News
Standards-Based Provenance, Built on Digital Trust Foundations
Tags
Septillion’s Scottish Enterprise Digital Manufacturing Challenge pilot with Stewart Technology is complete. The result is that Ledgit, our standards-based supply chain provenance platform, has been proven in a real contract electronics manufacturing environment. It’s built on full implementation of IPC-1782, W3C PROV, and ISO/IEC 15459, with a cryptographic trust layer anchored on Hyperledger FireFly. This is what we’ve built, why it works, and what it means for electronics manufacturers preparing for the next two years of regulatory change.
Scotland’s Digital Trust Ambition
Some background that’s worth setting out, because the pilot didn’t happen in isolation.
In 2023, Scotland’s Blockchain and Digital Trust Taskforce published the Scottish Blockchain Roadmap. The roadmap identified a £4 billion opportunity for Scotland through the adoption of blockchain and digital trust technologies, with manufacturing supply chains as one of the priority sectors. The Scottish Enterprise Digital Manufacturing Challenge that funded our pilot was created in direct collaboration with the Digital Trust Taskforce, alongside the Net Zero Technology Centre and the National Manufacturing Institute Scotland.
That matters because it means Ledgit isn’t a one-off engineering project. It’s a deliberate piece of work, supported by Scottish public investment, aimed squarely at the part of the roadmap that talks about provenance, transparency, resilience, and sustainability in manufacturing supply chains. The Taskforce identified the opportunity. The Digital Manufacturing Challenge created the runway. Septillion built the platform for Stewart Technology.
What We Built
Ledgit is a SaaS supply chain provenance platform for electronics manufacturing. The platform records every event in the lifecycle of a material or finished product: receipt, storage, inspection, transformation, consumption, and shipment. Every event carries a timestamp, cryptographic link, and a verifiable record in a complete provenance chain.
Three international standards working together:
- IPC-1782 defines the technical requirements for electronics supply chain traceability. At Septillion, we are actively involved in developing this standard at the Global Electronics Association. Ledgit implements all four Critical Tracking Events that the standard requires.
- W3C PROV provides the underlying data model. Provenance is expressed in terms of Entities, Agents, and Activities, as per the international standard for provenance data.
- GS1 Digital Link and ISO/IEC 15459 govern how Ledgit identifies things in the physical world. Every component and product package gets a globally unique identifier (GUID) that follows GS1’s web-native standard. A single scan can open a product’s provenance record, its compliance evidence, or its passport, depending on who’s scanning
Sitting above the standards is a configurable domain model. W3C PROV gives Ledgit the generic vocabulary of Entities, Agents, and Activities, and the domain model is the layer that maps sector-specific concepts, attributes, lifecycle events, and validation rules onto the standard vocabulary.
The standards-first approach has real commercial value. Stakeholders don’t need to learn a vendor-specific data model – evidence is interoperable. In tender processes with aerospace, defence, and medical device customers, evidence of standards-based traceability is increasingly a condition of being on the shortlist.
The Digital Trust Layer
Every event recorded in Ledgit is cryptographically linked to the previous event for that entity. The result is a sequence of events that’s mathematically tamper-evident. If anyone alters a historical record, the chain breaks and verification fails. Snapshot hashes of the entity, agent, location, and carrier data are captured the moment the event happens, so the state of the record at event time is preserved even if downstream data changes.
For customers who require third-party verifiability, event hashes are anchored to a public blockchain via Hyperledger FireFly. This lets Ledgit anchor cryptographic proofs to Ethereum (or other compatible networks) without requiring every user to operate blockchain infrastructure directly.
The combination is what makes Ledgit’s trust layer practical: cryptographic hash chains for everyday integrity, with blockchain anchoring for the cases where mathematical proof must be defensible to a third party. That’s digital trust applied to a real operational problem rather than as a marketing concept.
Protecting IP While Proving Provenance
One question that frequently comes up in conversations with manufacturers about supply chain transparency: if I share provenance data, am I giving away commercially sensitive information about my suppliers, my processes, and my customer relationships?
It’s a legitimate concern. Manufacturers could risk a) exposing supplier, customer and logistics partnerships, b) revealing yield rates and production volumes, and c) enabling design reverse engineering. Provenance and confidentiality have historically pulled in opposite directions, and the trade-off has been one of the reasons real adoption has lagged behind regulatory ambition.
We’re addressing this in Ledgit by building Verifiable Credentials (VCs) with Decentralised Identifiers (DIDs) into the platform. Both are W3C standards, which keeps the approach aligned with the same standards-first philosophy that runs through the rest of the platform.
The capability matters because of what it enables: selective disclosure. A supplier can issue a Verifiable Credential that proves a component meets a regulatory requirement, originates from a sanctioned source, or carries a particular sustainability attribute, without revealing the underlying production data, supplier identity, or commercial terms. A credential can be presented to an OEM customer that proves chain-of-custody integrity across the manufacturing process, without exposing process IP. An OEM can publish a Digital Product Passport that proves substantiated sustainability claims, without revealing the supply chain map that produced the evidence.
