تسجيل شحنة أصل
المحركات الأربعة
How CopperTrust works · كيف تعمل المنصة
Sovereign assurance for drone & sensitive-chip supply chains - from vendor intake to a signed, tamper-evident passport that anyone can verify. ضمان سيادي لسلاسل توريد الدرونز والشرائح الحساسة، من الاستلام حتى جواز موثّق ومضاد للعبث.
Who does what · الأدوار
Vendor · المورد
Registers incoming asset shipments - chips, drones, payloads - with serials, origin and part numbers.
Vendor viewLab auditor · المختبر
Runs the inspection pipeline, certifies, issues passports and manages lab devices & alerts.
Lab viewClient · العميل
Monitors their own certified assets, live risk score and passport status - nothing else.
Client viewAdmin · المشرف
Full oversight across every tenant - GRC, chain of custody, alerts and users.
All viewsThe end-to-end flow · دورة العمل
Seven stages take a shipment from the vendor’s dock to a client-visible, signed passport.
Vendor intake
Vendor view → Register Asset Shipment. Enter serial, client code, origin country, category and part numbers (OEM file optional). Risk is auto-scored from geo-origin + known chip CVEs + CIS hardening + component count, and the OEM file is stored AES-GCM encrypted.
Verification pipeline
Lab view → Update Pipeline. Pending Intake → Physical XRF Screening → Firmware Fuzzing Lab → Verified & Certified (or Flagged / Rejected), attaching XRF + fuzzing evidence and auditor notes.
Attestation passport
Lab view → Issue Passport. Produces an HMAC-signed passport hash binding serial + risk + physical + firmware evidence. Anyone can verify it; any tampering fails verification.
Governance (GRC + AI)
Lab view → Run GRC / Compliance Dashboard / Hardware Alerts. Predictive supply-chain risk mapped to ISO/IEC 27001, NIST SP 800-161 (C-SCRM) and a HK Critical-Infrastructure baseline, auto-raising deduplicated hardware alerts.
Chain of custody
Lab view → Custody form / Trail / Overview. Each handoff (foundry → assembly → distribution → integration → operation → decommission) is hash-chained + HMAC-signed. Editing any stored event flips verification to BROKEN at that point.
Lab instrument ingest + anomaly detection
Lab view → Register Lab Device / Anomaly Report. An instrument (X-ray, microscopy, thermal/electrical stress, side-channel, acoustic) gets a one-time signing key and pushes SIGNED readings. Readings are graded vs microelectronics baselines; an anomaly raises a critical alert and writes an inspection event onto the custody chain. Unsigned data is rejected.
Client monitoring
Client view. The client sees only their own assets (risk, status, passport). Click a row for its security report. All data is tenant-scoped by RBAC.
Worked case study - demo data · مثال تطبيقي ببيانات توضيحية
Follow one shipment through all seven stages. These are illustrative demo values.
| Shipment serial | CT-DRN-2026-0412 |
|---|---|
| Vendor | Falcon Aerospace Ltd |
| Client tenant | CT-CLIENT · Gulf Defense Systems |
| Asset category | Flight-controller MCU (drone avionics) |
| Origin country | CN - flagged high-risk origin |
| Part numbers | STM32H743 ×40 · ESP32-S3 ×40 · nRF52840 ×20 |
| Auto risk score | 78 · High |
a3f9…7c21 binds serial + risk + physical + firmware evidence. Verifies TRUE.XR-ATLAS-01 pushed signed readings: void ratio 6.5% (limit 2%), delamination 3 (limit 1), foreign bodies 2 (limit 0) → 3 anomalies, peak severity 100. Critical alert raised + inspection event appended to the custody chain.Daily notes · ملاحظات تشغيلية
Sign in
Email + password in the top bar; a name · role chip with Logout appears and the app opens your role’s view.
First login
Change the seeded password and enable 2FA (Security tab) for admin & lab accounts.
Forgot password
Use “Forgot?” on the login bar - a reset OTP is emailed to you.
Language
Switch AR / EN / ZH / RU / ES / FR top-right; layout flips RTL for Arabic.
Print / PDF
Open any report view and press Print for a clean export (nav & forms are hidden).