Skip to content
EBRICS EuraBelt Reserves Institutional Codification System
Invited institutions Verify a counterparty Code holders Document seals Legal Centre
Legal Centre › Security & trust
Version1.0
Effective1 October 2026
OwnerEBRICS Registry Security

On this page

  1. 1. Design principles
  2. 2. Cryptography
  3. 3. Application security
  4. 4. Access control
  5. 5. Key management
  6. 6. Monitoring and incident response
  7. 7. Business continuity
  8. 8. Reporting a vulnerability
Security & trust

Security Overview

How the Registry protects codes, the Reserve Ledger and personal data, in terms a counterparty's compliance or information-security team can assess.

1. Design principles

  • Server-side only. Code generation, check characters, ledger resolution and verification run only on the Registry's servers. The browser holds no Registry logic, keys or data beyond the page being shown.
  • Nothing to steal in the code. An EBRICS code carries no recoverable data. It is a keyed seal, and it means something only to the Reserve Ledger.
  • Consent-gated disclosure. A verified profile is shown only with a valid ATV issued by the holder and delivered by the Registry.
  • Uniform failure. Every failed verification returns the same response, padded to the same response time.

2. Cryptography

ControlImplementation
Code sealsHMAC-SHA256 over the canonical verified inputs, 256-bit random entropy, a microsecond timestamp, the entity identifier and the preceding seals
Check charactersKeyed (secret-dependent), so they cannot be derived from real codes
Key hierarchyVersioned master keys; a separate HKDF-SHA256 sub-key for every purpose
Data at restAES-256-GCM for sealed profiles, codes, entropy, holder requests and staff authentication secrets
Look-upsCodes, ATV references, tokens and API keys stored only as keyed hashes (blind indexes)
Ledger integrityHash-chained entries, re-derivation of every code on each verification, a nightly full audit
TransportHTTPS only, with HSTS
Staff credentialsArgon2id password hashing and TOTP two-factor authentication with replay protection

3. Application security

  • Strict Content Security Policy: no inline script, style or event handlers, and no third-party scripts
  • Clickjacking protection, no-sniff and no-referrer headers
  • Anti-CSRF tokens on every form; session cookies set as Secure, HttpOnly and SameSite=Strict
  • Server-side validation against controlled vocabularies for every input
  • Rate limiting on the decoder, holder services, seal checks, console sign-in and API keys
  • Single-use, time-limited confirmation links that act only on an explicit POST
  • Uploaded documents hashed in memory and discarded, never stored

4. Access control

Staff access is role-based (registrar, compliance officer, auditor, superadmin) with separation of duties. Console sessions end after 20 minutes of inactivity. Five failed sign-ins lock an account for 15 minutes. Every staff action is written to the audit log.

5. Key management

Master keys are held outside the web root and the database. Offline escrow copies are held under dual control. Keys can be rotated without invalidating codes already issued, and the rotation procedure is tested. Compromise of the database alone does not allow codes to be generated or profiles decrypted.

6. Monitoring and incident response

  • The integrity of the full chain is audited nightly, and any failure raises an immediate security alert.
  • Verification outcomes are monitored for enumeration patterns.
  • Personal data breaches are assessed without delay and, where required, reported to the ICO within 72 hours and to other supervisory authorities, and to affected individuals, within the periods their laws require.
  • If a holder's code or mailbox is suspected to be compromised, the code is suspended and re-issued. All ATVs issued under the old code are withdrawn automatically.

7. Business continuity

Encrypted database backups run daily and restoration is tested. The Registry Charter commits to key escrow, tested restoration and succession arrangements so that the Ledger survives the loss of any single system, supplier or operator.

8. Reporting a vulnerability

See the Responsible Disclosure policy or the machine-readable security.txt.

Related documents

  • Responsible Disclosure
  • Fraud & Impersonation Warning
  • Accessibility Statement
  • Legal Notice
  • All policies in the Legal Centre

Registry information, policies and references

EBRICS EuraBelt Reserves Institutional Codification System

The identity layer of the fuel industry. Verified once, proven on demand, disclosed only by consent. Built to serve for a century.

Genuine Registry address ebrics.eurabeltfuels.com Type it yourself. Never verify through a link or website supplied by the party being checked. Fraud warning →
  • Verify a counterparty
  • Invited institutions
  • Request access — principals only
  • Code holder services
  • Check a document seal
  • Legal Centre

Registry & governance

  • Registry Charter
  • Invitation & Access Policy
  • Verification Standard
  • Document Seal Policy

Terms & conditions

  • Terms of Use
  • Code Holder Terms
  • Counterparty Verification Terms
  • Institutional API Terms
  • Acceptable Use Policy
  • Disclaimer & Liability
  • Brand & Seal Use

Privacy & data

  • Privacy Notice
  • Cookie Notice
  • Your Data Rights
  • Data Retention Schedule
  • PAIA & POPIA Manual (ZA)

Compliance & integrity

  • Sanctions Policy
  • AML, CTF & KYC Statement
  • Anti-Bribery & Corruption
  • Modern Slavery & Human Rights
  • Speak-Up Policy
  • Complaints & Appeals

Security & trust

  • Security Overview
  • Responsible Disclosure
  • Fraud & Impersonation Warning
  • Accessibility Statement
  • Legal Notice
Regulatory references: sanctions lists, data protection authorities and standards

Sanctions lists

  • UK Sanctions List (FCDO)
  • OFSI — HM Treasury
  • OFAC Sanctions List Search (US)
  • UN Security Council Consolidated List
  • EU Sanctions Map
  • Consolidated Canadian Autonomous Sanctions List
  • FIC Targeted Financial Sanctions (South Africa)
  • FIU Trinidad & Tobago — Consolidated List

Data protection authorities

  • Information Commissioner's Office (UK)
  • Office of the Privacy Commissioner of Canada
  • Information Regulator (South Africa)
  • Data Protection Act, 2011 (Trinidad & Tobago)

Standards & registers

  • FATF Recommendations
  • Companies House (UK)
  • WCAG 2.2 (W3C)
  • RFC 9116 — security.txt

EBRICS is a verification and compliance registry. It is not a party to any transaction between its users and does not act as broker, agent or guarantor. Principals make their own decisions through their own teams. A tier or Reserve List designation is not a credit rating or an endorsement. A document without a valid EBRICS code is not recognised by the Registry.

© 2026 Eurabelt Fuels Ltd. Registered in England and Wales, company no. 16639303. Registered office: Flat 11 Clothier House, Kinveachy Gardens, London SE7 8EF, United Kingdom. ICO registration: ZC076060.

United Kingdom · Canada · Trinidad & Tobago · South Africa

  • Terms
  • Privacy
  • Cookies (one essential cookie)
  • Accessibility
  • Complaints
  • Speak up
  • Report a vulnerability
  • security.txt
  • Legal notice