Can we show who held the goods, and when?
Chain of custody records who held the goods, when responsibility transferred and on whose authority. Handoffs are signed by the parties and held as proof, and the chain survives a client leaving.
Home / For compliance and quality
For compliance and quality
For the people who answer to auditors, customs, customers and regulators: what is recorded, who can change it, and how you hand it to someone who does not trust you.
Chain of custody records who held the goods, when responsibility transferred and on whose authority. Handoffs are signed by the parties and held as proof, and the chain survives a client leaving.
Operational actions are written to an append-only audit trail, and each entry carries a cryptographic hash so the trail can be checked for alteration. The application itself holds no privilege to alter or delete those entries: an audit trail the application can edit is one an attacker who reaches the application can edit.
Each entry records who acted, when and on which record, including actions taken on your behalf by an agent, which stay attributed to the individual rather than to their company.
Each document is recorded against the movement it belongs to, with a fingerprint of its contents, so long after the shipment has closed anyone can check that a copy is the one that was filed. The file itself stays in your own document store; Cargovate keeps the record of it, not the file.
For manufacturers: serial genealogy runs both ways, so "which finished units contain material from lot X?" is one query. Release is a gate, not a status field: a unit cannot be released while an operation is incomplete, required evidence is missing or a nonconformance is open, and an override is a recorded disposition with a named signer.
From within the product you can export your audit trail and a shipment's compliance record. If you need a complete copy of your organisation's data, ask us and we will provide it.
That is what the optional anchoring module is for. When it is enabled, a fingerprint of a record is committed to an independent ledger; only the fingerprint is published, never the record itself. It is not switched on by default, and it needs a network connection, so an air-gapped site cannot use it. Nothing else depends on it.
For controlled-unclassified or export-control work, the relevant controls are access, audit, identification and authentication, and protection of data at rest, and the air-gapped deployment lets the system boundary be drawn where your assessor needs it. We hold no certification today and will not imply one; ask about a specific control set and you will get a straight answer.
Custody, evidence and the audit trail for a single consignment, in one session.