductsAssetsContents
ForManufactured goods produced in quantityUnique valuables: art, jewellery, collectiblesFiles: certificates, official documents, media
Item meansA production batchOne individual pieceOne document entry
Codes per itemMany — one per physical unitNormally oneOne per uploaded file
Issued byChoosing a quantityChoosing a quantityUploading files — each file becomes one code
Verified byScanning the printed codeScanning the code on the certificateScanning the code, or checking the file itself
Verifier seesBrand, product, batch, dates, scan historyAn ownership certificate with its provenanceA certification record and the document

A code is a short random string, unique across the platform, printed as text and encoded in a QR code. Codes are not sequential and cannot be guessed from one another.

Every code belongs to a code type, chosen at issuance. Code types are configured centrally for the whole platform and typically follow the distribution chain:

Code typeIntended forTypical placement
PublicEnd customers. The default.Visible on the product or its packaging
ResellerDistributors and retail partnersOn the carton or delivery documents
ControlInternal inspection and enforcementHidden or restricted placement

A verifier is the identity under which a scan is recorded — a shop, an employee, an inspector, or simply an anonymous consumer device. Verifiers are not dashboard user accounts; they exist so that an item’s history is meaningful, and so that custody can be tracked as goods move.

Each verifier belongs to a verifier type, which decides how it behaves:

  • Public — created automatically on first launch of the app. No credentials, no setup. This is what an ordinary customer uses without ever noticing.
  • Reseller — for trade partners; also self-provisioning, but tied to reseller codes.
  • Control — restricted inspection accounts. These are created by the platform administrator and handed out with a username and password (see Control verifiers).

Verifier types can also require the device’s location before a scan is accepted, restrict a verifier to codes created by a particular owner, or fill in the verifier’s profile automatically from the device.

Every scan — successful or not — creates an operation: a permanent line in the audit trail recording what was scanned, by which verifier, when, from where, and with what result. Operations are what feed the dashboard’s statistics, the map, and the warning system.

The verdict falls into one of three classes:

VerdictMeaningWhat to do
AuthenticThe code exists, is active, and nothing about the scan is unusual.Proceed with confidence.
Authentic, with a warningThe code is genuine, but the circumstances deserve attention — most often because it has been verified more times than a single item plausibly would be.Treat with care; the item may be genuine while its code has been copied.
Non AuthenticThe code does not exist, or it has been blocked or archived.Do not trust the item. Report it to the brand.

The exhaustive list of outcomes, with the exact message shown for each, is in §12 Verdict reference.

AuthPlus is an evidence system, so records are not destroyed. Instead of deleting a brand, product, item, issuance, code or verifier, you archive it. An archived record stays visible (behind the Archived filter), keeps its history, and can be restored.

Archiving has one immediate, deliberate consequence:

Use it deliberately: archiving a brand silently disables every code beneath it. When you only need to stop one batch, archive that issuance rather than anything higher up the chain.

Ownership

Every record in AuthPlus has an owner — the user account that created it. Ownership is the boundary of visibility: a standard user sees their own brands, subjects, items, codes, verifiers, operations and warnings, and nothing belonging to anyone else. Administrators can widen that boundary deliberately with the owner filter (The owner filter).

Roles & permissions

Who can do what, and why you may not see a screen that this documentation describes.

AuthPlus separates the people who check items from the people who manage them. Only the latter have accounts.

Verifier — no account
Anyone using the verification app. Identified by a verifier profile on their device rather than by a login. Ordinary customers get one automatically; trade and inspection profiles are issued with a username and password. A verifier can scan, view the verdict, transfer custody and see the history of their own scans. They have no access to the dashboard.
Standard user — the default account
A brand owner. Sees and manages only what they own: their brands, products, assets, contents, items, issuances, codes and verifiers, plus the operations and warnings those generate. This is the role every self-registered account receives.
Administrator
Everything a standard user can do, but across all owners, plus user management, global settings, the prohibited-name blocklist, brand-badge approvals and the full warning queue.
Superadministrator
A single platform-operator account created when the server is first started. Adds the platform-wide catalogue — code types, print templates and verifier types — and maintenance actions. It is never listed in Users and cannot be modified by administrators.

full access   limited — see note   no access

CapabilityVerifierStandardAdminSuper
Verify codes, files and links
Transfer custody of a code
Sign in to the dashboard
Create & manage brands, subjects, items, issuances, codes own any owner
Generate PDF / CSV label documents own
Create & manage verifier accounts permitted types only permitted types only all types
View operations (audit trail & map) own all
View warnings own over-verified only all kinds
Request a brand verification badge
Approve, reject or revoke a badge
Switch the owner filter (see other owners’ data)
Create users & change roles Standard/Admin only Standard/Admin only
Archive / restore a user account not self not self
Global settings (ceilings, label footer)
Prohibited-name blocklist
Code types, print templates, verifier types read-only read-only
Enable / disable interface languages

Two rules constrain administrators, by design:

  • You cannot change your own role or archive your own account. This prevents an administrator from accidentally locking everyone out of the platform. Ask another administrator.
  • The superadministrator is untouchable. It does not appear in the user list and cannot be demoted, archived, or created from the interface.

Every list in the dashboard is filtered by the owner scope in force. For a standard user that scope is fixed to their own account and cannot be changed. For an administrator it is chosen in the sidebar and applies everywhere at once — lists, statistics, the map, warnings and the global search. See §27 The owner filter.

Creating an account

Accounts are needed only for the dashboard. Verifying items never requires one.

Purpose. Create your own brand-owner account and reach the dashboard for the first time.

Prerequisites. An email address you can read right now, and a password of at least 8 characters.

  1. Open the AuthPlus website and choose Get started, then Create account. You can also go straight to /signup.
  2. Fill in First name, Last name, Email and Password, then submit the form.
  3. AuthPlus emails you a 6-digit verification code. Check your inbox — and your spam folder if it does not arrive within a minute or two.
  4. Type the code into Verification code and choose Verify & create account.

