How it works
A short guide to the Supplier Trust Registry — what it does, and how the pieces fit together.
What this is
The Supplier Trust Registry lets you evaluate your suppliers against your own criteria and keep a permanent, tamper-proof history of those evaluations. You own and control your registry — nobody else can write to it, not even ChainIntegrate.
Getting started
You need a Universal Profile (the account you sign in with) and an active ChainIntegrate Membership to create your first registry. Sign in from the top of the page — if the Universal Profile browser extension isn't installed, you'll be prompted to get it.
A note on timing: every time you save something — creating a registry, saving your criteria, adding a supplier, saving an evaluation — confirmation can take anywhere from a few seconds to a minute or more. Wait for it to complete before navigating away or trying again; the app shows you the status as it progresses (confirm in the Universal Profile app → saving → done).
Registries
A registry is your own supplier archive, and it stays tied to your profile. Depending on your Membership plan, you can create more than one — useful if you need to evaluate different kinds of suppliers separately (e.g. service providers vs. material suppliers) with different criteria for each.
Bronze 1 registry, up to 5 suppliers, 4 criteria
Silver 2 registries, up to 25 suppliers, 8 criteria, custom registry image
Gold 5 registries, up to 100 suppliers, 1000 criteria, confidential sharing, document attachments
Criteria
Before adding suppliers, you define your evaluation criteria once — for example "Timeliness", "Quality", "Documentation" — and a value range (e.g. 1–10). Every evaluation you write afterwards scores each supplier against these same criteria, so results stay comparable over time. The names of your criteria and the range are always visible to anyone who opens your registry.
Suppliers and evaluations
Add a supplier, then record evaluations for them over time. Each evaluation stores the criteria scores, an optional note, and the date it actually refers to (not just when you happened to record it — handy for entering historical data).
A chart shows how each criterion trends over time, along with the average score of each evaluation, so you can see a supplier's track record at a glance.
Correcting a mistake: use "Correct" on an evaluation. The form opens with the original values; the new evaluation replaces the old one, which stays visible in the history (marked as replaced) but no longer counts in charts and averages. If the original was public, it stays public even if the correction is private.
Public vs. private
Both supplier names and individual evaluations can be marked public or kept private, independently of each other.
- Public data is readable by anyone — permanently, even if you later switch the toggle back.
- Private data is encrypted in your browser before it ever leaves your device, and only whoever knows your secret code can read it again. ChainIntegrate never sees the content, nor the supplier's name.
For the history to be verifiable, a few things remain visible even for private data: that a supplier or an evaluation exists, how many there are and when they were saved, the label of your registry and your criteria. The content itself — names, scores, notes, attachments — can only be read with your secret code.
Sharing: the "Share link" button copies a direct link to your registry. Anyone opening it can view the public content, even without the browser extension and without signing in; private content stays encrypted.
Confidential sharing Gold: on a private evaluation, "Share confidentially" creates a personal link that lets a customer, a certification body or an auditor read that evaluation only — optionally with the supplier name and the attachment — without your secret code and without making anything public. The recipient needs no account or extension, and the page checks that the content is identical to what was originally recorded. The link cannot be revoked: whoever has it can read that evaluation for good, so send it only to the intended person. You can find the links you've created again under the evaluation ("Show links").
Making something public is not reversible in practice: even switching the toggle back later doesn't erase what's already been read and saved by others.
Permanence
Everything you save is designed to last, and that's what makes the history trustworthy. It also means that nothing can really be deleted.
The record of each save — creating a registry, defining criteria, adding a supplier, saving an evaluation — can never be edited or removed afterwards, by anyone, including ChainIntegrate. Mistakes are corrected by adding a new entry, never by deleting the old one.
The content itself (names, scores, notes, documents, images) is stored as files on a shared file network. ChainIntegrate could technically remove a file from its own servers, but anyone who has ever downloaded it — another service, a visitor's browser, a web crawler — could publish the exact same file again, at any time, outside ChainIntegrate's control.
- Public content is stored as plain, readable text — public permanently, from the moment it's saved.
- Private content is stored encrypted — but the encrypted file is just as permanent. "Private" means nobody can read it without your secret code. If your code were ever exposed or guessed, the encrypted content would still be there, waiting to be decrypted: choose a long code that isn't easy to guess.
Nothing you write to this platform — public or private — can ever be guaranteed to be truly and permanently removed. Think carefully before writing or uploading anything.
Your secret code
The first time you write anything private to a registry, you'll be asked to create a secret code. This code — combined with your registry's own identity — creates the key used to encrypt everything private in that registry. There is no way to recover it if you forget it: write it down somewhere safe. A phrase of a few words is better than a single word.
