Identify · Verify · Connect

A code is a link. A VCode is proof.

Point a phone at a VCode and get a verified answer on the spot. You decide what that answer is, who is allowed it, and when it stops working, long after the code is printed.

5 mm

Built for item-level deployment

Real-time

Policy evaluated at the moment of interaction

API + SDK

Integrate rather than replace

Individually addressable

One identity per physical item

Revocable

Stay in control after distribution

Audit history

Evidence and lifecycle context

Featured & referenced across
BBC Forbes Bloomberg Financial Times CNBC The New York Times CNN ITV NBC News The New Yorker Sky Sports Daily Mail The Sun The Mirror Channel 4 People Hello The Scotsman The Business Desk Healthtech World The Hindu Campaign
The technology

From a physical thing to a record you can trust.

The symbol is the doorway, not the room. What makes a VCode useful is everything that happens in the moment between the scan and the answer.

01

Physical object

A product, document, ticket, package or asset carries a VCode — printed, etched or displayed.

02

VCode

The symbol holds no readable payload. It is a reference, unique to that one item.

03

Digital identity

The platform resolves the reference against the record and the rules attached to it.

04

Verify & interact

A decision is returned, an action runs, and the scan is recorded as evidence.

Interactive illustration

Same code. Same image. Different answer.

One VCode, already issued. Change who is scanning it, where and when, then watch the platform decide. This is the part a printed code cannot do.

Scan conditions

Location

Location rule

Time

Validity window

Holder

Identity binding

Platform

Platform rule

The symbol is identical in every case. Only the platform's answer changes.

The same VCode in every scenario
Resolved
Returned
The record this code refers to
Rule applied
All conditions satisfied
Recorded
Scan written to history

Illustrative only — this page does not call the live platform.

Designed beyond the QR code

One was built to link. The other was built to identify.

QR codes do their job well. They were designed in the 1990s to encode data in an image — and that design decision is precisely what limits them when the question is not "where does this go?" but "is this genuine, and should this person be allowed?"

Read the full comparison: VCode vs QR code

Data-carrying codes
  • The payload lives in the image, readable by anyone
  • Fixed at printing. Only a redirect behind it can change
  • A photograph of the code is as good as the code
  • Withdrawing one means breaking the link it points to
  • A redirect can be logged. The scan itself cannot
VCode
  • The symbol is a reference; the data stays server-side
  • What a code means can change after it is printed
  • A copy is refused when it breaks the rules attached to it
  • Any code can be revoked instantly
  • Every scan is recorded, including the ones that fail
Interactive illustration

Decode it yourself.

A code is photographed constantly: by the person using it, by the person behind them, by anyone it is forwarded to. The question that matters is what the photograph is worth afterwards.

What the image itself contains
https://example.com/r/8F2A91C4
  ?ref=8F2A91C4
  &batch=2271
  &type=standard
  • Everything above was inside the picture: no lookup, no permission, no network. Whatever the issuer encoded travels with the image, personal details included.
  • It cannot be changed now. The image was fixed the moment it was printed.
  • The issuer has no idea this just happened.

Illustrative only. The sample payload is invented, and this page does not call the live platform.

The substitution attack

A sticker is all it takes.

Attagging is the crudest attack in the field and one of the most effective. A criminal covers a genuine code with a sticker carrying their own, and everyone who scans it reaches a destination the attacker picked. Nothing is hacked. The sticker was the only thing vouching for the code.

Reports of scammers "covering up QR codes on parking meters with a QR code of their own".

US Federal Trade Commission Consumer alert, December 2023

Action Fraud received 1,386 reports of QR code scams in 2024, against 100 in 2019. Organised crime groups are behind the rise.

BBC News Shared Data Unit, April 2025

Scanning QR codes in open spaces such as stations and car parks "might be riskier", and most QR fraud happens there.

UK National Cyber Security Centre Blog post, February 2024

Fake stickers replacing genuine codes on UK parking payment machines, sending drivers to cloned payment pages.

Forbes August 2024

Every VCode is verified before it resolves.

Attagging works because a QR code carries its own destination, so whoever printed the sticker decides where the scan lands and the phone has no way to tell a substitute from the original. A VCode removes the thing the attack depends on.

  • There is no destination in the symbol. Nothing in the image tells a device where to go, so there is nothing for an attacker to rewrite into it.
  • A valid code cannot be manufactured. A code does not exist until the platform mints it. A symbol produced by anyone else is not an unauthorised code, it is not a code at all, so there is nothing for it to resolve to.
  • Resolution is server-side, every time. The platform is asked what the code means at the moment of the scan. There is no offline path where the printed symbol speaks for itself.
  • The attempt is recorded. A scan that fails is still written to history, so a substitution attempt shows up rather than passing unseen.

