Origin Secured Event Chain & Trust Orchestration Infrastructure
OS's trust infrastructure allows authoritative organisations to issue contextual assertions as cryptographic-proof, recorded on event-chains and reused across systems without centralising data or permissions. Operating as a trust overlay, enabling verification of who asserted what, in which context, and whether it remains valid, without integrating systems or exposing underlying information.
Features
- Trust orchestration layer enforcing policy-driven authority and verification
- Contextual credentials, assertions and endorsements cryptographically linked to authorities
- Time-bound, scoped and revocable authority with deterministic lifecycle control
- Reusable confirmed authority across organisations without repeated credential checks
- Privacy-preserving verification enabling decisions without exposing underlying data
- Reduced onboarding, audit and assurance friction using reusable Digital Licences
- Enhances IAM, SSO, PAM and MFA with authority-aware trust signals
- Event-level recording of trust decisions with immutable provenance
- Instant proof of authority, compliance and entitlement without document exchange
- Granular permissioning and delegation controlled by community governance rules
Benefits
- Secure information sharing without data exposure using cryptographic, zero-knowledge proofs
- Integration-less interoperability enabling unified digital presence across existing environments
- Removes duplicated verification and approval checks across organisations
- Faster real-time decision-making at point of action
- Reduces cyber risk via continuous verification, not perimeter trust
- Clear accountability, traceability, and auditability supporting governance and GRC
- Works with existing infrastructure and cloud platforms without rip-and-replace
- Consistent trust across programmes, partners, and federated ecosystems
- Improved permissions, access control, and least-privilege authorisation
- Scales securely across complex delivery chains and partner ecosystems
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 8 4 5 6 4 6 9 7 7 5 9 4 6 7
Contact
ORIGIN SECURED LTD
Marc Ayres
Telephone: +447725544864
Email: marc.ayres@originsecured.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Endpoint security
- Security analytics
- Governance, risk and compliance
Identity and access management
- Access
- Privilege
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Digital trust
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Identity and Access Management (IAM) platforms
Cloud and application security platforms
Governance, risk, and compliance (GRC) and audit systems - Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- No
- System requirements
-
- Standards-based cloud or on-prem infrastructure
- Modern identity, application, or platform integrations
- End-user devices
User support
- Email or online ticketing support
- Yes
- Support response times
-
Critical
Same Business Day (where practicable)
High
1–2 Business Days (where practicable)
Medium
Within a reasonable time
Low
Within a reasonable time - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Critical
Same Business Day (where practicable)
High
1–2 Business Days (where practicable)
Medium
Within a reasonable time
Low
Within a reasonable time
No changes in support costs
A technical account manager will be provided - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Origin Secured helps users get started through online onboarding and self-service enablement.
We provide online training materials covering service setup, governance configuration, and API integration, alongside comprehensive user and technical documentation. Documentation includes administrative guidance, API references, security and governance concepts, and integration examples to support system-to-system adoption.
Onboarding focuses on enabling administrators and technical teams to configure communities, trust policies, and integrations independently. The service does not require onsite training; users can start using the platform remotely using the provided online resources and documentation. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When a contract ends, users can extract their data through documented and controlled data export processes designed to ensure availability, integrity, and confidentiality of service user data.
Service user data is made available for export in commonly used, structured formats via secure transfer mechanisms. Data extraction can be initiated by an authorised customer representative and is supported by clear offboarding documentation outlining the steps, timelines, and responsibilities involved.
During the extraction period, access controls remain in place to ensure only authorised users can access or export data. Data exports are logged and monitored in line with security and audit requirements. Customers are provided with a defined period following contract termination to complete data extraction before data is securely sanitised in accordance with industry-standard data destruction and retention processes.
The end-of-contract data extraction process is aligned with the organisation’s ISO/IEC 27001 information security management system, ensuring that data handling during offboarding is managed securely and consistently, with appropriate oversight and auditability throughout the process. - End-of-contract process
-
At the end of the contract, the service enters a controlled offboarding process designed to ensure service continuity, secure data handling, and a clear separation of responsibilities between the parties.
Upon contract termination, customer access to the service is restricted in line with agreed notice periods, while authorised access is retained for the purpose of data extraction. Customers are supported through documented offboarding procedures that describe how to export service user data and the timelines involved. Following completion of data extraction, service user data is securely deleted or sanitised in accordance with documented data retention and destruction processes and contractual requirements.