Expected result. The account is created, you are signed in immediately, and you land on the dashboard Overview with empty statistics. Your role is Standard user.

Sign-up form with name, email and password fields

Step 1 — your details.

Verification code screen

Step 2 — the emailed code.
ItemRule
PasswordMinimum 8 characters. No other requirement is enforced — no obligatory digits, symbols or mixed case, and no maximum length.
EmailMust be a valid address and must not already be registered.
Verification code6 digits, valid for 10 minutes, and accepted for at most 5 attempts.
NamesFirst and last name are both required.
RoleAlways Standard user. Only an administrator can grant the Admin role afterwards.
MessageMeaningResolution
An account with this email already existsThe address is already registered.Sign in instead, or use Forgot password if you cannot remember it.
Invalid or expired codeOne message covers every failure: wrong digits, more than 10 minutes elapsed, or five wrong attempts.Restart the sign-up form to have a fresh code sent.
Password must be at least 8 charactersThe password is too short.Lengthen it and submit again.
A valid email is requiredThe address is malformed.Correct the typo — a domain and an @ are required.
Challenge verification failedAn invisible anti-bot check did not complete, usually after the page has been left open a long time.Reload the page and submit again. See The invisible anti-bot check.

Accounts created for you by an administrator

Section titled “Accounts created for you by an administrator”

Organisations usually create accounts centrally instead of letting staff self-register. In that case an administrator creates the account with an initial password and passes it to you directly (see §28 User management).

Signing in

Two ways in — a password, or a single-use code by email — plus recovery if you are locked out.

  1. Go to /signin, or choose Get started on the website.
  2. Enter your Email and Password.
  3. Select Sign in.

Expected result. You arrive on the dashboard. If you were sent to the sign-in page from a deeper link, you return to that page instead.

AuthPlus sign-in page

The sign-in page — password, or a one-time email code.

Purpose. Sign in without typing a password — useful on shared or unfamiliar devices, or if you never set a memorable password.

  1. On the sign-in page choose Sign in with a code instead.
  2. Enter your email address and choose Send code.
  3. Read the 6-digit code from your inbox and enter it.

Expected result. You are signed in exactly as with a password. The code is then consumed and cannot be reused.

  1. On the sign-in page select Forgot password?
  2. Enter your email address and request the code.
  3. Enter the emailed code and your new password (at least 8 characters).

Expected result. The password is replaced and you can sign in with it immediately.

AuthPlus keeps you signed in across restarts of the browser or the mobile app; your session is renewed silently in the background, so you should not be interrupted while working. To end a session, open the avatar menu at the top-right and choose Sign out.

Managing your profile

Everything you can change about your own account, from the avatar menu → Profile.

Profile page with identity, timezone, ceilings and security

The profile page — identity, timezone, verification ceilings and security.

Your first and last name are what other users see beside the records you create — for example in the Created by column of the operations list. Both are required.

The Timezone setting governs every date and time displayed in the dashboard: operations, warnings, issuance dates, everything. Set it to the zone you actually work in so that “10:32” means what you expect. A live clock next to the field shows the current time in the selected zone.

A ceiling is the number of times one of your codes may be verified before AuthPlus raises an over-verified warning. It is the main automatic anti-counterfeiting signal: a genuine item is normally checked a handful of times, while a code copied onto a thousand fakes is checked constantly.

FieldApplies toDefault
Max verifications — productsCodes on product batches25
Max verifications — assetsCodes on individual valuables25
Max verifications — filesCodes certifying documents0 (disabled)

Setting a value to 0 disables the ceiling for that type — no over-verified warning will ever be raised. Files default to 0 because a public certificate is expected to be checked by many people.

Your personal ceiling takes precedence over the platform-wide default set by an administrator (Global settings).

Prerequisites. Either your current password, or access to your mailbox.

  1. Open Profile and find the security card.
  2. Enter your new password (at least 8 characters).
  3. Prove it is you, in one of two ways:
    • type your current password; or
    • select the mail icon in the field to switch to Use a code instead — AuthPlus emails a 6-digit code to your own address, which you then enter. This is the route to take if you always sign in with email codes and have no password to recall.
  4. Save.

Expected result. The password changes immediately and you stay signed in.

  1. In Profile, enter the new address in the Change email card.
  2. AuthPlus sends a 6-digit code to the new address. Read it there.
  3. Enter the code to confirm.

Expected result. The address is updated at once and becomes your sign-in identity. Your password is unchanged.

MessageResolution
An account with this email already existsAnother account already uses that address. Choose a different one, or archive the other account first.
Invalid or expired codeRequest a new code and enter the most recent one within 10 minutes.
Current password is incorrectShown when changing a password with the wrong current password. Use the emailed-code route instead if you are unsure.

The top bar carries a language selector and a light/dark theme toggle. Both apply instantly, are stored on the device, and are independent of your account — so the same user can work in French on a laptop and in English on a phone.

EnglishFrançaisالعربية — right-to-left layout

Choosing Arabic mirrors the entire interface to a right-to-left layout. The language you pick also becomes the default language offered when generating label documents (Labels & exports).

Getting started

  1. Open the AuthPlus site and choose Create account. Enter your details, then the 6-digit code emailed to you. Passwords are 8 characters or more.
  2. You land on Overview: live counts of subjects, codes issued, authentic scans, warnings and failures, plus recent activity.
  3. Set your timezone in Profile — every date in the dashboard follows it.

Dashboard overview

Overview — live totals and recent activity.

The core workflow, in four steps:

  1. BrandsNew brand. Add a logo, and request the verification badge — once an administrator approves it, customers see a green check beside your name.
  2. ProductsNew: name it and pick its brand. (Assets and Contents work the same way.)
  3. Open the product and add an item — your own batch reference, dates and unit value.
  4. Open the batch and choose Issue Codes: pick the code type and a quantity between 1 and 1000. For contents, upload files instead — each file becomes one certified code.