To be precise about what this does and does not do: anyone can still physically cover a code with a sticker, and no technology prevents that. What they cannot do is make the substitute resolve to a destination of their choosing. The scan fails instead of quietly misleading someone, which is the difference between a nuisance and a fraud.

Applications

One technology. Many industries.

Wherever a copied, forged or expired code would cause real harm, identification beats linking.

Digital identity

Connect a person or credential to a trusted digital service without exposing the record behind it.

Provenance

Establish where an item came from and what has happened to it since.

Anti-counterfeiting

Give genuine products a verification layer a convincing fake cannot reproduce.

Payments

Link a physical or visual identifier to a transactional workflow.

Ticketing

Issue tickets and credentials that can be checked, limited and withdrawn.

Supply chain

Follow assets through their lifecycle, with a record at every scan point.

Document verification

Bind a printed document to a digital original that can be checked on sight.

Connected packaging

Turn packaging into a verified, measurable digital touchpoint.

Closed loop

Built on the assumption that the symbol will be copied.

Authentic VCodes can only be generated by the platform. Only the VCode app or an approved SDK can resolve one and display what it refers to. Photographing a code yields an image and nothing more.

Validity is decided at the moment of the scan, against rules the issuer sets — including who is presenting the code, where they are, and how long it remains live.

How verification works

Single source of generation

The platform is the only origin of an authentic code, so a code cannot simply be manufactured by an attacker.

Permission-based access

Resolution can be constrained by user, location and other attributes chosen by the issuer.

Evidence by default

Every interaction is recorded, which turns a code from a delivery mechanism into a source of evidence.

Intellectual property

Technology that was ahead of its time.

VCode was founded in the United Kingdom by Louis-James Davis and developed into a working identification platform years before "connected packaging" and "phygital" became industry vocabulary.

VCode and VPlatform are UK registered trade marks. The symbology, the resolution platform and the rules engine are proprietary, and are available for licensing and integration.

Invention

A different premise

Rather than encoding data into an image, VCode was designed from the start as a reference to a controlled record.

Platform

VPlatform

Code generation, rules, actions and scan history were built into a single operational platform with an API.

Applied

Deployed across sectors

The technology has been applied to identity, health credentials, e-voting, ticketing and product authentication.

Today

Foundational layer

VCode now underpins newer products in the same technology ecosystem, including Confrmo.

Technology ecosystem

The identification layer beneath newer products.

VCode is the foundation. The clearest example of what gets built on top of it is Confrmo.

Built on VCode

Confrmo

Runtime identity infrastructure. Verify the human, not the password.

Confrmo proves the authorised human is behind a login, payment, approval or other high-risk action — at the exact moment it happens. A VCode scan is part of how it establishes that the right person is physically present, rather than someone holding a stolen credential.

  • Identity confirmed at the moment of risk, not just at sign-in
  • VCode scanning as the physical-presence signal
  • Drops into systems you already run
Where VCode sits
Confrmo Identity & trust
VCode Visual identification

Identification is the layer everything else depends on. Get that wrong and nothing above it can be trusted.

Questions

The short answers.

What is VCode?

VCode is a visual identification technology. A VCode is a scannable two-dimensional symbol that acts as a secure reference to a record held on the VPlatform, rather than a container that carries its own data. Scanning one asks the platform what the code means, and the platform answers according to rules the issuer controls.

How is VCode different from a QR code?

A QR code carries its payload inside the image, so anyone who photographs it holds everything it contains, permanently. A dynamic QR code can change where its link eventually points, but the image still carries a working destination that resolves for anyone holding a copy. A VCode carries no destination and no readable business payload, so meaning is resolved server-side at the moment of the scan, which is what allows a code to be restricted or revoked after it has been issued.

Who created VCode?

VCode was founded by Louis-James Davis, who also founded Confrmo. The technology has been developed and commercialised in the United Kingdom.

What is VCode used for?

Applications include digital identity, product authentication and anti-counterfeiting, provenance and track and trace, ticketing, access control, document verification, connected packaging, payments and asset identification.

How many unique VCodes are there?

Capacity is not a fixed ceiling. Codes are issued within namespaces, each carrying 72 quadrillion possibilities, and namespaces are added as demand requires, so the system scales rather than running out. The space presently spans approximately 2.2 quintillion identifiers. A code does not exist until it is minted, so identifiers are brought into being on issue rather than allocated from a pre-existing pool.

Can VCode technology be licensed?

Yes. VCode is available for licensing, integration and technology partnership. Integration documentation is provided to approved partners.

How does VCode relate to Confrmo?

Confrmo is a runtime identity platform founded by Louis-James Davis, and uses VCode scanning as part of how it verifies that an authorised human is present at a moment of risk. VCode is the underlying identification layer; Confrmo applies it to identity and trust.

Put VCode to work.

Licence the technology, integrate it into a product, or talk to us about a partnership.