The regulatory system of record for product compliance

UCVreg is an additional solution to ERP, PLM and PIM systems. It converts approved operational data into sealed, version-controlled regulatory records. The system maintains the documentation as issued. Subsequent changes become history and new versions, and remain auditable.

Operational systems keep changing. Your regulatory record keeps its history.

European manufacturer office
AI generated
The gap

Operational systems change. Regulatory records must preserve the past.

ERP, PLM and PIM keep the current operational state. When production changes, that history is overwritten.

Years after shipment you may still need to prove:

  • Which supplier was connected with the product or a batch
  • What the composition of the material was claimed to be
  • What regulatory information was published
  • What version of the record applied then

Operational systems answer current questions. UCVreg stores answers to previous ones.

  1. 01ERP / PLM / PIM: current operational state
  2. 02Validate and approve
  3. 03UCVreg: sealed issuance state
  4. 04Customer, public and authority views
The flow

From source systems to a sealed regulatory record

UCVreg is complementary to current operational systems. It utilizes their sanctioned structured output via a process that creates, maintains, and validates the relevant regulatory record.

  1. Source systems
  2. Validate
  3. Approve
  4. Seal
  5. Preserve and verify

Operational data stays within the source systems. The UCVreg component retains the regulatory history created through the approved data.

Connect

Systems we can connect around your compliance workflow

Most enterprise integrations are tailored. We review your data model, source systems, approval flow and publication requirements before recommending the right integration pattern.

ERP systems

Connect product identifiers, supplier references, purchase data, stock flows and business records.

SAP · Oracle · Dynamics · NetSuite

PLM systems

Connect BOM, material, lifecycle and product version data for passport and compliance records.

Centric · Siemens · PTC · Custom PLM

PIM systems

Connect product attributes, descriptions and channel content without treating marketing copy as compliance proof.

Akeneo · Salsify · Pimcore · Custom PIM

E-commerce channels

Offer tailored integration for commerce channels so passports can be managed from one place and surfaced where products are sold.

Shopify · WooCommerce · Magento · Headless

Supplier evidence

Bring supplier declarations, certificates, geolocation files and evidence documents into reviewable records.

API · CSV · SFTP · Portal

Architecture

The modules behind a sealed record

Snapshot & Publish-Time Anchoring

On publication, the UCVreg includes the structure and content of the payload which has been approved, and canonicalizes it to create an issuance snapshot that is then sealed. The integrity of this specific payload is provided using the deterministic SHA-256 hash function.

  • Canonicalization of structured payload before hashing
  • Differentiation between the snapshot and subsequent operational changes
  • Operational edits do not alter the sealed record
  • Approval of the state at the time of issuance
Why it mattersThe issued declaration can be accessed and compared to the original state of issuance.
Technical detail
Canonicalization ensures consistency of the structured payload before hashing it. The SHA-256 hash is stored along with the snapshot. Subsequent operational edits cannot alter the sealed issuance state.
02

Versioned Regulatory Records

Products, suppliers, and regulation requirements evolve over time. Whenever material changes occur, a new version is published, while earlier versions are not removed even if they relate to other products/batches.

v1.0 and v2.0 exist simultaneously.

Each product/batch refers to the corresponding version.

Why it mattersTeams have the ability to recreate whatever was announced at a certain point without altering the historical record.
Technical detail
Each released edition is linked with the context of release. Operation changes may be used for developing a new edition; however, they do not automatically change a released edition.
03

Cryptographic Verification

The sealed object is assigned an SHA-256 hash computed on canonical structured data. Recomputing the hash is a deterministic test for integrity; when the sealed data has changed, the recomputed hash value will not agree.

  • Integrity check by hash computation
  • Verification without revealing internal sources
  • Detection of modifications to the sealed data

e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

Why it mattersIntegrity of record is verifiable separately from any reliance on platform assertions.
Technical detail
Verification will recomputed the hash based on the canonical payload and compare it to the integrity reference at publication. The discrepancy implies that the payload under verification is not identical to the sealed issued state.

Append-Only Event Journal

Post issuance lifecycle events are appended to the record in chronological order and not used to edit the existing snapshot of the record.

Repairs, inspection, recall and other lifecycle events will be linked to the state of the record at issue.

  • Appends lifecycle events to the issued record
  • Preserves the order of subsequent modifications and events
  • Allows for reconstruction of history

WORM Principle

Write Once, Read Many. Events are hash-linked and append-only. They do not edit the issued snapshot. No retroactive mutation is possible without breaking the cryptographic chain.