You can reuse the same code across all your registries, or use a different one for each — either way, the actual encryption keys are always different per registry.
Documents and images (Gold / Silver)
On the Gold plan, you can attach a document to an evaluation — it follows the same public/private choice as the evaluation itself. On Silver and above, you can also set a custom image for your registry, to tell multiple registries apart at a glance.
Attached documents and registry images follow the same permanence described above. A document you attach, public or private, can never truly be deleted, exactly like any other content on this platform. The registry image is always public.
Data and trust
Every entry is saved together with a digital fingerprint of its content, so anyone who can read it can check it hasn't been altered since. For private data, the fingerprint also includes a random value hidden inside the encrypted content: it can be checked by whoever knows the secret code, but it can't be used to guess what's written.
For technical readers: saves are transactions on the LUKSO blockchain (the registry is a non-transferable LSP8 token); content is stored on IPFS; private content is encrypted client-side with AES-256-GCM using a key derived from the secret code with PBKDF2-SHA256; fingerprints are keccak256 hashes.
Come funziona
Una guida breve al Supplier Trust Registry — cosa fa, e come si incastrano i pezzi.
Di cosa si tratta
Il Supplier Trust Registry ti permette di valutare i tuoi fornitori secondo criteri tuoi e di conservarne uno storico permanente e non modificabile. Il tuo registro è tuo e lo controlli tu — nessun altro può scriverci, nemmeno ChainIntegrate.
Per iniziare
Serve un Universal Profile (l'account con cui accedi) e una Membership ChainIntegrate attiva per creare il tuo primo registro. Accedi dall'alto della pagina — se non hai l'estensione Universal Profile nel browser, te lo chiederà.
Una nota sui tempi: ogni volta che salvi qualcosa — creare un registro, salvare i criteri, aggiungere un fornitore, salvare una valutazione — la conferma può richiedere da pochi secondi a un minuto o più. Attendi che si completi prima di spostarti altrove o riprovare; l'app mostra lo stato man mano che procede (conferma nell'app Universal Profile → salvataggio in corso → completato).
Registri
Un registro è il tuo archivio fornitori e resta legato al tuo profilo. In base al tuo piano di Membership puoi crearne più di uno, utile se devi valutare tipi diversi di fornitori separatamente (es. fornitori di servizi e fornitori di materiali) con criteri diversi per ciascuno.
Bronze 1 registro, fino a 5 fornitori, 4 criteri
Silver 2 registri, fino a 25 fornitori, 8 criteri, immagine personalizzata del registro
Gold 5 registri, fino a 100 fornitori, 1000 criteri, condivisione riservata, documenti allegati
Criteri
Prima di aggiungere fornitori, definisci una volta i tuoi criteri di valutazione — per esempio "Puntualità", "Qualità", "Documentazione" — e un intervallo di valori (es. 1–10). Ogni valutazione che scrivi dopo valuta il fornitore secondo questi stessi criteri, così i risultati restano confrontabili nel tempo. I nomi dei criteri e l'intervallo sono sempre visibili a chiunque apra il tuo registro.
Fornitori e valutazioni
Aggiungi un fornitore, poi registra le valutazioni nel tempo. Ogni valutazione salva i punteggi per criterio, una nota facoltativa, e la data a cui si riferisce davvero (non solo quando l'hai scritta — utile per inserire dati storici).
Un grafico mostra l'andamento di ogni criterio nel tempo, insieme al punteggio medio di ciascuna valutazione, così vedi lo storico di un fornitore a colpo d'occhio.
Correggere un errore: usa "Correggi" su una valutazione. Il modulo si apre con i valori originali; la nuova valutazione sostituisce la vecchia, che resta visibile nello storico (indicata come sostituita) ma non conta più in grafici e medie. Se l'originale era pubblica, resta pubblica anche se la correzione è privata.
Pubblico e privato
Sia i nomi dei fornitori sia le singole valutazioni possono essere impostati come pubblici o restare privati, indipendentemente l'uno dall'altro.
- I dati pubblici sono leggibili da chiunque — in modo permanente, anche se in seguito rimetti l'interruttore su privato.
- I dati privati sono cifrati nel tuo browser prima ancora di lasciare il tuo dispositivo, e solo chi conosce il tuo codice segreto può rileggerli. ChainIntegrate non vede mai il contenuto, né il nome del fornitore.
Perché lo storico resti verificabile, alcune informazioni sono visibili anche per i dati privati: che un fornitore o una valutazione esiste, quanti sono e quando sono stati salvati, l'etichetta del registro e i tuoi criteri. Il contenuto vero e proprio — nomi, punteggi, note, allegati — si legge solo con il tuo codice segreto.
