Trust Registry
Trust Registry

Establish, govern, and prove trust at scale.

Define who is trusted, control who can verify it, and maintain a defensible audit trail for every decision, all from a single platform.

Your source of truth for digital trust decisions

Trust Registry acts as your source of truth for digital trust decisions, enabling relying parties to verify whether a credential issuer is authorised to issue specific claims via TRQP (Trust Registry Query Protocol).

Beyond simple verification, it introduces enterprise-grade governance over how trust is established, queried and audited across your ecosystem.

Impact

Reduce fraud exposure, accelerate partner onboarding, and demonstrate compliance with verifiable governance.

Publish with ownership

Publish and manage trust records with clear, accountable ownership, replacing fragmented spreadsheets and shared logins.

Enforce query access

Apply consistent access policies across HTTP and DIDComm channels, so only authorised parties can resolve trust.

Capture decision history

Keep a complete, auditable history of every published record and every query answered, ready for review.

What the Trust Registry does

Seven capabilities work together to give every trust decision the right governance, control and audit.

Trust record management

Maintain an authoritative, up-to-date trust dataset that reduces verification ambiguity and operational friction.

  • Authoritative dataset
  • Record lifecycle
  • Verification readiness

Admin and access management

Eliminate shared credentials and enforce accountable, role-based governance over who can publish and manage records.

  • Role-based access
  • Operator accountability
  • Least privilege

TRQP query protection

Prevent unauthorised access and reduce exposure to misuse or scraping with strong protections on every query.

  • Query hardening
  • Anti-scraping controls
  • Unauthorised access prevention

Policy and DID governance

Align trust decisions with organisational and regulatory policies, anchored to verifiable identifiers and credentials.

  • DID-based trust
  • Policy enforcement
  • Regulatory alignment

Audit logging

Provide evidence for audits, disputes, and compliance requirements with tamper-evident records of every decision.

  • Tamper-evident logs
  • Compliance evidence
  • Dispute support

Runtime configuration

Adapt quickly to regulatory or business changes without engineering overhead or redeployment.

  • Policy updates
  • No redeploys
  • Operational agility

Dual channel surface

Enable both enterprise integrations and decentralised, machine-to-machine trust ecosystems over HTTP and DIDComm.

  • HTTP APIs
  • DIDComm
  • Machine-to-machine trust

How the Trust Registry sits between issuers and verifiers

Issuers publish authoritative trust records. Relying parties query those records through TRQP, with policy, identity and audit applied in one place.

Verify trust the moment it matters

Trust Registry runs in the background of existing workflows, making credential checks instant, reliable and audit-ready across borders.

In practice

Real-time, cross-border verification during hiring and onboarding

When a candidate presents a credential, the customer’s system instantly checks an authoritative trust registry via TRQP to confirm that the issuing organisation is officially recognised and allowed to issue that credential. The answer comes back in real time, with no manual verification, no back-and-forth with institutions and no prior bilateral integrations.

For the business, decisions that used to take days, and carried risk and uncertainty, become instant, reliable and policy-compliant. The same flow works across jurisdictions, so a credential issued in one country can be verified against its home registry from anywhere in the world.

  • Real-time verification
  • No manual review
  • Audit-ready by default
  • Cross-border ready

Built for cross-border ecosystems

Trust decisions follow the credential, not the jurisdiction.

  • Verify issuers from any region against their home registry
  • Skip bespoke bilateral integrations per country
  • Make cross-border hiring, onboarding and data sharing repeatable

Integrates into existing workflows

Plug into the stack you already run, with no parallel infrastructure.

  • Query via simple HTTP APIs or cached data
  • Works for credential checks, API data sharing and AI agent flows
  • Practical to deploy and reliable in production

Open source, with a clear path to production

Trust Registry ships as open-source code you can read, run and extend. Follow the guide to stand up your own registry and start serving TRQP queries.

Get started with Trust Registry

Step-by-step setup, deployment notes and integration patterns for running Trust Registry against your own data.

Read the guide

Three components, one trust network

Trust Registry is the source of truth. Trust Resolver answers trust questions in real time. Trust Community is the governance layer that decides who belongs. Adopt one component first, then add the others as your ecosystem grows.

Runtime trust queries for verifiers.

  • Sub-second TRQP authorization endpoints
  • Federated cross-registry resolution
  • Real-time revocation propagation
Coming soon

Multi-stakeholder governance and federation.

  • Consortium governance workflows
  • Cross-border policy alignment
  • Trust chain resolution across communities
Coming soon

Ready to operationalise trust?

Trust Registry is in closed beta. Talk to us about your governance and verification needs.

Join our Early Access

Sign up for a free trial of Trust Registry and start building your governance layer.

Request Early Access

Book a demo

Discuss pilot scope, compliance needs and deployment topology with our team.

Schedule a Demo

Explore the docs

See deployment guides, API references and the open-source quickstart.

View Documentation

Cookie Preferences

We use cookies to enhance your experience. You can manage your preferences below. For more information, read our Cookie Policy.

Strictly Necessary Always Active

These cookies are essential for core website functions such as security, session integrity, and cookie preference storage. They cannot be disabled.

  • _cf_bm: Distinguishes humans from bots (Cloudflare) · 30m
  • _cfuvid: Ensures secure browsing (Cloudflare) · Session
  • __hs_initial_opt_in: Prevents HubSpot's banner · 7 days
  • _gtm_debug: GTM debug mode (testing only) · Session
Analytics

These cookies help us understand how visitors interact with the site so we can improve content and performance. All data is aggregated and anonymous.

  • _ga, _gid, _gat: Google Analytics · Session – 2 years
  • __hstc, hubspotutk, __hssrc: HubSpot visitor tracking · 13 months
  • __hs_opt_out: HubSpot opt-out preference · 6 months
Marketing & Targeting

These cookies allow us and our partners to serve personalised ads and measure campaign performance.

  • _gcl_au, _gcl_dc: Google Ads conversion tracking · 90 days
  • IDE: Google Display Network personalisation · 1 year
  • _fbp: Meta / Facebook remarketing · 90 days
  • li_gc, _li_fat_id, bcookie: LinkedIn tracking · 1–24 months
  • guest_id, personalization_id: Twitter/X analytics · 2 years