Issued codes

The minted codes — copy, view the QR, or archive any one of them.

Open the issuance and choose Documents. Generate a PDF — one sticker per code, with QR, product, batch, price and expiry — or a CSV listing every code for a printing partner. Both are available per language and stay downloadable afterwards.

A generated sticker

One print-ready sticker per code.

The CSV export

The CSV — every code with its details.

Operations lists every verification and transfer — who, when, what result and where — filterable, and plottable on a map. Look for clusters of failures in places you do not sell.

Operations map

Verifications where they happened.

Warnings flags codes verified more often than the ceiling you set in Profile (25 by default). Review each one against Operations, then Dismiss it if the activity is legitimate, or Block the code — which archives it, so it stops verifying at once. Both decisions can be reverted.

Requirements

Any current desktop or mobile browser, kept up to date. The interface is responsive and works on a phone, though the code tables and the map are far more comfortable on a laptop.

BrowserMinimum version
Google Chrome / Microsoft Edge107
Mozilla Firefox104
Safari (macOS / iOS)16

JavaScript and cookies-equivalent local storage must be enabled. No plug-ins or extensions are required.

Installation & access

Nothing is installed. Open the AuthPlus address supplied by your organisation and choose Get started, or go straight to /dash. You will be asked to sign in (Signing in).

The dashboard and the verification app are two areas of one product, and you can move between them at any time:

  • In the dashboard, the scan icon in the top bar opens the verification app — useful for checking one of your own codes exactly as a customer would.
  • In the verification app, the grid icon at the top opens the dashboard. You will be asked to sign in if you are not already.

On Android, the app opens on the verification screen; in a browser, the same address opens the dashboard. Both contain both areas.

Dashboard tour

Where everything lives, and what the first screen is telling you.

Dashboard overview with statistics and recent activity

Overview — live totals and the latest activity.
CardCounts
SubjectsProducts, asset categories and content categories you have registered.
Codes issuedEvery authenticity code you have minted, across all issuances.
AuthenticScans that returned a clean authentic verdict.
With warningsScans that were authentic but flagged — repeat checks, custody conflicts, over-verification.
Non-authenticScans that failed: unknown codes, or codes you have withdrawn.

Recent activity lists the five most recent verifications and transfers, each with its result and the place it happened. For the full list, use Operations.

ElementPurpose
SidebarOverview, Brands, Products, Assets, Contents, Verifiers, Operations, Warnings — and, for administrators, more (Administrator overview).
Warnings badgeA red count of unresolved warnings. It is hidden when there are none.
Search fieldSearches brands, subjects, items and codes at once. Type at least two characters.
Scan iconOpens the verification app, to check one of your own codes as a customer would.
Language / themeInterface language and light or dark appearance.
Avatar menuProfile and Sign out.
Version, bottom-leftThe AuthPlus release you are using — quote it when contacting support.
  • Search and filters sit above every table, including a date range on most.
  • Status filter — lists show Active records by default. Switch it to see archived ones.
  • Breadcrumbs at the top of detail screens climb back up the chain.
  • Pagination shows 25 rows per page by default.
  • Archive rather than delete — see Archiving — nothing is ever deleted.

Brands

The first thing to create: everything else hangs off a brand.

Purpose. Register the name that will appear to anyone verifying your products.

  1. Open Brands and select New brand.
  2. Enter the Name — required, and shown on every verdict screen.
  3. Add a Description (optional).
  4. Select Create.

Expected result. The brand appears in the list with status Active and can immediately be chosen when creating products.

Brands list

The brands list.

New brand dialog

Creating a brand.

Open the brand and use Add logo. The logo appears next to the brand name on verdict screens, which is a strong trust signal for customers.

RequirementValue
FormatAn image file. Non-images are rejected with please upload an image file.
Maximum size8 MB
RecommendationA square image on a transparent or white background reproduces best at small sizes.

Purpose. Obtain the green check displayed beside your brand name on every verdict screen — the visible proof that AuthPlus has confirmed you are who you claim to be.

  1. Open the brand and choose the verification request action.
  2. Add a note explaining who you are, and attach supporting evidence — registration documents, trademark certificates. Images and PDFs are accepted, up to 8 MB each.
  3. Submit. The brand’s status becomes Pending.

Expected result. An administrator reviews the request and approves or rejects it (Brand verification). Once approved, the badge appears everywhere the brand is shown.

StatusMeaning
NoneNo request has been made. No badge is shown.
PendingSubmitted and awaiting review. You cannot submit again while pending.
VerifiedApproved. The green check is displayed to everyone.
RejectedDeclined, with a reason from the reviewer. You may correct the issue and request again.
MessageResolution
Brand is already verified or pending reviewA request is already open, or the badge is already granted. Nothing to do.
Attachments must be images or PDFsConvert the evidence to PDF or an image before attaching.
Name is requiredShown when saving a brand with an empty name.

Editing is immediate and affects what verifiers see from then on. Archiving is the emergency control:

Products

Manufactured goods, organised as product → batch → codes. This is the most common workflow in AuthPlus.

  1. Open Products and select New.
  2. Enter the Name as customers know it — it appears on the verdict screen.
  3. Choose the Brand.
  4. Add a description (optional) and create.

Expected result. The product is listed with counts of its items and codes, both zero for now.

Products list

Products, with their item and code counts.

Purpose. A batch (an item) is the production run that codes will be minted for. Splitting production into batches lets you withdraw one run without touching the others.

  1. Open the product and add a new item.
  2. Enter a Reference of your choosing — your own batch or lot number, shown on the verdict screen and printed on labels.
  3. Optionally record the Manufacturing date, Expiration date, unit Value, and a description.
  4. Save.

Expected result. The batch appears under the product and can have codes issued for it.

Batch detail with issuances

A batch and its issuances.

Products and batches accept images (up to 8 MB each), which help your team identify the right record. One image can be marked as the primary one.

Assets

Unique valuables — art, jewellery, watches, collectibles — where each piece is registered individually and carries a signed ownership certificate.