Included in the contract price:
Standard offboarding support
Provision of onboarding and offboarding documentation
Secure data export in standard formats
Secure data deletion and sanitisation following the agreed retention period
Additional costs (if required):
Extended data retention beyond standard periods
Bespoke data exports or non-standard formats
Additional offboarding support outside standard support hours
This approach ensures transparency, security, and predictability for customers at contract end while aligning with recognised information security and service management practices. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/A
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
Origin Secured provides secure, API-first access to its Event Chain and Trust Orchestration infrastructure for system-to-system integration.
Using the API, authorised users can:
Set up and configure tenants, Entities, Communities, roles and governance rules
Issue, update, suspend and revoke Assertions, Endorsements, Digital Views and Digital Licences, with all lifecycle actions recorded as immutable Events
Verify Digital Licences and Assertions (including current status and revocation) via cryptographic proofs on the Event Chain
Orchestrate trust workflows, including consent-led access, selective disclosure, Alias Handles, and integration with external authoritative systems
Subscribe to or query trust events to automate downstream actions and compliance reporting
Users cannot:
Bypass community governance rules or policy enforcement
Alter or delete historical Events on the Event Chain
Access private or restricted data without permission or valid proofs
Perform primary identity proofing or KYC (these are provided by accredited third parties)
Use the API as a consumer-facing application interface
All API access is role-, scope- and tenant-restricted, with security controls, audit logging, and rate limiting applied by default. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise Origin Secured through configuration and governance controls, rather than bespoke development.
What can be customised
Community structures, membership rules, roles and permissions
Trust schemas, including required Assertions and Digital Licence structures
Digital Licence lifecycle rules (issue, renew, suspend, revoke)
Privacy and disclosure models (public, private, restricted, distributed, zero-knowledge)
Orchestration and verification rules, including event triggers and notifications
API integrations, scopes and event subscriptions
How users can customise
Using secure administrative interfaces and APIs
By configuring governance policies, schemas and rules enforced by the Orchestration layer
Through event-driven configuration that responds automatically to Event Chain activity
Who can customise
Authorised administrators within the customer tenant
Community governors (for shared or federated trust frameworks)
All customisation is role- and permission-controlled; end users cannot alter governance or core platform behaviour.
Scaling
- Independence of resources
-
The service is delivered using a logically segregated, cloud-based architecture designed to ensure that user workloads and data are isolated from one another. Resource allocation is managed to prevent one user’s activity from adversely impacting the performance or availability experienced by other users.
Capacity is monitored continuously, with automated scaling and alerting used to manage demand and maintain service performance. Service performance and availability are reviewed as part of ongoing operational monitoring and management review processes.
This approach ensures fair use of shared infrastructure while maintaining consistent performance, resilience, and availability for all users.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users export their data using documented, secure export processes provided as part of the service. Authorised users can request or initiate data exports in standard, commonly used formats to support portability and reuse.
Data exports are delivered through secure transfer mechanisms and are subject to access controls, logging, and validation to ensure data integrity and confidentiality. Clear guidance is provided in service documentation to support users through the export process.
Data export remains available during the contract term and for a defined period following contract termination, in line with the documented offboarding process. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to operate with high availability and resilience using a cloud-native architecture.
We guarantee 99.5% service availability, measured on a monthly basis, excluding scheduled maintenance notified in advance. Availability is defined as the ability for authorised users to access and use the core service functionality.
Availability is monitored continuously using automated monitoring and alerting. Performance and availability metrics are reviewed regularly as part of operational management and management review processes.
If the guaranteed availability level is not met, customers are entitled to service credits in accordance with the service level agreement. Service credits are calculated as a proportion of the monthly service fee and applied to the next billing period. Refunds are provided as service credits rather than cash payments.
SLA breaches, root cause analysis, and corrective actions are formally reviewed to prevent recurrence and to support continual improvement of the service. - Approach to resilience
-
Origin Secured is designed for resilience in line with the government’s Cloud Security Principle 2: Asset protection and resilience.
The service is delivered on UK-hosted cloud infrastructure with logical tenant isolation. Core components are deployed across multiple availability zones to reduce single points of failure and support continued operation during infrastructure faults. Data is protected using redundancy and automated backups to support recovery following incidents.
The Event Chain architecture is inherently resilient: events are append-only, cryptographically linked, and independently verifiable, allowing trust state to be reconstructed deterministically even after partial outages. Separation between the integrity, orchestration, and data layers reduces blast radius and supports graceful degradation.
Continuous monitoring, alerting, and health checks are used to detect and respond to service degradation. Documented incident, backup, and recovery procedures support restoration of service in the event of failure.
Details of specific datacentre locations, configurations, and disaster recovery parameters are considered sensitive and are available on request to public sector buyers under appropriate assurance arrangements. - Outage reporting
-
Service outages and service degradation events are reported through clear and timely communication channels to ensure users are kept informed.
