SecureCode
SecureCode seals a document with a cryptographic signature the issuer controls. Anyone can verify it at one trusted address, in the browser, offline, in seconds.
The single verification address
Built to improve trust, speed, and operational control.
Issuer-signed QR codes that make a document tamper-evident, verifiable in the browser at one trusted address, offline, in seconds.
Give recipients one address to check, instead of a new domain per issuer
Withdraw a document's trust without reissuing anything
The workflow pressure this product is designed to remove.
Issuer-signed QR codes that make a document tamper-evident, verifiable in the browser at one trusted address, offline, in seconds.
A document is only as trustworthy as the recipient's ability to check it. Statements, certificates and payment requests are forged, altered and re-issued, and the usual answer, calling the issuer or trusting a lookalike verification page, puts the burden on the person least equipped to carry it.
The operating capabilities that make the product usable in production.
- Cryptographic issuer signatures, with keys held in Azure Key Vault
- Instant revocation through a published status list, without reissuing the document
- Offline, private verification in the recipient's browser against cached keys
- White-label issuer branding bound to the signing key, not to attacker-controlled data
- Scan-to-pay, with the amount re-derived from the signed token and pluggable providers
- An append-only transparency log, and a one-tap path to report an untrusted document
Where this product fits in live workflow environments.
Statements and certificates
Bank statements, tax certificates and confirmations a recipient must be able to trust at face value, without phoning the issuer to check.
Invoices and payment requests
A verified code confirms the payee and the amount before money moves, with scan-to-pay built in.
Qualifications and credentials
Certificates and letters whose holder and issuer must remain provable long after they are printed.
Official and government documents
Permits, letters and records where a forged copy carries real-world consequences.
How the product fits into live regulated operations.
Sign
The issuer signs the document's details with a private key held in Azure Key Vault. The signature covers the exact values printed on the page.
Seal
A SecureCode QR carrying the signature is placed on the document. Altering any signed value breaks the signature.
Verify
A recipient scans the code and lands on securecode.deistech.co.za. Verification runs in their browser against the issuer's published keys.
What buyers validate before this product moves into rollout.
The code is the trust anchor, not the website
Verification is a cryptographic check against the issuer's published keys, not a database lookup a compromised site could answer differently.
Nothing about the scan leaves the device
Because the token travels in the URL fragment and is checked in the browser, the recipient's scan is not observable server-side.
Revocation without reissue
A published status list can withdraw trust from a code already in circulation, so a mistake does not require recalling printed documents.
One address to verify, by design
Verification always happens at securecode.deistech.co.za. A single, memorable destination is the anti-phishing property. Recipients learn one place to check, and lookalike per-client domains never become the norm. Issuer branding personalises the page; it never replaces the address.
- The signature covers the exact values printed on the page, so altering any signed value breaks it
- The token rides the URL fragment and is checked in the browser, so the code is never sent to a server
- A revoked code still verifies as authentic, but is reported as no longer trusted
- The verified issuer's identity is bound to the signing key, never to anything an attacker can set
Related solutions and supporting reading.
Use these links to move from product capability into workflow fit, operating context, and the supporting material buyers usually need before implementation planning begins.