Condivisione: il pulsante "Condividi link" copia il link diretto al tuo registro. Chi lo apre può consultare i contenuti pubblici, anche senza l'estensione del browser e senza accedere; i contenuti privati restano cifrati.
Condivisione riservata Gold: su una valutazione privata, "Condividi in modo riservato" crea un link personale che permette a un cliente, a un ente di certificazione o a un auditor di leggere solo quella valutazione — a scelta con il nome del fornitore e l'allegato — senza il tuo codice segreto e senza rendere pubblico nulla. Chi lo riceve non ha bisogno di account né estensione, e la pagina verifica che il contenuto sia identico a quello registrato in origine. Il link non si può revocare: chi lo ha può leggere quella valutazione per sempre, quindi invialo solo alla persona interessata. I link creati si ritrovano sotto la valutazione ("Mostra i link").
Rendere qualcosa pubblico non è reversibile nella pratica: anche disattivando di nuovo l'interruttore in seguito, non cancella quello che è già stato letto e salvato da altri.
Permanenza
Tutto ciò che salvi è pensato per durare, ed è questo che rende lo storico affidabile. Significa anche che niente può essere davvero cancellato.
La registrazione di ogni salvataggio — creare un registro, definire i criteri, aggiungere un fornitore, salvare una valutazione — non può mai essere modificata o rimossa in seguito, da nessuno, nemmeno da ChainIntegrate. Gli errori si correggono aggiungendo una nuova voce, mai cancellando quella vecchia.
Il contenuto vero e proprio (nomi, punteggi, note, documenti, immagini) è salvato come file su una rete di archiviazione condivisa. ChainIntegrate potrebbe tecnicamente rimuovere un file dai propri server, ma chiunque lo abbia mai scaricato — un altro servizio, il browser di un visitatore, un crawler web — potrebbe ripubblicare lo stesso identico file, in qualsiasi momento, fuori dal controllo di ChainIntegrate.
- Il contenuto pubblico è salvato in chiaro, leggibile — pubblico in modo permanente, dal momento del salvataggio.
- Il contenuto privato è salvato cifrato — ma il file cifrato è comunque permanente quanto quello pubblico. "Privato" significa che nessuno può leggerlo senza il tuo codice segreto. Se il codice venisse mai esposto o indovinato, il contenuto cifrato sarebbe comunque lì, pronto per essere decifrato: scegli un codice lungo e non facile da indovinare.
Niente di ciò che scrivi su questa piattaforma — pubblico o privato — può mai essere garantito come rimosso davvero e in modo permanente. Pensaci bene prima di scrivere o caricare qualunque cosa.
Il tuo codice segreto
La prima volta che scrivi qualcosa di privato in un registro, ti verrà chiesto di creare un codice segreto. Questo codice — combinato con l'identità propria del registro — genera la chiave usata per cifrare tutto ciò che è privato in quel registro. Non esiste modo di recuperarlo se lo dimentichi: scrivilo da qualche parte al sicuro. Meglio una frase di qualche parola che una parola sola.
Puoi riusare lo stesso codice su tutti i tuoi registri, oppure usarne uno diverso per ciascuno — in entrambi i casi, le chiavi di cifratura vere sono sempre diverse per ogni registro.
Documenti e immagini (Gold / Silver)
Con il piano Gold puoi allegare un documento a una valutazione — segue la stessa scelta pubblico/privato della valutazione stessa. Da Silver in su, puoi anche impostare un'immagine personalizzata per il tuo registro, per distinguere più registri a colpo d'occhio.
Documenti allegati e immagini del registro seguono la stessa permanenza descritta sopra. Un documento che alleghi, pubblico o privato, non può mai essere davvero cancellato, esattamente come qualunque altro contenuto su questa piattaforma. L'immagine del registro è sempre pubblica.
Dati e fiducia
Ogni voce viene salvata insieme a un'impronta digitale del suo contenuto, così chi può leggerla può verificare che non sia stata alterata da allora. Per i dati privati l'impronta include anche un valore casuale nascosto dentro il contenuto cifrato: la può verificare chi conosce il codice segreto, ma non può essere usata per indovinare cosa c'è scritto.
Per i lettori tecnici: i salvataggi sono transazioni sulla blockchain LUKSO (il registro è un token LSP8 non trasferibile); il contenuto è su IPFS; i dati privati sono cifrati lato client con AES-256-GCM, con chiave derivata dal codice segreto tramite PBKDF2-SHA256; le impronte sono hash keccak256.