Security + Authenticity

How you can rely on McGesund QR codes

A McGesund QR code carries important information: which company it promotes, whether it is a review code, a product code or a signal code, and how long it is valid. So that no one can rebuild, swap or forge a QR code, every code is cryptographically signed — like a seal that any smartphone can verify. Higher levels add a second, quantum-resistant signature to the seal — optionally even with two independent methods in parallel.

This page explains how that works — step by step, without jargon.

Badges explained

Every review on McGesund can carry one or more badges. At a glance, they show how the review came about and where its trust value comes from.

  • Geo-verified

    The review was submitted via QR code directly on site — the smartphone GPS was within the company's location radius.

  • Display-verified

    The review came in via the reception display — a rotating single-use QR code with a seconds-long TTL, which cannot be photographed for later use or redeemed remotely. Bulk actions are technically limited. More about the display →

  • Quantum-signed

    In addition to the classical signature, this review is signed with a quantum-resistant algorithm (Falcon or ML-DSA). It therefore remains verifiable even once classical algorithms become vulnerable to quantum computers.

  • Blockchain-anchored

    The signing key of this review is anchored in the Bitcoin blockchain via OpenTimestamps. This proves independently of McGesund that the key already existed at the time of anchoring.

  • McGesund-verified

    The review was manually checked and approved by the McGesund team — for example after clarifying proof of identity via a support ticket.

  • Under review

    The review is with the McGesund team for checking — for instance because the geo check was outside the radius or the profile does not yet have a verified owner. The content stays hidden until it is approved.

  • Without crypto signature

    The review dates from before our envelope system (imported legacy data). It cannot be technically checked for authenticity after the fact and therefore does not count towards the overall average.

  • Signature check failed

    The cryptographic check of the review failed — for example due to manipulated bytes, a revoked key or a broken envelope. The review does not count towards the overall average.

Several badges can combine — for example “Geo-verified” + “Display-verified” on the same review. The filters in the directory and on company profiles use the same terms.

What's inside the QR code

Inside the QR code sits a small, signed data package. It contains:

  • which company the code is for,
  • whether it is a profile code, a product code or a signal code,
  • when it was issued and when it expires,
  • a signature that lets any smartphone verify that the data comes unchanged from McGesund.

So while the QR code is readable, any change to its content would break the signature and be exposed on the very first scan.

How a review is verified in the browser

Every review on a company profile has a “Verify authenticity” button. Clicking it shows four green checkmarks, step by step:

  1. Signature valid. The review was signed with a secret key belonging to McGesund — the signature matches its public counterpart.
  2. Content unchanged since the review was submitted. The original text was not secretly altered after being sent.
  3. Post-quantum signature valid. At higher security levels, one or two additional quantum-computer-resistant methods are checked as well (Falcon and/or ML-DSA-87). At the dual-PQ level, each of the two signatures must be valid on its own.
  4. Key anchored in the Bitcoin blockchain. The key used for the signature was provably registered before a specific date — see the next section.

Important: The check runs entirely in the visitor's browser, not on McGesund servers. Even we cannot influence the result.

Classical and quantum-resistant — combined

Every QR code carries a classical Ed25519 signature — fast, compact and globally established. It is embedded in the QR code itself and can be verified by any device directly after the scan, even without internet.

Higher levels add one or two additional post-quantum signatures to this signature — methods that are secure even against future quantum computers. We offer two mathematically independent methods: Falcon (FN-DSA, in two sizes, 512 and 1024) and ML-DSA-87 (NIST primary recommendation from FIPS 204). So that the QR code remains crisply scannable, these signatures are not held in the QR code itself but encrypted in the McGesund backend. When you click “Verify authenticity”, your browser fetches them and verifies them locally.

At the highest level (“dual PQ”), both methods are used in parallel. This keeps the review quantum-resistant even if one of the two methods should ever be broken — no single-algorithm risk.

The practical benefit: you are ready today for the day after tomorrow — and the QR code stays equally small and equally scannable everywhere.

LevelWhat is checked
Standard
Ed25519
Classical signature
Post-quantum (Falcon-512)
Ed25519 + Falcon-512
Classical + quantum-resistant (NIST Level 1)
Post-quantum Max (Falcon-1024)
Ed25519 + Falcon-1024
Classical + maximum quantum level (NIST Level 5)
Post-quantum (ML-DSA-87)
Ed25519 + ML-DSA-87
Classical + NIST primary recommendation (Level 5)
Dual PQ
Ed25519 + Falcon-1024 + ML-DSA-87
Classical + both quantum methods in parallel

The QR code stays the same size and equally scannable at every level — the extra security comes from the McGesund backend, not from the QR code itself. You can see which levels are assigned to your plan in the QR tabs of your profile.

Why we rely on Falcon

Falcon (FN-DSA) is, alongside ML-DSA-87, the second post-quantum signature method selected by NIST and is in the final FIPS 206 standardisation. We nevertheless offer it today already — for three reasons:

  1. Algorithm diversity — Falcon is based on NTRU lattices, ML-DSA-87 on Module-LWE. Both methods are mathematically independent by construction. An attack that breaks one method does not automatically break the other. At the dual-PQ level we use both in parallel — even a complete break of Falcon would leave the review valid via ML-DSA-87.
  2. Data minimisation — At ~666 or 1280 bytes, a Falcon signature is considerably more compact than an ML-DSA-87 signature (4627 bytes), at a comparable security level. This means we store less cryptographic material per QR code on our servers. That fits our principle of collecting and retaining only as much data as is genuinely necessary for authenticity checks.
  3. Faster browser verification — Falcon signatures verify considerably faster in the end customer's browser than ML-DSA-87. Anyone who checks a review's authenticity with a click sees the result noticeably sooner.

