TradeTrust

Trust Infrastructure

TradeTrust is an open-source framework from GovTech Singapore for issuing and verifying trade documents as electronic transferable records, built on W3C Verifiable Credentials and DIDs with title transfer and selective redaction. It is a candidate trust infrastructure building block, aligned with UNCITRAL MLETR for cross-border legal recognition.

Verifiable trade documents
electronic transferable records (ETR)
W3C VC
DID
document attestation
title transfer

All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.

15 of 18 checks met

3 partially met

Layer 1

Recognised DPG

Layer 2

DPI Relevance

Layer 1 Recognised Digital Public Good

Listed in the DPG Registry.
VerifiedVerified DPG logo

Layer 2 DPI Relevance

Does it provide a foundational DPI function, reusable across sectors, at population scale?

Domain fit
Cross-sector reuse
Population scale
3/3

Document attestation built on W3C VC and DID standards places it in the Trust Infrastructure domain. The attestation framework is reusable for any document type even though trade is the primary use case, and it is designed for international trade at global scale.

Layer 3 DPI Architecture Alignment

How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.

A · Interoperability

3/3

Can other systems connect without modifying the core, using documented open standards?

External API docs
Open standards
Open data formats

The OpenAttestation framework exposes documented APIs and published npm packages. Standards adoption covers W3C Verifiable Credentials, W3C DIDs, UNCITRAL MLETR and UN/CEFACT, with credentials expressed as JSON-LD and JWT in standard W3C formats.

B · Minimalist & Reusable Design

2/3

Is it a modular building block that does one thing well, rather than a monolithic platform?

Modular architecture
Core/app separation
Config-driven adaptability · Partially meets

OpenAttestation core, token-registry and renderer ship as separate packages, with a clear distinction between the core framework and reference implementations such as the website and CLI. Configuration is oriented towards trade documents, and country-specific deployment guidance could be expanded.

C · Ecosystem Enablement

3/3

Can other public and private actors build on top of it?

Third-party buildability
External integrations
No vendor lock-in

npm packages, SDKs and documented extension points support third-party development, and adoption extends beyond Singapore through an ICC partnership and multi-country pilots. Apache 2.0 licensing under GovTech Singapore governance means no vendor lock-in.

D · Federation Readiness

2/3

Can it run in distributed or federated deployments suited to national infrastructure?

Federated deployment
Data sovereignty · Partially meets
High availability

The blockchain and DID-based architecture is inherently decentralised, requiring no central authority and providing redundancy without a single point of failure. How personal data held off-chain stays within a jurisdiction is not clearly documented.

E · Security & Privacy at Scale

2/3

Does it meet the security and privacy bar for population-scale infrastructure?

Infrastructure-grade security
Vulnerability disclosure · Partially meets
Privacy by design

Document integrity rests on cryptographic verification and blockchain security, and a selective redaction feature provides privacy by design for sensitive trade documents. No vulnerability disclosure policy specific to TradeTrust was found published.

Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.

Spot something out of date? Contact the DPGA