Outages are communicated to customers via email alerts sent to nominated service contacts, providing details of the issue, impact, and progress updates. Where appropriate, follow-up communications are issued to confirm service restoration and outline any corrective actions taken.
Service availability and incidents are monitored continuously using automated monitoring and alerting. Information on significant incidents, including root cause analysis and remediation actions, is shared with customers as part of post-incident reporting.
At present, the service does not rely on a public status dashboard or outage reporting API. Outage communication is managed directly to customers to ensure accuracy, relevance, and appropriate handling of sensitive operational information.
This approach ensures transparent, controlled, and effective outage reporting aligned with service management and information security best practices.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted through role-based access control and the principle of least privilege.
Administrative access is limited to authorised personnel with defined responsibilities, enforced through strong authentication and individual user accounts. Access rights are approved, reviewed regularly, and revoked promptly when no longer required.
Support channels are restricted to verified customer contacts and authorised internal staff. Requests involving sensitive actions or data require additional verification before being processed.
Access activities are logged and monitored to detect unauthorised or inappropriate use, and controls are reviewed as part of ongoing security governance and audit processes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
The organisation operates a formal information security management system (ISMS) aligned with ISO/IEC 27001, which defines the policies, processes, and governance arrangements used to protect information assets.
Information security policies cover areas including risk management, access control, incident management, asset management, supplier security, data protection, and secure system operation. These policies are documented, approved by senior management, and reviewed regularly to ensure they remain appropriate and effective.
Security governance is overseen by senior leadership, with defined roles and responsibilities for information security management. Security performance, risks, incidents, and compliance activities are reported through a structured management review process, ensuring appropriate oversight and decision-making.
Compliance with policies is enforced through access controls, documented procedures, staff training and awareness activities, and regular internal audits. Deviations, incidents, or nonconformities are recorded, investigated, and addressed through corrective action processes, supporting continual improvement.
This structured approach ensures information security policies are consistently applied, monitored, and improved in line with recognised best practice and regulatory expectations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and change management is governed through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.
Service components are identified and tracked through their lifecycle using asset and configuration records, ensuring visibility of ownership and dependencies. Changes to systems, configurations, or services are formally requested, assessed, and approved prior to implementation.
All changes are assessed for potential security and operational impact, including risks to confidentiality, integrity, and availability. Where required, changes are tested before deployment. Post-implementation reviews confirm successful outcomes and identify corrective actions. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability management is delivered through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.
Potential threats are identified through monitoring, penetration testing, vulnerability scanning, supplier review and platform security advisories. Identified vulnerabilities are assessed using a risk-based approach, considering severity, exploitability and potential impact on confidentiality, integrity and availability.
Patches and mitigations are prioritised based on risk. High-risk vulnerabilities are addressed as a priority, with patches deployed promptly following testing. Lower-risk issues are scheduled into maintenance cycles.
Threat intelligence is sourced from cloud providers, software vendors, security advisories, and industry sources, reviewed regularly to ensure timely response. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Protective monitoring is delivered through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.
Potential compromises are identified through centralised logging, continuous monitoring, and automated alerts covering authentication events, system activity, and security-relevant behaviour. Logs are retained and reviewed to support detection and investigation.
When a potential compromise is identified, incidents are triaged, contained, and investigated in accordance with documented incident response procedures. Appropriate corrective actions are implemented to mitigate impact and prevent recurrence.
Security incidents are responded to promptly, with high-severity incidents prioritised for immediate action and escalation to senior management where required. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incident management is delivered through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.
Pre-defined procedures exist for common security and operational incidents, including unauthorised access, service disruption, and data security events. Incidents are logged, triaged, and managed according to severity and impact.
Users report incidents via email or the support ticketing process. All incidents are recorded and tracked through to resolution.
Incident reports are provided to affected users where appropriate, including details of impact, actions taken, and any required follow-up. Incidents, root cause analysis, and corrective actions are reviewed to support continual improvement. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Wednesday 13 August 2025
- What the ISO/IEC 27001 doesn’t cover
- The certification does not extend to customer-managed environments, customer endpoint devices, or third-party systems that are not operated or controlled by the organisation. Responsibility for the secure configuration and use of the service within customer environments remains with the customer.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Wednesday 13 August 2025
- What the ISO 9001 doesn’t cover
- Third-party managed data centres and cloud infrastructure (e.g. AWS), which are outside of direct operational control. These services are instead managed through supplier assurance, contractual controls, and reliance on the third party’s own certified management systems.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B37a829a-ac55-4130-af5f-c9fa608401e3
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Fe487148-6f13-49ca-8236-de75fb5f7d12
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-