The problem with onboarding a new overseas supplier
You have found an Indian manufacturer with the right price and the right product. Now you have to decide whether they are who they say they are. Traditionally that means slow, expensive due diligence: a registration number you cannot easily check from abroad, a scanned certificate of origin emailed as a PDF, an invoice, maybe a bill of lading — all of which can be edited in a few minutes by anyone with the right software. You end up trusting documents because they look official, not because you have confirmed they are genuine.
For European buyers the stakes just went up. Under CBAM (the EU Carbon Border Adjustment Mechanism) you have to report the embedded emissions of covered goods you import — steel, aluminium, cement, fertilisers, hydrogen and electricity. That means asking your supplier for emissions data and being able to stand behind it. A forged or unverifiable emissions figure is now a compliance problem, not just a commercial one.
AssureLocker's Trade Provenance Pack (TPP) collapses all of this into one link. The exporter shares a single public URL — a provenance page at /provenance/<packId> — and you verify it yourself. The important word is yourself: the trust does not come from us. It comes from public registries and official tools you can run independently.
What is in the pack — WHO, WHERE-FROM, REALISED
A Trade Provenance Pack is organised around three plain questions a buyer actually needs answered, and each component carries an evidence tier that tells you, honestly, how strongly it stands up:
- WHO — the exporter's identity. A GLEIF / LEI (Legal Entity Identifier) you can look up in the global GLEIF public registry, alongside registry-backed DigiKYB identity (GSTIN and related Indian registrations). This is an identity that travels across borders, not just a domestic registration number you have no way to check.
- WHERE-FROM — the trade documents. Each one — a chamber-of-commerce or DGFT-issued certificate of origin, or generically any typed document such as a bill of lading, a GI (geographical indication) certificate, an insurance certificate, or an emissions declaration like a CBAM embedded-emissions statement — is rendered as an OpenAttestation / TradeTrust document and recorded in an immutable registry (hashes only).
- REALISED — where available, e-BRC realised-forex history. This corroborates that the trade relationship is real: foreign exchange that actually returned through a bank, not just orders on paper.
No personal data is exposed in the bundle — only the fields you need to check, plus document hashes and anchor references.

Before the detail, here is the shape of it. You open one link and check each component against its own public authority — the identity against GLEIF, the documents against the TradeTrust verifier, the hash against the public registry. The exporter is never in the loop, and neither, in any load-bearing way, are we.
Verify WHO: check the exporter against the GLEIF registry
The Legal Entity Identifier is a 20-character code issued under a global, ISO-standard system governed by GLEIF. Crucially, it is publicly resolvable. Take the LEI shown on the pack and search for it directly at search.gleif.org. You will see the registered legal name, the legal address, the registration status (you want Issued, not lapsed), and the managing local operating unit. Confirm the legal name and country match the entity you are dealing with.
This is a registry-grade check that has nothing to do with AssureLocker. We surface the LEI; GLEIF confirms it. Alongside it, the DigiKYB identity ties the entity to Indian registries (GSTIN and so on), and the pack shows a DigiKYB composite hash so the identity record itself is tamper-evident.
Verify WHERE-FROM: run each document through the official TradeTrust verifier
Every trade document in the pack is an OpenAttestation file — the open standard behind TradeTrust, the framework used internationally for electronic trade documents. From the provenance page you can open each document and run it through the official oa-verify / TradeTrust verifier. That verifier does two independent things:
- Issuer identity (DNS-DID) — it confirms the document was issued by a domain that genuinely controls it, so you know who put their name on it.
- Tamper check— it recomputes the document's cryptographic hash and compares it to what was issued. If a single character changed, the check fails.
Each document is also recorded in an immutable registry, meaning its hash (never its contents) is written to a public registry, so the integrity record is not something we can quietly rewrite. The honest framing here matters: this makes the documents tamper-evident, not tamper-proof. You can reliably detect alteration; no system can promise no document is ever compromised by any means. Detecting tampering is exactly what protects you against the emailed-PDF problem.
CBAM: what a verifier-attested emissions declaration gives an EU buyer
If you import covered goods into the EU, CBAM requires you to report their embedded emissions, and over time to surrender certificates against them. The hard part is the data: you need credible embedded-emissions figures from the supplier, and you need to be able to show where they came from.
A Trade Provenance Pack can carry the supplier's emissions declaration as a verifier-attested, tamper-evident document — the same OpenAttestation format, with the same independent checks. That is precisely the kind of supporting evidence CBAM reporting calls for: a supplier-provided figure that an independent verifier has attested to, that you can confirm has not been altered, and that is anchored for later audit.
Be clear about the boundary. AssureLocker does not file CBAM on your behalf and does not guarantee CBAM compliance. We do not produce the emissions figure either. What the pack does is carry the supplier's genuine, verifier-attested declaration in a form you and your customs broker can independently check, instead of a bare spreadsheet you have to take on faith.
What the evidence tiers actually mean
The single most useful thing about the pack is that it does not flatten everything into a green tick. Each component is labelled so you can weight it correctly:
- Registry-verified — confirmed against an authoritative public registry (for example the LEI against GLEIF). The strongest tier.
- Verifier-attested — an independent verifier has attested to the document (a typical tier for an emissions or origin declaration that has been checked).
- Issuer-attested — the named issuing authority signed it, and that issuer identity is confirmable via DNS-DID.
- Self-declared, tamper-evident — the exporter declared it themselves, but it is hashed and anchored, so you can at least detect any later change.
- Self-declared— the exporter's own statement, presented as such, with no external corroboration. Treat accordingly.
This honesty is the point. You are not asked to trust a blanket “verified” badge; you are told what kind of evidence each item is, and given the tools to confirm it.
Why this beats PDF-and-email due diligence
Conventional supplier verification is slow because every party re-does it from scratch, and weak because it rests on documents that are trivial to forge and impossible to check from another country. A Trade Provenance Pack inverts that. The exporter assembles the evidence once; you, your bank's trade desk and your customs broker each verify the same link independently, in minutes — the LEI against GLEIF, each document through the official TradeTrust verifier, the realised-forex history as corroboration that real money has moved. Nobody has to trust AssureLocker, because every meaningful check is performed against an external authority.
It is worth stating plainly what AssureLocker is not. We do not issue the certificate of origin, the emissions declaration or the identity; those come from the chamber, the verifier, DGFT, GLEIF and the Indian registries. We do not lend, finance or hold funds. What we do is make genuine, issuer-created documents independently verifiable, and present them with an honest evidence tier so you can decide for yourself.
How to use it on your next India order
Ask your Indian supplier whether they can share a Trade Provenance Pack link. When they do, open the provenance page, check the LEI on GLEIF, run each document through the official TradeTrust verifier, note the evidence tier on each item, and hand the same link to your bank and broker so they can repeat the checks. If you import CBAM-covered goods, confirm the emissions declaration is present and verifier-attested. You will have done real, independent due diligence in the time it used to take to read one emailed PDF — and you will not have had to trust us to do it. See Export Trust for how the pack is built, and remember the only thing worth trusting here is the verification you ran yourself.