FAQ

Answers to common questions about Registry Stack.

Short answers to the questions program teams, security reviewers, and engineers ask first. For the longer story, each answer links to the page that goes deeper.

What it is

What does Registry Stack actually do?

It helps a registry you already run provide what another service needs without handing over the complete source record. Depending on the agreed need, that can be one signed answer or selected data.

Compare the two solutions →
Do we have to replace our current registry or platform?

No. Registry Stack runs alongside the systems you already operate and reads from the registry source you already keep. You do not have to replace the registry or migrate source records into Registry Stack.

See how it fits →
Can it work with a spreadsheet or a legacy database?

Yes. Registry Stack can read from common files and tables, including CSV, XLSX, Parquet, and PostgreSQL, and provide agreed fields through a read-only API.

See Protected Registry APIs →

Data, security, and privacy

Does our data leave our systems?

The source records stay in the system run by the registry owner. A signed answer or selected data may leave it when the agreed rules allow. Registry Stack is self-hosted, so records and audit logs do not flow to Aubex.

Read the security model →
What happens if a connected service is compromised?

A connected service can receive only the questions and fields configured for it, with rate limits, monitoring, and revocation available around that connection. Broad permissions still carry broad risk, so the agreement should remain narrow.

What the security model covers →
How do AI agents fit in?

An AI-assisted service uses the same defined interface as any other service. It does not receive special access to the source. Registry Stack does not currently sell an AI review or approval product.

See current use cases →

How it fits

How is this different from an exchange layer like X-Road?

Registry Stack is deployed next to the source registry, before the exchange layer. It applies the registry owner’s rules and produces the answer or selected data. An exchange layer such as X-Road can then transport the request and response between institutions.

See how the systems fit together →
How is this different from a foundational ID system like MOSIP?

Identity systems establish who a person is. Registry Stack answers what is true about that person in a specific registry, such as alive, enrolled, or registered, after the identity layer has done its job.

Where Registry Stack sits →
What standards does it use?

It adopts established standards rather than inventing them. Evidence Gateway uses OpenAPI, OIDC, signed JWS, and an optional SD-JWT VC serialization of the same assertion. Registry Relay and Registry Manifest use standards-shaped APIs and metadata. Support differs by standard, so the technical docs carry the exact claims.

The standards we adopt →

Adoption and cost

Is it really free?

Evidence Gateway, Registry Relay, and Registry Manifest are Apache-2.0 open source and can be self-hosted without a software license fee. Aubex charges for pilot design, integration, deployment help, training, upgrades, and support when a team wants that help.

See pilot and support →
Do you charge per person or per assertion?

The open-source software has no per-person or per-assertion license fee. Commercial work is scoped around the pilot, integration, deployment, or support a team asks Aubex to provide.

What paid help covers →
Can we add more questions after the pilot?

Yes. Each new question or data view is configured with the registry owner: agree who needs it, for what purpose, and what can be returned. The same source connection can then support more than the first pilot use case.

What a pilot looks like →
Who uses it today, and is it ready for us?

The products are release-managed, signed, and running in a public hosted lab on synthetic data. For production use, we recommend a scoped pilot with one registry, its first questions or fields, and the required safeguards. Aubex engineers can work directly with the government and its implementation partner.

What a pilot looks like →
Who is behind Registry Stack?

It is built by Aubex. Founder Jeremi Joslin brings experience from OpenSPP. Aubex also participates in Digital Convergence Initiative standards work and has contributed to the GovStack registry building block. The code, documentation, releases, and hosted lab are public for review.

Who is behind this →

More information

Read the technical documentation or contact us to discuss a pilot.