How buyers verify RegAlign®
Current evidence is separated from planned, qualified and still-to-be-reconciled assurance work. Jersey examples and public-register entries do not imply regulatory approval or endorsement of the product.
Pilot-ready for Jersey trust company businesses. Crown Dependencies and UK on the roadmap — same methodology and hash-chained record, source ingestors for JFSC, GFSC, IoM FSA and FCA already shipping.
Evidence and publication authority are separate controls
A repository file, historical version, synthetic-data label or implemented feature does not by itself authorise public or customer-facing issue. Buyer material requires current evidence, approved wording, a defined audience and surface, and explicit release authority.
Public registers
- VerifyJFSC entity registerRegAlign Limited, No. 165263 — company/entity-register evidence only; not a statement of regulatory approval, licensing or product endorsement.
- VerifyUK IPO trade mark registerRegAlign®, UK00004283882.
- VerifyJOIC public RegistryJersey Office of the Information Commissioner, registration No. 103914.
Integrity verifier
The implemented verifier contract is POST-based and returns bounded integrity results. The retained legacy invalid/forked-chain limitation remains explicit; verifier availability is not independent assurance.
POST /api/public/audit-trail/verifyPOST /api/public/evidence/verifyPOST /api/public/controls/verifyPOST /api/public/findings/verifyPOST /api/public/issues/verifyPOST /api/public/decisions/verifyControlled diligence materials
See document status →Trust, commercial, sample, methodology and value materials are controlled separately. Current issue requires the applicable evidence, audience, confidentiality and release decision.
Assurance status and roadmap
- Internal audit-trail integrity mechanismLive
Implemented SHA-256 chained integrity checks and verifier surfaces exist. Retained legacy invalid/forked-chain history means this is not a claim that every historical chain universally validates.
- Public integrity-verifier routesLive
Implemented POST verifier routes return bounded integrity results. They do not establish wider compliance, control effectiveness or universal historical-chain validity.
- BCP / recovery assuranceIn progress
Continuity design exists, but current backup configuration, representative restore evidence and continuity operating effectiveness remain evidence-dependent.
- Sub-processor / data-location assuranceIn progress
Current supplier, access, location, transfer and notification evidence remains under reconciliation. No universal location or transfer statement is inferred here.
- Independent penetration testingPlanned
A testing scope may exist internally, but no completed independent penetration-test report is claimed and no static scope/report is offered for public download from this surface.
- SOC 2Planned
Roadmap only. No SOC 2 report or certification is currently claimed.
- ISO 27001Planned
Roadmap only. No ISO 27001 certification is currently claimed.
- Security-scanning evidenceIn progress
A current scanner connection, scope, cadence, finding flow and data boundary must be evidenced before a scanner-specific assurance statement is made.
Continuity, successor, escrow, insurance, liability, exit and support arrangements are engagement-specific and must be executed where relied on; they are not universal always-on guarantees.
Deployment location, transfer treatment and recovery objectives require current controlled evidence for the relevant engagement. No universal current location, RTO or RPO is inferred here.
Security and governance information
Machine-readable security contact: /.well-known/security.txt.
Need controlled diligence material?
Request a scoped review at hello@regalignplatform.com. Any issue remains subject to the current evidence and release controls.