Verify Your Indian Supplier Yourself — Before the Goods Ship

A single public link that lets you, your bank or your customs broker check who the exporter is, where the documents came from, and whether anything has been altered — without taking our word for any of it.

For BuyersAssureLocker Team·9 min read
Published: 28 June 2026

The problem with onboarding a new overseas supplier

You have found an Indian manufacturer with the right price and the right product. Now you have to decide whether they are who they say they are. Traditionally that means slow, expensive due diligence: a registration number you cannot easily check from abroad, a scanned certificate of origin emailed as a PDF, an invoice, maybe a bill of lading — all of which can be edited in a few minutes by anyone with the right software. You end up trusting documents because they look official, not because you have confirmed they are genuine.

For European buyers the stakes just went up. Under CBAM (the EU Carbon Border Adjustment Mechanism) you have to report the embedded emissions of covered goods you import — steel, aluminium, cement, fertilisers, hydrogen and electricity. That means asking your supplier for emissions data and being able to stand behind it. A forged or unverifiable emissions figure is now a compliance problem, not just a commercial one.

AssureLocker's Trade Provenance Pack (TPP) collapses all of this into one link. The exporter shares a single public URL — a provenance page at /provenance/<packId> — and you verify it yourself. The important word is yourself: the trust does not come from us. It comes from public registries and official tools you can run independently.

What is in the pack — WHO, WHERE-FROM, REALISED

A Trade Provenance Pack is organised around three plain questions a buyer actually needs answered, and each component carries an evidence tier that tells you, honestly, how strongly it stands up:

  • WHO — the exporter's identity. A GLEIF / LEI (Legal Entity Identifier) you can look up in the global GLEIF public registry, alongside registry-backed DigiKYB identity (GSTIN and related Indian registrations). This is an identity that travels across borders, not just a domestic registration number you have no way to check.
  • WHERE-FROM — the trade documents. Each one — a chamber-of-commerce or DGFT-issued certificate of origin, or generically any typed document such as a bill of lading, a GI (geographical indication) certificate, an insurance certificate, or an emissions declaration like a CBAM embedded-emissions statement — is rendered as an OpenAttestation / TradeTrust document and recorded in an immutable registry (hashes only).
  • REALISED — where available, e-BRC realised-forex history. This corroborates that the trade relationship is real: foreign exchange that actually returned through a bank, not just orders on paper.

No personal data is exposed in the bundle — only the fields you need to check, plus document hashes and anchor references.

A sample Trade Provenance Pack as a buyer sees it: the exporter's GLEIF/LEI and DigiKYB identity, a Certificate of Origin and an EU CBAM emissions declaration each with an evidence tier, e-BRC realised-forex, and the immutable registry tamper-evidence anchor.
What you open when an exporter shares a link: identity, documents and realised forex, each with its evidence tier. Synthetic demo data.

Before the detail, here is the shape of it. You open one link and check each component against its own public authority — the identity against GLEIF, the documents against the TradeTrust verifier, the hash against the public registry. The exporter is never in the loop, and neither, in any load-bearing way, are we.

How an importer verifies a provenance pack independentlyThe pack's components — GLEIF/LEI identity, certificate of origin, CBAM emissions declaration, e-BRC realised forex and an anchored tamper-evidence hash — are each checked by the importer against an outside authority (the GLEIF registry, the TradeTrust verifier and the public immutable registry), without contacting the exporter or trusting any intermediary.You verify the pack yourselfno call to the exporter · no trust in any intermediaryPROVENANCE PACKWHO · LEI / GLEIFCertificate of OriginCBAM emissions decl.e-BRC realised forexAnchored hashtamper-evidence anchoropen one linkYou / bank / brokerrecompute hash · check signatureGLEIF public registrysearch.gleif.orgTradeTrust / oa-verifyissuer DNS-DID + tamper checkImmutable registryrecompute hash vs anchorExporternot contacted to verifyEvery answer comes from an outside authority —never from the exporter, never from us.
One link opens the pack; you check each component against its own public authority. If a hash or signature does not match, the check fails — and you learn that without ever asking the exporter.

Verify WHO: check the exporter against the GLEIF registry

The Legal Entity Identifier is a 20-character code issued under a global, ISO-standard system governed by GLEIF. Crucially, it is publicly resolvable. Take the LEI shown on the pack and search for it directly at search.gleif.org. You will see the registered legal name, the legal address, the registration status (you want Issued, not lapsed), and the managing local operating unit. Confirm the legal name and country match the entity you are dealing with.

This is a registry-grade check that has nothing to do with AssureLocker. We surface the LEI; GLEIF confirms it. Alongside it, the DigiKYB identity ties the entity to Indian registries (GSTIN and so on), and the pack shows a DigiKYB composite hash so the identity record itself is tamper-evident.