The structure mirrors products, with different meanings:

LevelFor assetsExample
SubjectA category of valuablesCollector Timepieces
ItemOne individual pieceHERITAGE-1965
IssuanceNormally a single code for that piece1 code
  1. Open Assets and create a category, choosing its brand.
  2. Inside the category, add one item per physical piece, with its reference or serial number and its value.
  3. Issue a single code for it (Issuing codes) and attach the printed certificate to the piece.

Expected result. Scanning that code shows a certificate view with the certification date and the number of ownership transfers, rather than a product view.

Asset categories list

Asset categories.

Contents

Certified files: certificates of authenticity, warranties, official documents, media. Each file becomes one code and carries a fingerprint that makes tampering detectable.

  1. Open Contents and create a category — for example Certificates & Documents.
  2. Add an item per document, with a reference and description.
  3. Issue codes by uploading the files themselves. Each uploaded file becomes exactly one certified code.

Expected result. The file is stored, its fingerprint recorded, and anyone can then confirm the document is genuine — by scanning its code, by checking the file directly, or by pasting a link to it (Verifying assets & documents).

Content categories list

Content categories — one certified code per file.

Issuing codes

Minting the codes that will be printed on your goods.

Prerequisites. A brand, a subject and an item must already exist.

  1. Open the batch (or asset item) and select Issue Codes.
  2. Choose the Code typePublic for anything a customer will scan.
  3. Enter the Quantity: between 1 and 1000 codes.
  4. Select Issue.

Expected result. The issuance is created instantly with that many unique codes, listed and ready to view, download or print.

Issued codes list

The minted codes.
MessageResolution
Quantity must be between 1 and 1000Split larger runs into several issuances.
Item and authcode type are requiredSelect both before submitting.
File subjects require uploaded files; products and assets require a quantityYou are issuing for a content item — upload files instead of entering a quantity (Issuing codes for content).
Object storage is not configuredA server-side setup problem. Contact your administrator — see Troubleshooting.
  1. Open the content item and select Issue Codes.
  2. Choose the code type.
  3. Select the files to certify — up to 1000 files at a time, each up to 8 MB.
  4. Select Issue. The count of files is shown before you confirm.

Expected result. One certified code per file, each bound to that file’s fingerprint.

Open an issuance to see its codes. Each row offers:

ActionWhat it does
Copy codeCopies the code text to the clipboard.
QR codeShows the QR image, with a download button for a single label.
HoldingsShows which verifier currently holds the item, and since when.
OperationsEvery scan and transfer recorded for this one code.
SettingsCode configuration, including ownership transfer for assets and contents.
ArchiveStops this single code verifying, without affecting the rest of the batch.

QR code dialog

Every code has a downloadable QR image.

Purpose. Hand an asset or a certified document to another AuthPlus account — for example when a valuable is sold to a collector who has their own account.

  1. Open the code’s settings from the issuance list.
  2. Enter the recipient’s AuthPlus account email under Transfer ownership.
  3. Confirm.

Expected result. The code moves to the other account, which can then manage it. The movement is recorded and contributes to the provenance count shown on the certificate.

Labels & exports

Turning codes into something you can physically print.

  1. Open the issuance and select Documents.
  2. For a printable sheet: choose a Template and a Language, then Generate PDF.
  3. For a data file: choose a language and Generate CSV.
  4. Generated documents stay listed, with a download button, so colleagues can retrieve them later.

Documents dialog with generated PDF and CSV

Generated documents remain available for download.

A generated PDF sticker

One print-ready sticker per code.

The CSV export as a table

The CSV — every code with its details.
PDF sticker showsCSV columns
QR code · product or subject name · batch reference · unit value · expiry date · code type · the platform label footer text for that languageCode · Product · Batch · Price · Expiration Date — with headings translated into the language you chose
MessageResolution
No print template availableNo label template is configured on the platform. Ask an administrator to add one (Platform configuration).
Kind must be pdf or csvAn internal request problem — reload the page and try again.
Object storage is not configuredDocuments cannot be stored server-side. Contact your administrator.

Managing verifiers

The register of who is allowed to scan your codes in the field.

Verifiers list

Verifier accounts under your ownership.

Everyday profiles — the consumer Public type and, where configured, Reseller — are created automatically by the app, so this page is mostly a register: it shows who can scan for you, their type, username and creation date.

  1. Select New verifier.
  2. Give it a recognisable Name — this is what appears in scan histories, so name it after the shop or the person.
  3. Choose the Type. Only types your role may create are offered.
  4. Set a Username and Password (at least 4 characters), and save.
  5. Pass the credentials to the person who will use them; they add the profile as described in Adding a professional profile.

Archiving a verifier immediately prevents it from verifying anything, while preserving every scan it already made. This is the correct response to a lost device or a terminated partner.

Operations

The complete audit trail: every verification and transfer of every code you own.

Operations table

Operations — the audit trail of your codes.
ColumnMeaning
TimeWhen it happened, in your profile’s timezone.
TypeVerification or Transfer.
ResultThe verdict returned to the verifier.
Subject / KindWhat was scanned, and whether it is a product, asset or file.
CodeThe code scanned.
Created byThe account that owns the code.
VerifierThe profile that performed the scan.
LocationWhere the scan came from, as a place name and network address.

Filters above the table narrow by free text, subject type, result, operation kind, verifier, subject and date range. They combine, so you can isolate, for example, every non-authentic scan of one product last month.

Switch to Map to plot the same filtered set geographically. Each point is a scan, coloured by result.

Operations map view

Map view — verifications where they happened.

Warnings

Automatic alerts on suspicious activity affecting your codes.

Warnings page

The warnings queue.

As a brand owner you see one kind of warning: over-verified codes. A warning is raised when one of your codes has been verified more times than the ceiling you set in your profile (Your verification ceilings) — the clearest automated signal that a code has been copied onto counterfeit goods.