Deterministic Reconstruction

Historical state can be rebuilt exactly as it existed at any point in time from the hash-linked event chain.

Why it mattersThe team has the ability to track the history of the product lifecycle while keeping intact the declaration that was issued initially.
Technical detail
The journal uses the concept of write once and append only. Every new entry extends the history from the initial snapshot state.
05

Access Control & Tenant Isolation

The role-based access control is implemented at the API level where the processes of drafting, approving and verifying are separated.

  • Permissions that are explicitly implemented at the API level
  • Division of drafting and publishing powers
  • Logical separation at the tenant level
  • Separate encryption keys per tenant
Separate encryption keys per tenant.
Why it mattersSystem guidelines regulate both the regulatory approval and access to the organization.
Technical detail
Permissions are granted explicitly, and there is no implied authorization for publication. Isolation at the tenant level ensures that users of one organization cannot access the regulatory records of another organization.
Drafter
Drafting
Approver
Approving and sealing
Auditor
Retrieving and validating

Architecture, Not Policy.

Security in regulatory systems is not a statement. It is a property of system design.

UCVreg enforces immutability at the structural level. It does not rely on user behavior, best efforts, or internal guidelines to maintain integrity.

Accountability

Built for inspection, with clear responsibility limits

Inspection-readiness evidence requires two aspects: valid information being entered into the system and integrity of the record following publication. The customer is responsible for the correctness and validity of any input that they provide. UCVreg maintains the validated regulatory state, including its different versions and its history.

  1. Customer controls
  2. UCVreg preserves
  3. Inspection outputs

Customer controls

  • Correctness of the source data
  • Supply chain declaration and evidence
  • Authenticity of physical product
  • Internal approval decisions

UCVreg preserves

  • Publication state with seals
  • Published version history
  • Append-only history of events
  • Role and access enforcement
  • Schema and issuance context of the original

Inspection outputs

  • Machine readable output
  • Integrity check by hashes
  • Relevant schema context
  • Completeness of records
  • State reconstruction history

What we guarantee

Immutability Guarantee

Published artifacts cannot be altered. Once sealed, the content is frozen forever.

Verifiability Guarantee

Integrity can be independently validated via hash recalculation by any third party.

Chain Integrity

Lifecycle events cannot silently modify original declarations. The sequence is unbreakable.

Retention Integrity

Records remain structurally retrievable over long time horizons, independent of ERP changes.

UCVreg does not certify that each supplied claim is factually true. It provides the structure in which an approved record can be sealed, preserved, and later verified.

Regulatory trust is not assumed. It is verifiable.

Longevity

Still usable when regulations and systems change

Regulatory requirements for products change with new regulations, schemas, and product types. Changes to operational technology occur with ERP changes, software updates, and vendor changes.

The UCVreg database distinguishes between regulatory records from changes to both kinds of requirements.

When regulation changes

  • New regulatory records may comply with new schemas and product requirements.
  • Older records will refer to the regulations and schemas relevant at the time of issue.
  • Changes to regulations do not retroactively alter old published versions.

When operational systems change

  • ERP, PLM, and PIM systems can be updated and even replaced.
  • But new operational data can continue to be modified.
  • Old regulatory records are separated from the operational systems that generated them.
  • New regulatory records can be based on new requirements without losing the context of past issuing.
Boundaries

Easy mistakes to avoid

×

Document storage

We do not build SharePoint. We build verifiable data structures.

×

An ERP replacement

We separate liability from operations. We do not extend mutable systems.

×

A PDF generator

Static files cannot be programmatically verified. We anchor structured records.

×

A consultancy workflow

We provide structural enforcement, not project management advice.

Operational systems optimize production. UCVreg: Compliance You Can Trust.

EU product rulesFREEUnder 5 minutes

Calculate your product risk and get your free report.

A few simple questions. They show which product rules may need a look before a sale, launch, or supplier call gets stuck.

Direct Rule Screening

Instant applicability check across ESPR, DPP, EUDR, PPWR & Battery Regs.

Risk & Gap Exposure

Identify supplier data missing links and customs audit bottlenecks.

Free Audit Report

Receive a structured, actionable executive roadmap with zero obligation.

100% Free · No credit card required
Instant interactive risk scorecard
Furthermore

Operational systems optimize production.
UCVreg: Compliance You Can Trust.

System Status

Operational / Enforced

Integrity Model

SHA-256 Anchoring (Active)

Log Topology

Append-Only / Immutable

Last Architectural Review

2025-12-31

Review Cycle: Annual

Product Compliance Platform & System of Record | UCVreg