Primi Tecnologia: Tracking Products Against Counterfeiting

Counterfeiting drained $85 billion from the US economy in 2025. The physical seal is only a third of the solution—the rest is serialized codes, APIs, and logs.

by Cleverson Gouvêa

Primi Tecnologia: Tracking Products Against Counterfeiting

Primi Tecnologia entered the search radar of Americans the same week the US Chamber of Commerce released a number hard to ignore: $85 billion lost to the illegal market in 2025. It's no coincidence. When counterfeiting makes headlines, companies rush to get seals, traceability, and proof of authenticity—only to discover that the expensive part isn't the sticker. It's the system behind it.

TL;DR

  • Primi Tecnologia is a Brazilian security printing and RFID/IoT identification company, based in Santana de Parnaíba (SP).
  • The illegal market cost between R$ 473 billion (FNCP) and R$ 514 billion (ABCF) in Brazil in 2025—the difference is methodology, not error.
  • Inmetro and GS1 have already pushed traceability digital: seal with QR Code printed by the Brazilian Mint, mandatory unique identification for footwear, and 2D codes at retail by 2027.
  • The physical seal solves maybe a third of the problem. The rest is a verification endpoint, a serialized database, logs, and a customer service channel.
  • If your company sells branded products and doesn't have a public authenticity verification page, you're leaving the answer in the hands of the counterfeiter.

Primi Tecnologia presents itself as a security technology company: it produces holographic seals, authenticity seals, traceability seals, tickets, event wristbands, diplomas, and certificates. It is based in Santana de Parnaíba, in Greater São Paulo, and serves cosmetics, food and beverages, chemical industry, and government agencies.

What separates this type of supplier from a common printing shop is the stack of certifications. Primi Tecnologia declares ISO 9001 (quality), ISO 14001 (environment), ISO 27001 (information security), ISO 45001 (occupational health and safety), and NBR 15540—the specific Brazilian standard for security printing. ISO 27001 in a printing shop is not a footer decoration: it means that your seal file, exactly what the counterfeiter wants, is treated as an information asset with access control and audit trail.

The company also accumulates seven Fernando Pini awards for printing excellence and maintains a line called Primi ID, described as identity management with RFID and IoT. In practice, the label stops being just a seal and becomes an addressable object: radio frequency reading for access control, anti-theft, and material flow.

None of this was born this week. What changed was the context. Counterfeiting became a daily agenda in Brazil, and a technical name that previously only circulated in industry purchasing departments started being searched by people who have never bought a seal in their lives.

It's worth making the distinction that no one makes in the commercial: Primi Tecnologia sells the security item and the radio frequency identification. It does not deliver the website that responds to the consumer when they read the code. That piece is yours—and that's where the project usually stops.

R$ 473 billion or R$ 514 billion? Why the numbers don't match

On August 5, 2026, the National Forum Against Piracy and Illegality (FNCP) released that the illegal market—smuggling, counterfeiting, piracy, and tax evasion—caused losses of R$ 473 billion in Brazil in 2025, adding industry losses and tax evasion across 15 sectors. That's a 64% increase in five years.

Three months earlier, on May 27, the Brazilian Association for Combating Counterfeiting (ABCF) published the 2026 Counterfeiting Yearbook with another value: R$ 514 billion in 2025, 8% above 2024. The ranking by sector:

Sector Estimated loss in 2025
Alcoholic beverages R$ 89.5 billion
Apparel R$ 55 billion
Fuels R$ 30 billion

The difference between the two studies is not a contradiction: they are different sectoral scopes and methodologies. Use either one, but cite the source. And be wary of any supplier that throws a round number in a sales pitch without saying where it came from.

The most uncomfortable data from the ABCF yearbook is the estimate that 36% of alcoholic beverages sold in the country are counterfeit. Between September and December 2025, the methanol poisoning outbreak resulted in 22 confirmed deaths. In this sector, traceability stopped being a marketing topic and became a matter for autopsies.

Real traceability has three layers

Serious suppliers like Primi Tecnologia deliver the first layer well, and the marketing material usually stops there. Those who have already implemented know there are three layers, and the third is the one that breaks schedules.

Physical layer: making copying expensive

Hologram, reactive ink, microtext, tamper-evident seal that shatters on removal. The goal was never to be impossible to copy—it was to make the copy too expensive to be worth it. Counterfeiters are economic agents: they abandon the product when the margin disappears.

Identification layer: each unit with a unique code

This is where most go wrong. A beautiful seal identical across a million units doesn't track anything—it only confirms that someone bought seals. Traceability requires serialization: a unique number per unit, encoded in QR Code, DataMatrix, or RFID/NFC chip, with a map of which series went to which batch, which distributor, which state.

Digital layer: the endpoint that answers "is it original?"

The consumer points the camera. Something needs to respond in under two seconds. That "something" is an API, a database, and a public page—and it's exactly the piece no one budgeted for. It's worth remembering that this endpoint becomes a target: it's software exposed on the internet, with all the supply chain risk we discussed in the case of NPM packages infected by Shai-Hulud.

Inmetro and GS1: the regulatory calendar has already started

Anyone who thinks they can delay needs to look at the dates. Inmetro replaced the traditional conformity seal with a digital model, with QR Code printed by the Brazilian Mint and verification via the free app "Inmetro Na Palma da Mão", which shows manufacturer, technical standards, and validity. The first phase covered motorcycle helmets, fire extinguishers, and CNG cylinders, with lamps, electrical wires, auto parts, mattresses, lighters, and pressure cookers in line.

In footwear, Ordinance No. 459/2025 made unique product identification mandatory. The original deadline was July 31, 2026, and was extended, at the request of Abicalçados, to December 31, 2026—news published on August 3, 2026.

Front Requirement Deadline
Inmetro (phase 1) Digital seal with QR Code from the Mint In effect
Inmetro — Ordinance 459/2025 Unique identification of footwear 12/31/2026
GS1 Sunrise 2027 GS1 standard QR Code read at POS End of 2027
PL 3375/24 (Chamber) Penalty of 2 to 4 years for trademark counterfeiting In progress

The GS1 Sunrise 2027 initiative is the most structural: by the end of 2027, the 2D code must be universally scannable at the point of sale, alongside the traditional EAN-13. While EAN carries only the GTIN, the GS1 standard QR Code carries batch, expiry, origin, and a link for the consumer. It's the definitive fusion between label and web page.

In the criminal field, PL 3375/24, approved in committee in the Chamber, raises the penalty for improper reproduction of a registered trademark from three months to one year to two to four years.

The takeaway for manufacturers is direct: the seal that Primi Tecnologia and its competitors print will come with a mandatory unique code, and someone will need to answer for that code on the internet.

Where projects stall: the software

I've seen the script repeat. The company signs the seal contract with Primi Tecnologia or a competitor, receives the rolls, applies them on the production line—and only then discovers that the QR Code needs to point somewhere. Then comes improvisation: a spreadsheet on Drive, a link to the brand's Instagram, a static page that says "original product" for any code, including invented ones.

A page that always answers "original" is worse than having no page. It teaches the consumer to trust a test that tests nothing, and gives the counterfeiter a free stamp of approval.

The minimum digital layer that works has five pieces: a database with the serialized codes issued, a query API with rate limiting, a public result page, a record of each reading (date, time, IP, approximate geolocation), and an internal alert dashboard. The log is the most underestimated asset of the set: if the same code was read 4,000 times in nine states in the same month, you don't have a very popular original product—you have an industrial-scale clone, and you know where it is.

That dashboard is a security system like any other, with the same credential and audit requirements we discussed when analyzing the attack via malicious VS Code extension on GitHub.

How to build the digital layer in six steps

Suppliers like Primi Tecnologia handle the physical side well. The order below is what's usually missing on the software side, and it applies to both industry and e-commerce brands that outsource production.

  1. Define granularity before buying seals. Tracking by batch is cheap and detects channel diversion. Tracking by unit is expensive and detects cloning. These are different and irreversible decisions after purchase.
  2. Generate the codes yourself, not the supplier. Use non-sequential, non-guessable identifiers (UUIDv4 or truncated hash). A numeric sequence is an invitation: the counterfeiter prints 1 to 100,000 and gets them all right.
  3. Deploy the verification endpoint before the first roll. Short URL, HTTPS, response in under two seconds, working on poor 3G. If the consumer needs to install an app, the verification rate plummets.
  4. Write the negative response carefully. "Code not found" is not the same as "counterfeit product". Explain what to do, offer a contact channel, and capture a photo of the product.
  5. Log everything and alert by default. Repeated readings, readings outside the distribution region, sudden spikes. An automated agent—along the lines of what we described in AI agents for businesses—handles the initial triage without human on-call.
  6. Close the loop with legal. Logs with date, time, and location become evidence. Agree in advance with whoever will use it: format, retention, and chain of custody.

Five mistakes that kill a traceability project

  • Identical seal on everything. Without serialization, there is no traceability—there is decoration.
  • QR Code pointing to the site's homepage. The consumer doesn't want to learn about the brand; they want to know if the bottle in their hand is genuine.
  • Verification behind a login. No one creates an account to check a jar of cream. Verification is public or it doesn't happen.
  • Ignoring repeated readings. It's the cheapest and most reliable sign of cloning, and almost everyone throws it away.
  • Treating the dashboard as a marketing project. It's security infrastructure. It needs backup, access control, and a named responsible person.

WhatsApp: the channel where reports actually arrive

QR Code verification answers yes or no. What comes after—"I bought it at such store", "the box was tampered with", "I have a photo"—needs a conversation. In Brazil, that conversation happens on WhatsApp.

A flow that works: the negative result page opens WhatsApp with a pre-filled message containing the scanned code. The consumer just hits send. On the other side, customer service already receives the context and asks for photos. In two weeks, you have a map of suspicious points of sale that no field audit would deliver in the same timeframe.

For relevant volume, this requires the official API, not the common app—the difference between the two models is detailed in WhatsApp Business App vs Official API. With the official API, you can automate triage, classify by region, and trigger internal alerts when the same address appears three times.

Where to start

If the topic reached you because of Primi Tecnologia or any other security printing supplier, the recommendation is simple: ask for two separate quotes. One for the seal, another for the digital layer. Compare the timelines. If the digital layer isn't ready when the roll arrives, delay the seal purchase—not the other way around.

A good security printing supplier, whether Primi Tecnologia or any other, will ask you what granularity you want to track. Arrive at the meeting with the answer ready and with the verification endpoint already specified. That single change in order saves months.

At Agathas Web, I've been developing custom systems for industry, education, and services since 2008, and the architecture of an authenticity verifier is well-known: serialized database, public API with rate limit, lightweight page, and WhatsApp integration. The hard work isn't technical. It's deciding, before printing a million stickers, what exactly you want to be able to prove.