  1. Open Warnings. Pending items are shown by default; the sidebar badge counts them.
  2. Read the entry: which code, which subject, and how many scans it has accumulated.
  3. Cross-check it in Operations — filter by that code and look at where and how often it was scanned.
  4. Decide:
    • Dismiss — the activity is legitimate. The warning is closed; the code keeps working.
    • Block — the code is compromised. It is archived, so it stops verifying at once and any further scan returns This product has been withdrawn.

A closed warning can be reopened later with Revert, which also restores a blocked code.

StatusMeaning
PendingAwaiting your decision. Counted in the sidebar badge.
DismissedJudged legitimate. The code was left active.
ResolvedThe code was blocked.

Getting started

ScreenWhat it does
Owner selectorScopes every page to your own items, one owner, or all owners. Check it first when data looks missing.
UsersCreate accounts (Standard or Admin), change roles, archive. No invitation email is sent — pass the password on yourself.
SettingsPlatform-wide verification ceilings and the footer text printed on every label.
Prohibited namesThe blocklist that flags brand, product and item names for review.
Brand verificationApprove, reject or revoke brand badges. Record why — nobody is emailed the decision.
WarningsEvery kind, including duplicate and prohibited names, with the power to block a record.

Server requirements

Only relevant if your organisation hosts AuthPlus itself.

ComponentRequirementPurpose
ApplicationA single self-contained binary, distributed as a container imageServes the website, the dashboard, the verification app and the API from one process.
DatabasePostgreSQL 18 with the postgis, pg_trgm, fuzzystrmatch and unaccent extensionsStorage; map positions; duplicate-name detection.
Object storageAny S3-compatible serviceLogos, product images, certified files and generated labels. Without it, code issuance is disabled.
PDF rendererThe Typst binary, included in the container imageRenders label sheets, including right-to-left scripts.
Reverse proxyRecommended, terminating TLSThe application itself speaks plain HTTP and expects to sit behind a proxy.
Outbound mailAn SMTP relayOne-time codes. Without it, no one can register or reset a password.

Installing the server

A production installation consists of three containers and a reverse proxy:

  1. Application — the AuthPlus bundle image, listening on its internal port and bound to the loopback interface.
  2. Database — PostgreSQL 18 with PostGIS, on a persistent volume. Not exposed outside the container network.
  3. Object storage — an S3-compatible service on a persistent volume. Its data API stays internal; only the management console is proxied, if at all.
  4. Reverse proxy — terminates TLS, redirects plain HTTP, and forwards the client’s real address so that verification locations are recorded correctly.

Configuration is entirely by environment variables. Database migrations run automatically at startup, and the first superadministrator account is created then from the credentials you supply.

Administrator overview

What administrators get in addition to everything in Part IV.

An administrator is a brand owner with a wider view and a moderation mandate. Every screen described in Part IV works identically; the difference is that you can point them at any owner, and you have five extra responsibilities.

Administrator dashboard with owner filter and extra pages

An administrator's sidebar — note the owner selector and the additional pages.

Scope

Work on any owner's catalogue, or on all of them at once.

§27 The owner filter →

People

Create accounts, grant and remove the administrator role, archive accounts.

§28 User management →

Policy

Platform-wide verification ceilings and the text printed on every label.

§29 Global settings →

Trust

Decide which brands are entitled to display the verification badge.

§31 Brand verification →

Moderation

The full warning queue, the name blocklist, and the power to block a record.

§33 Moderation →

The owner filter

The single control that decides whose data you are looking at.

A standard user always sees only their own records. As an administrator, the Owner selector at the top of the sidebar widens that scope:

ChoiceEffect
My itemsOnly the records you created yourself. The default.
A specific ownerThat user’s catalogue, exactly as they see it. Search the list by name or email.
All ownersEvery record on the platform, from every account.

Owner selector open

My items, all owners, or one specific owner.

The choice applies everywhere at once — brands, products, assets, contents, verifiers, operations, warnings, the statistics on Overview, and the global search. It persists between sessions.

User management

Creating accounts, granting roles, and withdrawing access.

Users list

Users — accounts, roles and status.
  1. Open Users and select New user.
  2. Enter First name, Last name and Email.
  3. Set an initial Password of at least 8 characters.
  4. Choose the Role: Standard or Admin.
  5. Select Create.

Expected result. The account exists immediately and can sign in with the credentials you set.

Create user dialog

Creating a user — name, email, initial password and role.
MessageResolution
An account with this email already existsSearch the list — the account may be archived rather than absent. Restore it instead of creating a duplicate.
A valid email is requiredCorrect the address.
Password must be at least 8 charactersSet a longer initial password.
Role must be ‘admin’ or ‘standard’Choose one of the two offered roles.

Use the role selector on the user’s row. The change takes effect the next time that user’s session refreshes.

Two changes are refused by design:

  • You cannot change your own role — ask another administrator.
  • You cannot change your own status — you cannot archive yourself.

The superadministrator account never appears in this list and cannot be modified from it.

Purpose. Withdraw access when someone leaves, or suspend an account under investigation.

  1. Find the user and choose the archive action.
  2. Confirm.

Expected result. The account can no longer sign in and is marked Archived. Restoring it re-enables sign-in.

Global settings

Platform-wide policy: detection thresholds and label text.

Settings page

Global ceilings and the label footer.

These are the platform’s own thresholds, applied to every code regardless of who owns it. They are separate from the ceilings each owner sets for themselves, and both are evaluated:

CeilingSet byDefaultRaises
Owner ceilingEach user, in Profile25 products · 25 assets · 0 filesA warning the owner sees
Global ceilingAdministrators, here100 products · 100 assets · 0 filesA warning administrators see

Setting a value to 0 disables that ceiling. A single code can trip both and produce two separate warnings — one for its owner, one for the platform.

The footer text is printed at the bottom of every generated PDF label, for every brand on the platform. It is maintained per language, so a French label carries the French text.

Prohibited names

The blocklist that prevents the platform being used to certify things it should not.

Prohibited names list

The moderation blocklist.

