secQR
Use cases

Supply Chain Traceability: From Custody to Compliance

31 Jan 2026 · 6 min read

Every supply chain runs on hand-offs, and every hand-off is an act of faith. The plant trusts the carrier, the carrier trusts the warehouse, the warehouse trusts the retailer, and each party records the moment in a system the others never see.

The unit itself carries none of it. By the time a pallet reaches a shelf, the truth about where it has been is spread across four databases, a spreadsheet and a delivery note in a glovebox. When a dispute arrives, reconstruction starts from scratch, months after the facts were cheap to capture.

Where product truth goes missing

Suppose a pallet of finished goods leaves a plant on a Tuesday. The manifest names one carrier; a subcontractor actually collects it. The pallet waits two days in a depot nobody planned for, crosses a border with a re-labelled outer, and arrives looking exactly as the paperwork promises. Nothing in that chain lied to a system, because no system asked. Documents describe shipments and then fall silent.

Diversion lives in these gaps. So do label swaps, unauthorised storage and the custody disputes that surface months later, when a damaged or diverted lot finally reaches a customer who complains.

The scan is the hand-off

secQR treats each custody transfer as a checkpoint with a question attached: whether this unit, in these hands, at this place and time, is expected. Each unit or shipment carries a serialised, signed code. At the hand-off the receiving party scans it. We verify the signature, evaluate the policy for that hop (authorised scanner, expected corridor, plausible time window) and log the outcome either way. A pass is recorded. A refusal is recorded with its reason, which is often the more valuable entry.

Policies treat place and time as first-class inputs rather than metadata. An arrival outside its expected window flags for inspection. A scan outside the approved corridor is refused and escalated. A second scan against a one-time transfer marks the hop as contested. None of this needs continuous tracking hardware; it needs a decision at each checkpoint the chain already has.

The result is one log, ordered by unit, spanning every party: plant to distributor to retailer to customer, each hop stamped with who, where, when and what the policy decided. The log is tamper-evident, so an entry written at hop three cannot be quietly rewritten after a dispute at hop five.

plantdistributorretailercustomerSCAN · TIME · GEO → ONE LOG
Each hand-off from plant to customer is validated at scan time and written to one shared log.

Operations read the log first

The usual objection is that this sounds like an audit programme, and audit programmes are cost centres. The order matters here. The first reader of a custody log is your own operations team on an ordinary Tuesday. Dwell time between hops shows where stock sits idle. Corridor exceptions show which routes drift. A contested hop is an early diversion signal, raised while the trail is fresh. Carriers get compared on evidence instead of anecdote.

The auditor is the second reader. The same log, filtered and exported, answers custody questions without a reconstruction project, because the evidence was written at the moment of transfer by the parties involved. Compliance becomes a view over records that operations already relies on daily.

A hop nobody scanned shows up as silence, and silence in a custody log is information.

The honest costs

Every checkpoint adds a scan, and partners have to perform it. A distributor gains a step at goods-in; a carrier gains one at collection. Adoption is a negotiation, and coverage builds hop by hop rather than overnight. The log stays useful through that build-out precisely because it is honest: a hand-off nobody scanned appears as a gap, and the gap shows where process or incentive still needs work. Some multi-party disputes push teams towards anchoring log segments in an external ledger. Weigh that as an optional pattern once the signed log itself is running, since anchoring adds parties and cost of its own.

Regulation is heading the same way

Unit-level answers are becoming a baseline expectation. GS1's Sunrise 2027 programme expects retail points of sale to scan 2D codes alongside EAN and UPC barcodes by the end of 2027, which places a capable scanner at the final hop of most consumer chains. The EU Digital Product Passport makes the battery passport mandatory from 18 February 2027, with further product categories following under ESPR through to 2030. Each framework assumes a product can answer questions about its own history on demand.

Custody data gathered for operational reasons is the raw material those answers are built from. The practical move is to start where loss already hurts: pick the corridor with the most disputes, instrument its hand-offs, and let the first quarter of log data make the case for the rest of the network.

Regulatory summaries are for orientation only and are not legal advice.