Security

Your records. Your rules. Controls you can review.

Registry Stack helps your organization control changes to its records and access to the information it shares. You define the permissions and operate the deployment; the open-source software applies the configured rules.

What the software does

Make each change and disclosure accountable.

Base Registry Engine and Evidence Gateway address different responsibilities and can be used independently. Each product checks its own access rules.

Control changes to the register

Base Registry Engine checks who may change a record and whether the change follows your configured rules. It keeps revisions so authorized users can inspect the history through your application.

Decide what each service receives

Evidence Gateway checks permission for a predefined question before reading the source. Registry Relay applies your rules for access to selected fields. Your organization defines those permissions and the information each service may receive.

Verify where an answer came from

Evidence Gateway signs its answers. A receiving service can check that the answer came from a trusted issuer, has not been altered, and meets the expected purpose and validity requirements.

Review activity

The products record audit events for the requests they handle. Evidence Gateway records authorized source access and disclosure before releasing an answer. Your team protects and retains these records for review.

Organizational responsibility

Keep authority with the people responsible for the register.

Software controls support the rules your organization has agreed. They work alongside your governance, source systems, and operating safeguards.

Your organization sets the rules

You own the records and decide who may maintain them, which services may ask for information, and for what purpose. Your team defines the rules, reviews the configured permissions, and decides how returned information is used.

Your operator runs the deployment

You host the software in an environment you control. Your operator manages access to the database or source, protects credentials and audit logs, and handles monitoring, updates, and incident response. The software does not send your records or audit logs to Aubex.

Your technical team scopes database accounts, source connections, and network access to the work each deployment needs. The maintained security docs explain the threat model, host protection, key management, and audit retention.

Understanding a signed answer

A service can verify the answer before using it.

In an illustrative procurement check, Evidence Gateway consults the configured business register and signs an answer about a supplier’s registration status. The procurement service checks the issuer, signature, intended use, and validity before relying on that answer.

The signature establishes the origin and integrity of the answer. The registry owner remains responsible for the source information; the procurement service remains responsible for its purchasing decision.

Explore Evidence Gateway →

For your technical and security teams

Inspect the software and the evidence behind it.

Your team and auditors can review the source, verify a release, and use the local tutorials to assess product behavior with sample data. Detailed threat and operating guidance lives in the maintained documentation.

Release verification

How to check release assets against signed checksums and inspect the software bill of materials.

Coordinated disclosure

Report a security issue privately.

Use GitHub private vulnerability reporting so an issue can be investigated before it is made public. We will acknowledge your report and work with you on coordinated disclosure.

Machine-readable reporting details in security.txt →

For your security team

Review the detailed security model with your technical team.

Evaluate the open-source software with your team, or get paid implementation help and ongoing support.