SupplierTrust

Security and privacy

A badge presents three supplier business fields: the supplier’s name, its status in the source and a valid-until date. A buyer can check each one.

How it is built

What the public sees
Three supplier business fields, with the result, source context and verification details. Keys, status lists and proofs support the check.
Who decides what a claim says
Your department, or the source authority it designates. SupplierTrust shows that decision; it never decides whether a supplier is eligible.
Signing and revocation
Credentials, badges, status lists and receipts are signed with separate keys. When the issuer revokes or suspends a credential, its next check fails wherever the badge appears. How quickly a change in the source record reaches the badge depends on how often the source is read; the test will measure it.
Where it runs
Tests are planned in Microsoft Azure’s Canadian regions, subject to your approval. Signing is designed for a managed key vault, with keys that can’t be exported.
Languages and accessibility
Everything works in English and French. We build to WCAG 2.1 AA, and a formal review is planned during the test.

Tested so far, and still to do

Prototype checks completed in our development environment as of September 25, 2026. Test records and release evidence are available to the Technical Authority on request. Independent assessments are planned as part of a departmental test.

Tested on the prototype

  • The full workflow and its failure cases, with automated tests
  • Revocation, suspension, out-of-date sources and copied badges
  • Database restart, single-use requests, and backup and restore, run locally
  • Signing through a remote key service, using a test service
  • Keyboard and automated accessibility checks, in English and French

Planned for a test

  • An independent security assessment, with serious findings fixed before any public supplier records are loaded
  • A formal accessibility review against WCAG 2.1 AA
  • Independent standards-conformance testing
  • Evidence on the Canadian environment and key custody, for your security team
  • Speed and availability, measured under agreed conditions

Reporting a security issue

Email hello@suppliertrust.ca. Our security.txt has the details. We answer in English or French.

This website

It sets no cookies and runs no analytics, advertising or third-party scripts. Its badge-check code, served from this site, checks our own badge on the About page. See the privacy notice.