When a user names a brand, subject or item, AuthPlus compares that name against this list. A match raises a prohibited warning for administrators to review; it does not block the user’s action outright.

  • Comparison ignores capitalisation, accents and punctuation.
  • A match is raised when the name equals a blocked term, contains one, or is contained by one — so replica matches Replica Watch Co.
  • Entries can be written in English, French or Arabic; the list ships with a baseline covering regulated, illegal and counterfeit-indicating terms.
  1. Add a term with the create action. Duplicates are refused with this name is already on the blocklist.
  2. Edit or remove a term with the row actions.

Brand verification

Deciding which brands may display the green check that customers rely on.

Brand verification review queue

The review queue — approve, reject or revoke.
  1. Open Brands and switch to the Brand verification tab. A red count shows how many requests are waiting.
  2. Open a request and read the owner’s note and attachments — registration documents, trademark certificates.
  3. Decide:
    • Approve — the badge appears immediately, everywhere the brand is shown.
    • Reject — record a clear reason; the owner sees it and may request again.
    • Revoke — remove a badge previously granted.

Control verifiers

Restricted inspection profiles, for enforcement staff and internal audit.

Everyday verifier types provision themselves; Control profiles do not. They are created deliberately and issued to a named person, and they can only verify Control-tier codes.

  1. Open Verifiers and select New verifier.
  2. Give it a recognisable Name — for example Inspector 01. This name appears in every scan history it produces.
  3. Choose Control as the Type.
  4. Set a Username and Password, then save.
  5. Hand the credentials to the inspector, who adds them in the app as described in Adding a professional profile.

Creating a Control verifier

Creating a Control verifier.

Moderation

The full warning queue and the administrative archive.

Administrators see three kinds of warning that owners never do:

KindRaised whenTypical decision
DuplicateA new or renamed brand closely resembles another brand belonging to the same owner — by spelling or by sound.Usually a legitimate variant; dismiss. Block if it looks like an attempt to impersonate.
ProhibitedA brand, subject or item name matches the blocklist (Prohibited names).Judge in context — replica in a model name may be innocent. Block genuine abuse.
Over-verified (global)A code has passed the platform ceiling (Global verification ceilings).Investigate in Operations. Block a code that is plainly being used on counterfeits.

Filters let you narrow by kind, by entity type, by status and by date.

ActionEffect on the recordReversible
DismissNone. The warning is closed and the record stays active.Yes — Revert reopens it.
BlockArchives the offending brand, subject, item or code. It stops verifying immediately, and the archive is marked as administrative.Yes — Revert restores the record and reopens the warning.
RevertUndoes a previous decision and returns the warning to pending.

When an administrator archives a record — directly or through Block — the owner cannot restore it themselves. They see archived by an administrator; only an admin can unarchive it.

Platform configuration

The catalogue that shapes how every brand on the platform works. Visible only to the superadministrator.

PageGovernsNotes
Code typesThe tiers available at issuance — Public, Reseller, Control — each with a code length between 12 and 20 characters, an optional logo, and a default print template.One type is the platform default. Changing a type does not alter codes already issued.
TemplatesThe label layouts used to render PDF stickers.At least one template must exist, otherwise owners see no print template available.
Verifier typesHow verifier profiles behave: which code tier they may verify, whether they self-provision, whether they require location, whether they are limited to one creator’s codes, and which role may create them.This is where the Control type is restricted to the superadministrator.
LanguagesWhich interface languages are offered.
MaintenanceRe-running the baseline setup that installs the default types and templates.Safe to repeat; it does not overwrite your changes.

Security

How AuthPlus protects accounts and codes, and what is expected of you.

MeasureDetail
Password storagePasswords are never stored, and cannot be recovered by anyone including administrators. Only a modern, deliberately slow one-way hash is kept, so a stolen database does not yield usable passwords.
Password rulesMinimum 8 characters. No further complexity is imposed — strength is your responsibility.
One-time codes6 digits, valid for 10 minutes, at most 5 attempts, single use. Requesting a new code cancels the previous one.
Automated-abuse protectionSign-in, sign-up, password reset and every public scan carry an invisible proof-of-work check that makes bulk automated attempts expensive (The invisible anti-bot check).
Role separationOrdinary users cannot reach administrative functions, and administrators cannot alter the superadministrator account.

Signing in creates a session that is renewed silently while you work, so you are not interrupted. Sessions are long-lived by design, so that field staff are not asked to sign in repeatedly.

ActionEffect on sessions
Sign outEnds the session on that device only.
Password reset (from the sign-in page)Ends every session, on every device.
Password change (from your profile)Other devices stay signed in.
Email changeSessions are unaffected.
  • Unguessable. Codes are random, drawn from a 32-character alphabet that excludes easily confused glyphs, and are 12 to 20 characters long. They are not sequential, so knowing one tells an attacker nothing about another.
  • Verified centrally. A code is meaningless on its own — authenticity is decided by the server, not by anything printed on the label.
  • Signed for assets and documents. Certificates carry a cryptographic signature over the record’s identity; altering the record breaks the signature and the verdict becomes Verification failed.
  • Fingerprinted for files. A certified document is bound to a fingerprint of its exact contents, so any modification is detectable.
  • Copy-detection. Because copying a genuine code onto many fakes cannot be prevented physically, AuthPlus detects it statistically through verification ceilings and custody conflicts (Authentic, with a warning).

Before a sign-in, a sign-up, a password reset or a public scan is accepted, your device performs a small computation that proves a real client is present. There is no puzzle, no checkbox and nothing to read.

What you may noticeExplanation
A brief delay before the button respondsNormal, particularly on older devices.
Challenge verification failedThe check expired — usually a page left open a long time. Reload and try again.
Could not fetch verification challengeThe device could not reach the server. Check connectivity.
  • Give each person their own account and their own verifier profile; never share credentials.
  • Keep the number of administrators to a minimum and review the list regularly (User management).
  • Archive accounts and verifier profiles the day someone leaves.
  • Change any initial password set for you by an administrator at first sign-in.
  • Sign out on shared or public computers — closing the tab is not enough.
  • Treat the CSV of issued codes as confidential: it lists valid codes in bulk.
  • Review Warnings and Operations on a regular schedule; nobody is emailed when something suspicious happens (Notifications).

Data & privacy

What AuthPlus records, where it goes, and how long it stays. Read this before deploying the app to customers.

Every completed scan or transfer writes one permanent line to the audit trail:

RecordedDetailVisible to
What was scannedThe code, and the item it belongs to when it is recognisedThe code’s owner, administrators
The resultAuthentic, a warning, or the reason it failedSame
WhenServer timestampSame
WhoThe verifier profileSame
The deviceA stable device identifier, plus manufacturer, model and operating systemSame
WhereNetwork address, resolved town or city, and precise coordinates when location is usedSame
SourceWhen usedPrecision
Device location (GPS)When the verifier type requires it, and permission is grantedPrecise — the actual position of the scan
Network addressOtherwiseApproximate — typically the town or the internet provider’s location
  • Uploaded files — logos, product images, certified documents — are stored unchanged, in their original form. They are not resized or re-encoded, so any metadata they contain (including photograph location data) is preserved.
  • Certified content is additionally fingerprinted, and that fingerprint is what verification compares.
  • When you verify a file from your own device, the file is not uploaded — only its fingerprint is sent. Verifying a link is different: the server downloads the file to fingerprint it.

AuthPlus is built to preserve evidence. The audit trail, in particular, is never edited or removed by the application.

RecordCan be removed?
Operations (verifications and transfers)No — permanent
Brands, products, assets, contents, items, issuances, codesArchived only, never deleted
User accountsArchived only
WarningsClosed, not deleted
Verifier accountsArchived only
Code types, print templates, verifier typesArchived only
Generated label documentsYes — deleted along with the stored file
Prohibited-name entriesYes

Only two things can be removed outright, and neither is a record of anything: a generated PDF or CSV, which you can produce again at any time, and an entry on the prohibited-name blocklist. Everything else is archived.

Records are otherwise kept indefinitely: AuthPlus applies no automatic retention limit, and there is no self-service account deletion. Erasure requests are handled manually by the platform operator.

StoredWhy
A device identifierIdentifies the automatic verifier profile so scan history is continuous.
Verifier profiles and the active oneSo you do not re-enter credentials at every launch.
Sign-in tokensKeeps you signed in to the dashboard.
Language, theme, and the administrator’s owner filterPreferences, per device.

AuthPlus uses no analytics, no advertising and no tracking cookies, and loads no third-party fonts or scripts. The only external call made by the app is the location lookup described in How location is determined.

Removing a verifier profile in the app removes it from that device only; the account and its history remain on the server.

Codes can be exported as CSV per issuance (Labels & exports), and label sheets as PDF. There is no bulk export of operations, catalogue or account data from the interface — an operator with database access can produce one on request.

Notifications

What AuthPlus tells you, and — importantly — what it does not.

AuthPlus sends exactly one kind of email: a one-time code. Every message expires after 10 minutes and asks for nothing else.

TriggerSubjectSent to
Signing upVerify your AuthPlus emailThe address being registered
Signing in with a codeYour AuthPlus sign-in codeYour address
Forgotten passwordReset your AuthPlus passwordYour address
Changing your emailConfirm your new AuthPlus emailThe new address
Changing your password by codeYour AuthPlus password-change codeYour address
SignalWhereMeaning
Red count on WarningsSidebarUnresolved warnings. Hidden when there are none.
Red count on BrandsSidebar, administrators onlyBrand verification requests awaiting a decision.
Brief messagesCorner of the screenConfirmation or failure of the action you just performed. They disappear after a few seconds.
Status chipsBrand pagesVerified, pending or rejected badge status.

Troubleshooting

Symptoms, causes and resolutions, grouped by where the problem appears.

SymptomLikely causeResolution
Invalid email or passwordWrong credentials, or the address is not registered.Re-type carefully. Use Forgot password, or sign in with an email code instead.
Account is not activeThe account has been archived by an administrator.Contact your administrator; only they can restore it (Archiving an account).
No code arrivesWrong address, spam filtering, or the address is not registered.Check spam. Confirm the address. For a sign-in code, remember the request always reports success even for unknown addresses.
Invalid or expired codeMore than 10 minutes elapsed, five wrong attempts, or an older code was used.Request a fresh code and use the newest email.
Challenge verification failedThe page has been open too long.Reload and retry.
Signed out unexpectedlySomeone performed a password reset on the account.Sign in again. If you did not request it, tell your administrator immediately.
SymptomLikely causeResolution
You are not allowed to verify this code typeThe active profile does not match the code’s tier.Switch profile (Switching the active profile). The item is not necessarily suspect.
Select a verifier firstNo profile is active on the device.Open Verifiers and select one.
Camera shows nothing, or is refusedCamera permission denied, or another app holds the camera.Grant camera access in the device settings; close other camera apps; use manual entry meanwhile.
The QR will not readPrint too small, poor contrast, glare, or a damaged label.Improve lighting, hold steady at 10–15 cm, or type the printed code instead.
Stuck on Enable locationThe profile requires a position and none is available.Enable location, allow the permission, and move where the sky is visible (When location is required).
Everything times outNo connectivity, or the device cannot reach the server.Verification always needs a connection. Check the network; on a private installation confirm the device is on the right one.
Verdict says withdrawn for stock you believe is fineThe brand, product, batch, issuance or the owner’s account has been archived.Ask the brand — the withdrawal is deliberate (Archiving — nothing is ever deleted).
SymptomLikely causeResolution
Records are missingThe status filter is on Active, or (administrators) the owner filter is on the wrong owner.Switch the status filter to see archived records; check the owner selector (The owner filter).
Times look wrongNo timezone set on your profile.Set it in Profile (Name and timezone).
Quantity must be between 1 and 1000Too many codes requested at once.Split the run into several issuances.
Please upload an image file / attachments must be images or PDFsUnsupported file type.Convert to PNG, JPEG or PDF, under 8 MB.
Upload fails silently on a large fileThe file exceeds 8 MB.Compress or resize it.
No print template availableNo label template is configured on the platform.Ask an administrator (Platform configuration).
Object storage is not configuredServer-side storage is unavailable, so files and documents cannot be saved.This is an installation problem — contact whoever operates your AuthPlus server.
The map is emptyNo operations match the filters, or none carry a position.Widen the date range and clear filters; remember approximate locations depend on the network.
A page briefly shows a generic errorTransient server or connectivity problem.Use the retry action. If it persists, note the time and contact support.

