Control changes to the register
Base Registry Engine checks who may change a record and whether the change follows your configured rules. It keeps revisions so authorized users can inspect the history through your application.
Security
Registry Stack helps your organization control changes to its records and access to the information it shares. You define the permissions and operate the deployment; the open-source software applies the configured rules.
What the software does
Base Registry Engine and Evidence Gateway address different responsibilities and can be used independently. Each product checks its own access rules.
Base Registry Engine checks who may change a record and whether the change follows your configured rules. It keeps revisions so authorized users can inspect the history through your application.
Evidence Gateway checks permission for a predefined question before reading the source. Registry Relay applies your rules for access to selected fields. Your organization defines those permissions and the information each service may receive.
Evidence Gateway signs its answers. A receiving service can check that the answer came from a trusted issuer, has not been altered, and meets the expected purpose and validity requirements.
The products record audit events for the requests they handle. Evidence Gateway records authorized source access and disclosure before releasing an answer. Your team protects and retains these records for review.
Organizational responsibility
Software controls support the rules your organization has agreed. They work alongside your governance, source systems, and operating safeguards.
You own the records and decide who may maintain them, which services may ask for information, and for what purpose. Your team defines the rules, reviews the configured permissions, and decides how returned information is used.
You host the software in an environment you control. Your operator manages access to the database or source, protects credentials and audit logs, and handles monitoring, updates, and incident response. The software does not send your records or audit logs to Aubex.
Your technical team scopes database accounts, source connections, and network access to the work each deployment needs. The maintained security docs explain the threat model, host protection, key management, and audit retention.
Understanding a signed answer
In an illustrative procurement check, Evidence Gateway consults the configured business register and signs an answer about a supplier’s registration status. The procurement service checks the issuer, signature, intended use, and validity before relying on that answer.
The signature establishes the origin and integrity of the answer. The registry owner remains responsible for the source information; the procurement service remains responsible for its purchasing decision.
Explore Evidence Gateway →For your technical and security teams
Your team and auditors can review the source, verify a release, and use the local tutorials to assess product behavior with sample data. Detailed threat and operating guidance lives in the maintained documentation.
Trust boundaries, request checks, and the controls your operator supplies.
Published security claims and the evidence available to review them.
How to check release assets against signed checksums and inspect the software bill of materials.
The public implementation and its release history for your technical team and auditors.
Coordinated disclosure
Use GitHub private vulnerability reporting so an issue can be investigated before it is made public. We will acknowledge your report and work with you on coordinated disclosure.
For your security team
Evaluate the open-source software with your team, or get paid implementation help and ongoing support.