TradeTrust is an open-source framework from GovTech Singapore for issuing and verifying trade documents as electronic transferable records, built on W3C Verifiable Credentials and DIDs with title transfer and selective redaction. It is a candidate trust infrastructure building block, aligned with UNCITRAL MLETR for cross-border legal recognition.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
3 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
Document attestation built on W3C VC and DID standards places it in the Trust Infrastructure domain. The attestation framework is reusable for any document type even though trade is the primary use case, and it is designed for international trade at global scale.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
The OpenAttestation framework exposes documented APIs and published npm packages. Standards adoption covers W3C Verifiable Credentials, W3C DIDs, UNCITRAL MLETR and UN/CEFACT, with credentials expressed as JSON-LD and JWT in standard W3C formats.
Is it a modular building block that does one thing well, rather than a monolithic platform?
OpenAttestation core, token-registry and renderer ship as separate packages, with a clear distinction between the core framework and reference implementations such as the website and CLI. Configuration is oriented towards trade documents, and country-specific deployment guidance could be expanded.
Can other public and private actors build on top of it?
npm packages, SDKs and documented extension points support third-party development, and adoption extends beyond Singapore through an ICC partnership and multi-country pilots. Apache 2.0 licensing under GovTech Singapore governance means no vendor lock-in.
Can it run in distributed or federated deployments suited to national infrastructure?
The blockchain and DID-based architecture is inherently decentralised, requiring no central authority and providing redundancy without a single point of failure. How personal data held off-chain stays within a jurisdiction is not clearly documented.
Does it meet the security and privacy bar for population-scale infrastructure?
Document integrity rests on cryptographic verification and blockchain security, and a selective redaction feature provides privacy by design for sensitive trade documents. No vulnerability disclosure policy specific to TradeTrust was found published.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA