ChainIntegrate · Supplier Trust Registry
Back to app

How it works

A short guide to the Supplier Trust Registry — what it does, and how the pieces fit together.

What this is

The Supplier Trust Registry lets you evaluate your suppliers against your own criteria and keep a permanent, tamper-proof history of those evaluations. You own and control your registry — nobody else can write to it, not even ChainIntegrate.

Getting started

You need a Universal Profile (the account you sign in with) and an active ChainIntegrate Membership to create your first registry. Sign in from the top of the page — if the Universal Profile browser extension isn't installed, you'll be prompted to get it.

A note on timing: every time you save something — creating a registry, saving your criteria, adding a supplier, saving an evaluation — confirmation can take anywhere from a few seconds to a minute or more. Wait for it to complete before navigating away or trying again; the app shows you the status as it progresses (confirm in the Universal Profile app → saving → done).

Registries

A registry is your own supplier archive, and it stays tied to your profile. Depending on your Membership plan, you can create more than one — useful if you need to evaluate different kinds of suppliers separately (e.g. service providers vs. material suppliers) with different criteria for each.

Bronze 1 registry, up to 5 suppliers, 4 criteria
Silver 2 registries, up to 25 suppliers, 8 criteria, custom registry image
Gold 5 registries, up to 100 suppliers, 1000 criteria, confidential sharing, document attachments

Criteria

Before adding suppliers, you define your evaluation criteria once — for example "Timeliness", "Quality", "Documentation" — and a value range (e.g. 1–10). Every evaluation you write afterwards scores each supplier against these same criteria, so results stay comparable over time. The names of your criteria and the range are always visible to anyone who opens your registry.

Suppliers and evaluations

Add a supplier, then record evaluations for them over time. Each evaluation stores the criteria scores, an optional note, and the date it actually refers to (not just when you happened to record it — handy for entering historical data).

A chart shows how each criterion trends over time, along with the average score of each evaluation, so you can see a supplier's track record at a glance.

Correcting a mistake: use "Correct" on an evaluation. The form opens with the original values; the new evaluation replaces the old one, which stays visible in the history (marked as replaced) but no longer counts in charts and averages. If the original was public, it stays public even if the correction is private.

Public vs. private

Both supplier names and individual evaluations can be marked public or kept private, independently of each other.

For the history to be verifiable, a few things remain visible even for private data: that a supplier or an evaluation exists, how many there are and when they were saved, the label of your registry and your criteria. The content itself — names, scores, notes, attachments — can only be read with your secret code.

Sharing: the "Share link" button copies a direct link to your registry. Anyone opening it can view the public content, even without the browser extension and without signing in; private content stays encrypted.

Confidential sharing Gold: on a private evaluation, "Share confidentially" creates a personal link that lets a customer, a certification body or an auditor read that evaluation only — optionally with the supplier name and the attachment — without your secret code and without making anything public. The recipient needs no account or extension, and the page checks that the content is identical to what was originally recorded. The link cannot be revoked: whoever has it can read that evaluation for good, so send it only to the intended person. You can find the links you've created again under the evaluation ("Show links").

Making something public is not reversible in practice: even switching the toggle back later doesn't erase what's already been read and saved by others.

Permanence

Everything you save is designed to last, and that's what makes the history trustworthy. It also means that nothing can really be deleted.

The record of each save — creating a registry, defining criteria, adding a supplier, saving an evaluation — can never be edited or removed afterwards, by anyone, including ChainIntegrate. Mistakes are corrected by adding a new entry, never by deleting the old one.

The content itself (names, scores, notes, documents, images) is stored as files on a shared file network. ChainIntegrate could technically remove a file from its own servers, but anyone who has ever downloaded it — another service, a visitor's browser, a web crawler — could publish the exact same file again, at any time, outside ChainIntegrate's control.

Nothing you write to this platform — public or private — can ever be guaranteed to be truly and permanently removed. Think carefully before writing or uploading anything.

Your secret code

The first time you write anything private to a registry, you'll be asked to create a secret code. This code — combined with your registry's own identity — creates the key used to encrypt everything private in that registry. There is no way to recover it if you forget it: write it down somewhere safe. A phrase of a few words is better than a single word.

You can reuse the same code across all your registries, or use a different one for each — either way, the actual encryption keys are always different per registry.

Documents and images (Gold / Silver)

On the Gold plan, you can attach a document to an evaluation — it follows the same public/private choice as the evaluation itself. On Silver and above, you can also set a custom image for your registry, to tell multiple registries apart at a glance.

Attached documents and registry images follow the same permanence described above. A document you attach, public or private, can never truly be deleted, exactly like any other content on this platform. The registry image is always public.

Data and trust

Every entry is saved together with a digital fingerprint of its content, so anyone who can read it can check it hasn't been altered since. For private data, the fingerprint also includes a random value hidden inside the encrypted content: it can be checked by whoever knows the secret code, but it can't be used to guess what's written.

For technical readers: saves are transactions on the LUKSO blockchain (the registry is a non-transferable LSP8 token); content is stored on IPFS; private content is encrypted client-side with AES-256-GCM using a key derived from the secret code with PBKDF2-SHA256; fingerprints are keccak256 hashes.