Decentralised Identifiers are the cryptographic identities that let stakeholders issue, hold, and verify these credentials without depending on a central authority. Each party owns its own identity, and controls what is disclosed, to whom, and under what conditions. For the wider electronics manufacturing sector, this matters because it removes one of the main commercial objections to participating in shared provenance infrastructure.
The Four Critical Tracking Events
The four Critical Tracking Events defined in IPC-1782 are the backbone of the platform – many people working in electronics supply chains have heard of the standard, but fewer have worked through what it actually asks for.
- Material Packing (MP). A component or assembly is sealed into a package with full metadata: part number, manufacturer, lot code, date code, MSL level, originating supplier. A unique identifier (GUID) is generated and physically linked to the package via a printed label, or intrinsically part of the packaging.
- Material Package Logistics (MPL). The package moves between parties. Carrier, origin, destination, and custody transfers are recorded. Every handoff is captured.
- Material Package Processing (MPP). The package is opened, inspected, and accepted. Where contents are split or repackaged, child packages inherit the parent’s provenance.
- Material Package Consumption (MPC). Components are consumed into a work order. The consumption is recorded against the GUID and the resulting build, linking material to finished product.
These four CTEs give bidirectional traceability for everything that passes through a manufacturing supply chain. Forward traceability (“which products contain components from this lot?”) and backward traceability (“what went into this finished product?”) become queries that return in seconds.
Physical to Digital®, in Practice
Septillion’s core proposition is what we’ve registered as Physical to Digital®: the linkage between a tangible asset and a verifiable digital record. This pilot taught us a lot about how that linkage must work on a factory floor.
In operation, GUIDs are associated with packed materials as they are manufactured – a Material Packing event. When these packed materials leave or enter a new facility, an operator scans the label, which automatically creates a Material Package Logistics event with full metadata. The same GUID carries through all subsequent logistics, processing, and consumption events. This scanning workflow fits within most manufacturers existing physical handling processes, and operations continue without disruption.
Key Capabilities
A few features delivered in the pilot are worth highlighting because they answer specific questions manufacturers tend to ask:
- Multi-tenant architecture with data isolation. Proprietary manufacturing data, supplier relationships, and component information are cryptographically and architecturally isolated from other tenants.
- Work order and BOM management. Full production work order lifecycle through integration with enterprise manufacturing systems.
- Geographic journey visualisation. Interactive maps show the physical journey of packages from component manufacturer through logistics to assembly and onward to customers.
- Headless architecture. Over 40 API endpoints with full documentation, standardised response format, pagination, advanced filtering, and scoped API keys. Ledgit is designed to sit alongside existing enterprise manufacturing and quality management systems rather than replace them. The same architecture allows Ledgit to operate as a headless provenance layer behind other front ends, including the AI-driven manufacturing platforms many electronics manufacturers are deploying for production planning, quality, and predictive maintenance.
What This Delivers for Electronics Manufacturing
Regulatory readiness. The EU Digital Product Passport Registry launches in July 2026. The Ecodesign for Sustainable Products Regulation rolls out across product categories through 2030. The Empowering Consumers for the Green Transition Directive takes effect in September 2026 and requires environmental claims to be backed by verifiable data. Ledgit captures the provenance core that underpins compliance with all of these.
Counterfeit defence. Active components available through authorised channels accounted for over 25% of all counterfeit cases reported in 2024. Physical to Digital® linkage via GUID-tagged packages, combined with cryptographically verifiable event chains, gives manufacturers a far stronger defence than documentation-based approaches.
Audit and recall response. Recall-readiness queries that previously required days of manual investigation return results in seconds. For a manufacturer exposed to recall risk, that’s a material reduction in operational exposure. The same speed applies to customer audits.
Compatibility with AI-driven manufacturing transformation. Many manufacturers are investing in AI for production scheduling, quality inspection, predictive maintenance, and supply chain optimisation. Those AI systems are only as trustworthy as the data they’re trained on and the data they act on. Ledgit’s role in an AI-driven manufacturing stack is to provide the verifiable ground truth: every material, every event, every transformation, cryptographically linked and standards-compliant. As a headless layer, Ledgit feeds clean, attributable provenance data into AI platforms, and the AI’s outputs can be written back as events with full traceability. The combination turns AI from a black box into an auditable contributor to the production record.
Supply chain visibility. The multi-party architecture allows component suppliers, logistics providers, and OEM customers to contribute or access provenance data within their scope. Each party sees what they need to see, and nothing else. The platform becomes shared infrastructure across the supply chain rather than a single-operator system.
What Comes Next
The conversation with the wider supply chain has begun. Extending Ledgit to more manufacturers, suppliers and customers is now a commercial conversation that we’re keen to have.
If you’re a contract electronics manufacturer, an EMS provider, or an OEM thinking about how the next two years of DPP deadlines will land in your operation, we’d be glad to walk you through what Ledgit does and what we learned in the pilot. Get in touch for a demo.
We’re proud of what was delivered. Scottish public investment in digital trust technology turned into working software, tested in a real manufacturing environment, ready to support electronics manufacturers across the UK and beyond as the regulatory landscape moves toward verifiable provenance as the baseline.