Frequently asked questions

Do customers need an account to verify a product?
No. The verification app works with no account and no registration, in the mobile app or a browser.
Does verification work without an internet connection?
No. Authenticity is decided by the server, so a connection is always required.
Can I verify a product without the mobile app?
Yes — open the AuthPlus website and choose the verification area. Everything except precise location works the same way.
What if the QR code is damaged?
Type the code printed beside it. Codes deliberately avoid the characters most often confused.
Someone scanned my product before me. Is it fake?
Not necessarily — a batch is normally checked by the factory, the distributor and the shop. What matters is the pattern: many checks, in distant places, in a short time.
How many codes can I issue at once?
Up to 1000 per issuance. Larger runs are split into several issuances, which also gives finer recall control.
Can I reuse or re-issue a code?
No. Every code is unique and permanent. Issue new codes instead.
Can I change a product's name after codes are printed?
Yes — verdict screens show the current details. What is printed on the physical label does not change, so keep the two consistent.
What size should the printed QR be?
Test before the full run. Print one sheet at the final size, on the final material, and scan it with an ordinary phone (Labels & exports).
Can I stop a single code without affecting the batch?
Yes. Archive that one code. Archiving the issuance, item, product or brand affects everything beneath it.
I forgot my password.
Use Forgot password, or sign in with a one-time email code (Signing in).
Can an administrator see my password?
No. Passwords are stored only as an irreversible hash. An administrator can set a new one for an account they create, but cannot read an existing one.
Can two people share one account?
Technically yes, but do not: the audit trail attributes every action to the account, so sharing destroys accountability.
What happens to my products if my account is archived?
They stop verifying — every code you own returns withdrawn until the account is restored (Archiving an account).
How do I get the Admin role?
Another administrator must grant it. It cannot be requested from the interface.
Is my document uploaded when I verify a file?
No. The fingerprint is computed on your own device and only that value is sent. Checking a link is different: there the server downloads the file to hash it.
Can I delete a record?
Records are archived, not deleted, so the audit trail stays intact. Archived records stop verifying and can be restored.
Who can see where a scan happened?
The owner of the scanned code, and administrators. Verifiers see their own history.
Will I be notified if one of my codes is abused?
Not by email or push — a warning appears in the dashboard and the sidebar badge (Notifications).

Glossary

Archive
To withdraw a record without deleting it. Archived records stop verifying and can be restored (Archiving — nothing is ever deleted).
Asset
A unique valuable registered individually and carrying a signed ownership certificate.
Authenticity code (code)
The unique string, printed as text and as a QR symbol, that identifies one protected unit.
Batch
An item under a product: one production run, to which codes are attached.
Brand
The top of the protection chain; the name shown to anyone verifying.
Code type
The tier of a code — Public, Reseller or Control — which decides who may verify it.
Content
A certified file: a document, certificate or media item bound to a fingerprint of its contents.
Custody / holder
Which verifier profile currently holds an item in the field. Moved by a transfer in the app (Transfers & custody).
Fingerprint
A value computed from a file's exact contents. If the file changes, the fingerprint no longer matches.
Issuance
One act of minting codes for an item, and the unit at which codes are printed and withdrawn.
Item
A concrete unit: a batch of a product, one individual valuable, or one document entry.
Operation
One recorded verification or transfer — a line in the audit trail.
Over-verified
A code checked more times than its ceiling allows; the principal automated counterfeit signal.
Owner
The account a record belongs to, and the boundary of who can see it.
Owner filter
The administrator control that chooses whose data every screen shows (The owner filter).
Ownership transfer
Moving a code from one AuthPlus account to another, in the dashboard. Distinct from custody.
Product
A manufactured good produced in quantity, organised into batches.
Subject
The generic term for a product, an asset category or a content category.
Superadministrator
The platform operator's account, which configures code types, templates and verifier types.
Verification ceiling
The number of scans a code may receive before a warning is raised (Your verification ceilings).
Verifier
The identity under which a scan is recorded — a device profile, not a dashboard account.
Verifier type
The template governing a verifier's behaviour: which codes it may check, whether it self-provisions, whether it needs location.
Verification badge
The green check displayed beside a brand whose identity AuthPlus has confirmed (Brand verification).
Warning
An automatic alert on suspicious activity, awaiting a human decision (Warnings, Moderation).

Support

Getting help, and what to include so that help is fast.

  1. Check §38 Troubleshooting — the majority of reports match an entry there.
  2. Reproduce the problem once more and note the exact wording of any message.
  3. Confirm whether it affects one record, one device, or everyone.
DetailWhy it matters
The exact messageDistinguishes between a dozen similar-looking causes.
Date, time and your timezoneLets the team find the corresponding record.
The code, brand or record involvedIdentifies exactly what was affected.
The account and role you were usingMany behaviours are role-dependent.
Web or mobile app, and the deviceCamera, location and storage issues are platform-specific.
The version at the bottom of the sidebarConfirms which release you are running.
A screenshotFaster than any description.
  • Questions about your own catalogue, codes or account — your organisation’s AuthPlus administrator, who can see your records and act on them directly.
  • Everything else — platform faults, installation and configuration questions, and suspected security problems — write to contact@authenticity-plus.com.