Solid Logo

Solid Databox

Solid for Organisations

A hypermedia communications service—like a modern-day postbox—acting as a private, two-way exchange point between one organisation program and its community.

What is the Solid Databox?

The Databox is not the person's general-purpose wallet. It is a relationship-specific post-box operated for a declared program. It enables the organisation to securely provide records, receipts, credentials, warranty information, and notices to the consumer, while enabling the consumer to return submissions, corrections, claims, preferences, or evidence.

Key Features

  • Isolated Security: Every program relationship is a separate security domain.
  • Immutable Records: Accepted records are not silently overwritten; changes create linked, auditable events.
  • Long-term Connections: Connection credentials are portable, rotatable, and holder-bound API keys.
  • Cryptographic Receipts: Every accepted submission produces a signed receipt.

Developer Resources

To set up a Databox for your organisation, you must define an Institution Profile and connect it to the Databox Forge control plane.

Read the Documentation
Open the Admin Demo → Forge Control Panel →

Live in-browser demos with synthetic data — no backend required.

Transformational ESG Governance & Compliance

The Databox provides a globally standards-based method to transformationally improve the governance, delivery, and auditability of ESG (Environmental, Social, and Governance) obligations. It achieves this by encoding rights and obligations as versioned, machine-readable ODRL policies that produce auditable duties. Every transaction generates cryptographically signed receipts and immutable evidence ledgers, ensuring verifiable, zero-knowledge compliance with complex data privacy frameworks.

Platform Features

The Forge Admin console provides a comprehensive suite of tools for organisations to manage their Solid Databox infrastructure, programs, and consumer relationships.

Commerce & POS

  • POS Terminal: Full point-of-sale interface with cart, checkout, tax handling, cash/card payments, and receipt generation.
  • Waiter Ordering: Table-side order management with kitchen dispatch, real-time order tracking, and item-level quantity control.
  • Customer Self-Order: Kiosk-style self-service ordering for customers, reducing friction at the counter.
  • Promotional Display: Digital signage and promotional display preview for in-store screens.
  • Receipt Management: Browse, search, and view all issued receipts with full order details.

Infrastructure & Hosting

  • Hosting Setup: One-click Cloudflare DNS and tunnel configuration with apex domain, www subdomain, and origin binding.
  • IPMS Modules: Dynamic module system with enable/disable toggles, capability declarations, and route management.
  • Connector Mappings: ODBC and LDAP connector simulator with connection string testing and query preview.
  • Event Dispatcher: Dispatch and monitor typed events across the Databox infrastructure.
  • Program Management: Create and manage organisation programs with full lifecycle support.

Governance & Credentials

  • Governance: Role bindings, ODRL policy management, approval gates, and resolution workflows.
  • Verifiable Credentials: Issue, verify, and revoke W3C verifiable credentials for members and programs.
  • Member Management: Provision member pods, manage lifecycle states, and send LDN notifications.
  • Operations: Phase 3 operational horizontals — consent, delegation, emergency, inventory, loyalty, and pricing.

Consumer Rights (ADR-0023)

  • Access Requests: Receive and process consumer access requests with approve/deny workflows.
  • Correction Requests: Handle consumer-initiated data corrections with field-level change tracking.
  • Consumer Ledger: Immutable event ledger tracking all consumer interactions and transactions.
  • Data Portability: Export and import data in standard formats, with full portability registry tracking.

IPMS Module Catalog — 50+ Industry Modules

The Databox IPMS ships with a dynamic module system of 50+ industry modules, each with capability declarations, route management, and enable/disable toggles. Modules are organised into industry verticals and can be tailored per organisation profile.

Commerce & Retail

  • POS: Full point-of-sale — cart, cash register, customer ordering, table sessions, promotions, tickets, native device contract.
  • Menu: Menu management with item categories, pricing, and availability.
  • Catalogue: Product catalogue with variants and attributes.
  • Pricing: Retail pricing and wholesale pricing engine.
  • Discounts: Discount engine with rules, stacking, and conditional logic.
  • Loyalty: Loyalty program management with points and tiers.
  • Barcode: Barcode scanning and lookup.
  • EFTPOS: EFTPOS terminal integration.
  • Payments: Payments, refunds, splits, subscriptions, and tax.

Food & Health Safety

  • Allergy Profile: Allergen matching, ingredient declarations, consumer allergy profiles.
  • Concessions: Concession and entitlement management.
  • Emergency: Break-glass emergency access controls.
  • Consent: Consent management and tracking.
  • Delegation: Delegation of authority management.
  • Device Auth: Device authentication and registration.

Operations & Logistics

  • Delivery: Delivery management, driver dispatch, and driver management.
  • Inventory: Stock management and inventory tracking.
  • Bookings: Reservation and availability management.
  • Jobs: Work-order and job management.
  • Events: Event management and dispatching.
  • Feeds: Product feed generation.
  • Print: Print shop management and job routing.
  • Quotations: Quotation management and rendering.

