Evidence Gateway

Answer the question. Keep the records.

Give approved services signed facts and limited answers from sources your organization maintains. Define what each answer means, what it may reveal, and who may receive it, while keeping the full source record in your own system.

One example: a supplier registration check

Does this supplier have an active business registration?

A government procurement service needs the answer before processing a supplier’s application. The business registry can provide that status while keeping addresses, filing history, and other details out of the response.

Illustrative example with a fictional business registration

Procurement service

Is this business actively registered?

A-1042

Kept by the business registry

Source record

Business registration A-1042
Registration status
Active
Registered address
12 Market Road
Filing history
4 filings

The registry continues to maintain these fields.

Evidence Gateway

A defined answer

Checks permission.
Derives and signs the status.

Returned to the service

Signed answer

Procurement service receives

Registration status
Active
Digitally signedBusiness registry

The service checks the issuer, signature, and validity dates before use.

Kept at source Address, filing history, and other source fields.

Audit The request and its outcome are recorded.

The digital signature acts as a seal: the service can check that the expected issuer produced the answer and that it has not been altered. The procurement service remains responsible for deciding what that answer means for the application.

An answer both teams understand

Agree the question, the source, and who may ask.

An answer can confirm adult status, report registration status, or return a residence region. The registry team and receiving services agree what each answer means. Evidence Gateway applies those definitions and the organization’s access rules to each request.

Define the answer and its source

Choose the source information and how to derive the permitted answer. Return only the defined facts, such as a residence region without the street address, or adult status without a date of birth.

Limit who may ask

Authorize services for defined answers and agreed purposes. Evidence Gateway checks that permission before consulting the configured source and records the outcome of the request.

Keep answers current

Set how long an answer is valid. Your team keeps the source current and defines how its age is checked; the receiving service verifies the answer’s dates and signature before use.

How it fits your organization

Keep maintaining the register where it is.

Evidence Gateway can use an existing source. Your organization keeps ownership of its records, continues to maintain them in its current system, and decides which services may receive each answer.

Using Evidence Gateway does not require Base Registry Engine. If you choose both, your technical team configures the connection between them.

Your registry team defines the answers
Agree what each fact means, its permitted uses, and the source responsible for the underlying information. The same source can support different defined answers for different services.
Your technical team connects the source
Configure how Evidence Gateway reads the necessary information, checks requests, and signs answers. Your team operates the service and manages its access rules.
The receiving service makes its decision
Its team verifies the answer and decides how to use it alongside its own rules and other information. Your organization remains responsible for the decisions its services make.
Answers a person can carry, from systems you already run
An answer can also be issued as a credential a person keeps in a digital wallet and presents to other services. Health information systems and civil registration systems can serve as sources. Tutorials show a credential from a health record and a birth certificate credential from OpenCRVS.

For developers and implementers

Request and verify your first signed answer.

The introductory tutorial asks “Is this person an adult?” Run a synthetic source, define the question, and verify the signed answer without returning the person’s name or date of birth.

Run the adult-status tutorial →

Read the product documentation →
Source connection
The tutorial supplies a local source. An institutional HTTP source needs a reviewed configuration describing the connection and how to derive the answer.
Answer and verification
The tutorial covers signed JWS and SD-JWT VC assertions. The receiving service verifies the expected issuer, signature, request binding, and freshness.
When a service needs selected fields
Registry Relay supplies permitted data fields for services that need more than an answer to a predefined question.

Work with us

Get help when you need it.

Get hands-on help through a paid implementation pilot, or ongoing support while your team builds and runs the solution.

Implementation and support