If Falcon does not become final after all: Existing QR codes that were signed with Falcon remain functional — after all, they additionally carry the classical Ed25519 signature in the QR itself, which is verifiable offline and independently of Falcon. For the quantum-resistant layer, we would switch affected QR codes server-side to ML-DSA-87; the printed QR does not need to be replaced for that. Ed25519, the Bitcoin anchoring and the review's identity remain untouched in every scenario.

Note on the Falcon variant: The underlying NIST standard FN-DSA (FIPS 206) is in final ratification. Should FN-DSA not be finally standardised, we will switch affected QR codes to ML-DSA-87. The Ed25519 signature and the Bitcoin anchoring of every review remain untouched by this — the authenticity of existing reviews is not lost in any scenario.

The Bitcoin blockchain as a trust anchor

Who checks that McGesund does not secretly swap out a key to make a forged review look “genuine”?

The answer: no one has to trust us. Every key we use to sign reviews, we register in a public digital logbook that no one can alter — the Bitcoin blockchain. Once a key is entered there (which takes 1–2 hours), it is fixed forever from when it existed. Swapping it out afterwards is impossible — that would break the worldwide Bitcoin consensus.

What this gives you:

  • Every single review stores the blockchain block number in which the signing key was anchored.
  • A forgery inserted later would be mathematically detectable — the key would not yet have existed at the time of the entry.
  • External auditors can independently trace the anchoring with standard tools, without having to trust us.
When we create a new keyMcGesund backendKey + descriptionFingerprint (32 bytes)short, unique numberLogbook 1Logbook 2Logbook 3BitcoinBlock~1–2 hBlock number is stored in the key registerBitcoin block height

This is what verification looks like on a profile (example: dual-PQ level)

Authenticity of this review

Classical signature (Ed25519)

Mathematically confirmed by your browser

Post-quantum signature (Falcon-1024)

Mathematically confirmed by your browser

Post-quantum signature (ML-DSA-87)

NIST primary recommendation — additionally confirmed in the browser

Key anchored in the Bitcoin blockchain

Block #826.114 — the key existed no later than 19/05/2026. A subsequent forgery would depend on manipulating Bitcoin consensus.

Content unchanged since the review was submitted

SHA-256 matches the signed value

Submitted on site (geo-verified)

Submitted at the company's location

What does this mean? Your browser recomputed the cryptographic signatures locally — without having to trust McGesund. When all the checkmarks are green, this review is provably genuine and unchanged.

Preview — when you click “Verify authenticity” on a real profile, exactly this check is computed in your browser.

Keys with a lifecycle

Every signing key has a start and an end date. We rotate the keys routinely — newly issued QR codes are signed with the new key, while older QR codes retain their validity because the original key remains available for verification.

For emergencies, we keep additional reserve keys ready that are already anchored in the Bitcoin blockchain. This lets us switch over immediately when needed, without creating a trust gap.

Should a key be compromised, we revoke it — all QR codes from that key's period immediately lose their validity. In that case we inform you and provide new QR codes.

What the signature cannot do

A signature protects against forgery, not against copying — a photographed QR code remains scannable. That is why we work with further layers:

  • Geo-verification for reviews: submissions outside the permitted radius around your location are rejected server-side.
  • Single use for product QRs: after the first review, the code is spent.
  • Revocation function directly in the dashboard: you can deactivate any QR code at any time.

Reception display (Klassik+)

From the Klassik+ plan onwards, you can additionally set up a reception tablet that shows rotating QR codes. Each code is valid only briefly and can be redeemed only once. This creates an additional, on-site-bound authenticity trail that a classic printed QR notice cannot provide.

  • The code changes automatically at short intervals. Anyone who photographs a code and wants to scan it later ends up with an expired code.
  • Scan once, review once: a successful code is locked immediately — reuse is ruled out.
  • Location required at submission: reviews outside the permitted radius do not appear automatically, but go into approval only after manual checking and strict criteria.
  • Tablet pairing revocable at any time: you can lock a lost or retired tablet with one click in the dashboard.

Reviews that come in this way carry the purple “Display-verified” badge — visible on your profile and in the review listing.

The review itself is additionally cryptographically signed when it is saved — regardless of whether it came in via a display or a classic QR code. This means every single review hangs on the same chain of evidence explained in the Bitcoin anchoring section.

Expiry and renewal

Every QR code has its own expiry date (default: two years from issuance). 60 days before expiry you receive an email reminder. After that, you can create and print a new QR code in the dashboard with one click — the old one automatically loses its validity on its expiry date.

If you suspect misuse

If you suspect that a QR code is being misused (for example a notice in a place where it does not belong), simply revoke it in the dashboard via the trash-can icon — existing notices then no longer work. For larger incidents, please get in touch via the support area.

In short: Anyone who scans a McGesund QR code can rely on the fact that the data behind it has not been forged and not been secretly altered — verifiable in their own browser, without having to trust us, with an anchor in the world's largest public blockchain.

Contact