Our governance documents, compliance posture, technology, and bylaws — open to every member, regulator, and researcher who wants to verify how the trust fabric is run.
Decisions about the platform are made by an elected board, ratified by the membership, and recorded with minutes that anyone can read.
We talk about a "trust ecosystem" because it names the guarantees — verified, standards-based, auditable — rather than the mechanism. But a transparency page should be plain about the mechanism.
The platform is a cloud-native, serverless application on AWS that resolves GS1 Digital Link identifiers and unifies the EU Digital Product Passport and EPCIS 2.0. Trust comes from a cryptographically verifiable, tamper-evident audit trail — a hash-chained history of every change, independently validated by an external audit log — rather than from a blockchain. The earlier Quorum / OpenDSU approach has been retired. There is no token and no cryptocurrency, and the platform can run as managed SaaS or be self-hosted in your own cloud.
Read the architecture reference →Data minimization by design; encryption with customer-managed keys; least-privilege, role-based access.
Documented Quality Management System with SOPs spanning product SDLC & validation, deviation, document, and identity & access management.
Electronic records and signatures, relating to clinical workflows (AstraEngage platform — coming soon).
The ePI product (AstraLabel) is GMP-qualified for production use in regulated environments.
Patient-facing ePI is assessed against WCAG 2.2 international accessibility standards — text-to-speech, font scaling to 300%, and screen-reader support.
Full per-product control mappings are versioned in the document library.
Named channels — because a transparency page that ends in a dead end isn't one.
GDPR inquiries & data-subject requests, handled by the Data Protection Officer.