Verify WHERE-FROM: run each document through the official TradeTrust verifier

Every trade document in the pack is an OpenAttestation file — the open standard behind TradeTrust, the framework used internationally for electronic trade documents. From the provenance page you can open each document and run it through the official oa-verify / TradeTrust verifier. That verifier does two independent things:

  • Issuer identity (DNS-DID) — it confirms the document was issued by a domain that genuinely controls it, so you know who put their name on it.
  • Tamper check— it recomputes the document's cryptographic hash and compares it to what was issued. If a single character changed, the check fails.

Each document is also recorded in an immutable registry, meaning its hash (never its contents) is written to a public registry, so the integrity record is not something we can quietly rewrite. The honest framing here matters: this makes the documents tamper-evident, not tamper-proof. You can reliably detect alteration; no system can promise no document is ever compromised by any means. Detecting tampering is exactly what protects you against the emailed-PDF problem.

CBAM: what a verifier-attested emissions declaration gives an EU buyer

If you import covered goods into the EU, CBAM requires you to report their embedded emissions, and over time to surrender certificates against them. The hard part is the data: you need credible embedded-emissions figures from the supplier, and you need to be able to show where they came from.

A Trade Provenance Pack can carry the supplier's emissions declaration as a verifier-attested, tamper-evident document — the same OpenAttestation format, with the same independent checks. That is precisely the kind of supporting evidence CBAM reporting calls for: a supplier-provided figure that an independent verifier has attested to, that you can confirm has not been altered, and that is anchored for later audit.

Be clear about the boundary. AssureLocker does not file CBAM on your behalf and does not guarantee CBAM compliance. We do not produce the emissions figure either. What the pack does is carry the supplier's genuine, verifier-attested declaration in a form you and your customs broker can independently check, instead of a bare spreadsheet you have to take on faith.

What the evidence tiers actually mean

The single most useful thing about the pack is that it does not flatten everything into a green tick. Each component is labelled so you can weight it correctly:

  • Registry-verified — confirmed against an authoritative public registry (for example the LEI against GLEIF). The strongest tier.
  • Verifier-attested — an independent verifier has attested to the document (a typical tier for an emissions or origin declaration that has been checked).
  • Issuer-attested — the named issuing authority signed it, and that issuer identity is confirmable via DNS-DID.
  • Self-declared, tamper-evident — the exporter declared it themselves, but it is hashed and anchored, so you can at least detect any later change.
  • Self-declared— the exporter's own statement, presented as such, with no external corroboration. Treat accordingly.

This honesty is the point. You are not asked to trust a blanket “verified” badge; you are told what kind of evidence each item is, and given the tools to confirm it.

Why this beats PDF-and-email due diligence

Conventional supplier verification is slow because every party re-does it from scratch, and weak because it rests on documents that are trivial to forge and impossible to check from another country. A Trade Provenance Pack inverts that. The exporter assembles the evidence once; you, your bank's trade desk and your customs broker each verify the same link independently, in minutes — the LEI against GLEIF, each document through the official TradeTrust verifier, the realised-forex history as corroboration that real money has moved. Nobody has to trust AssureLocker, because every meaningful check is performed against an external authority.

It is worth stating plainly what AssureLocker is not. We do not issue the certificate of origin, the emissions declaration or the identity; those come from the chamber, the verifier, DGFT, GLEIF and the Indian registries. We do not lend, finance or hold funds. What we do is make genuine, issuer-created documents independently verifiable, and present them with an honest evidence tier so you can decide for yourself.

How to use it on your next India order

Ask your Indian supplier whether they can share a Trade Provenance Pack link. When they do, open the provenance page, check the LEI on GLEIF, run each document through the official TradeTrust verifier, note the evidence tier on each item, and hand the same link to your bank and broker so they can repeat the checks. If you import CBAM-covered goods, confirm the emissions declaration is present and verifier-attested. You will have done real, independent due diligence in the time it used to take to read one emailed PDF — and you will not have had to trust us to do it. See Export Trust for how the pack is built, and remember the only thing worth trusting here is the verification you ran yourself.

Continue reading

See AssureLocker in action

Book a 30-minute walkthrough — bringing verified evidence to your clients.

Book a demo →
AssureLocker
Right Vectors India
3rd floor, Innov8, SKCL Tech Square,
SIDCO Industrial Estate, Guindy,
Chennai, TN 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. Right Vectors India, the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 Right Vectors India. All rights reserved. · Site version: al-20260721-155225-34ff216c8

Aligned with India Stack. Made in India.