Governance & Identity

  • Governance: Role bindings, ODRL policy management, approval gates, resolution workflows.
  • Credentials: W3C VC issuance, verification, revocation, and lifecycle.
  • Access: Credential-gated access control.
  • Consumer: Consumer access requests, correction requests, and rights management.
  • Provenance: Provenance tracking and chain of custody.
  • Reputation: Reputation management.
  • Licensing: Licensing management.
  • Org Network: Organisational unit and network management.

Infrastructure & Integration

  • Hosting: Cloudflare DNS, tunnel configuration, and hosting setup.
  • Integration: ODBC/LDAP connector contracts, R2RML mapping, runtime plans.
  • Backups: Backup management and scheduling.
  • Accounting: Accounting bridge and ledger integration.
  • Tax: Tax engine with jurisdiction-aware calculation.
  • Notifications: Notification management and delivery.
  • I18n: Internationalisation and locale negotiation.
  • A11y: Accessibility auditing and contrast checking.
  • Theming: Theming tokens and customisation system.

Web & Social

  • Website: Public website with customer display renderer, public feed renderer, SEO, sitemap/robots.
  • Social: Social notes and interactions.
  • Business: Business information and opening hours.
  • HR: Human resources module.
  • Household: Household management.
  • Records: Record entries and management.
  • Receipt: Receipt documents and management.
  • Ticketing: Ticketing system.
  • MCP: Model Context Protocol server API.

Databox Engine Subsystems

Beyond the IPMS modules, the Databox engine provides 24 core subsystems that implement the governed data exchange, policy enforcement, evidence chain, and compliance decision support.

Identity & Authorization

  • Opaque Provisioning: 128-bit cryptographically secure opaque Databox URL generation — no customer identifiers in paths.
  • Tenant Isolation: Per-program tenant binding, context, isolation guard, and resolver.
  • Authenticated Context: Assurance crosswalk between IdP claims and Databox assurance levels, step-up authentication.
  • Connection Credentials: Holder-bound, program-specific, revocable W3C Verifiable Credentials with bitstring status lists, ES256 signing, and RFC 8693 token exchange.
  • Composed Authorizer: Integrates Databox policy with WAC/ACP, reason codes, and step-up response handling.

Policy & Compliance

  • ODRL Policy Engine: Versioned policy bundles, conflict strategy, constraint evaluation, duty engine with state machine and handlers.
  • Compliance Engine: Australian compliance registry with pinned legislation, compliance digest, and decision-support views.
  • Policy Evaluator: ODRL permission/prohibition/duty evaluation with complexity guard and bundle admission.

Exchange & Evidence

  • Deposit/Submission Gateway: Idempotency registry, RDF shape validation, binary evidence quarantine, and real evidence scanners.
  • Record Proof Validation: Canonicalization, issuer trust store, offline verification, and record proof suite.
  • Signed Receipts: Durable commit before receipt issuance, state progression, and receipt verification.
  • Evidence Ledger: Append-only evidence chain with audit projection and ledger store.
  • Append-Only Storage: Supersession links, tombstone handling, and correction history.

Review & Notification

  • Governed Review Queue: Review assurance, disposition workflow, signed dispositions, and append-only disposition store.
  • Transactional Outbox: Outbox drainer with cursor recovery, SSRF-guarded endpoint validation, and outbound notification channels.
  • Cursor Feed: Cursor-based recovery feed with pagination for catch-up after disconnection.
  • Institutional Bridge: Source-outbox consumption, relationship resolution, and institutional record builder.
  • Reference Consumer Agent: Consumer connection registry, local knowledge store, scoped submissions, and ODRL terms presenter.

Org Mobile Apps — WASM/PWA Container

A unified WASM/PWA container that fetches its identity, features, and permissions from the IPMS at runtime based on the org's vertical profile and the app's purpose. Instead of building separate apps for each purpose, one container dynamically loads UI modules from the IPMS.

App Profiles

  • Waiter App: Table-side order management (local-only network scope).
  • Driver App: Delivery driver management (remote-capable).
  • Tradie App: Trade/tradie field service (local-only).
  • Print App: Print shop operations (local-only).
  • Scorekeeper App: Scorekeeping for events (local-only).
  • Referee App: Referee management for sports (local-only).

Container Features

  • Dynamic Module Loading: UI component bundles fetched from IPMS at boot.
  • Per-Install VC Licensing: Each install receives a Verifiable Credential licence binding app, org, device, scope, and permissions.
  • Network Scope Enforcement: Service worker enforces local-only vs remote-capable access.
  • Solid-OIDC Auth: PWA shell with Solid-OIDC authentication.
  • Profile-Driven Availability: Apps filtered by org's enabled IPMS modules and vertical profile.

Rust Native Components

Beyond the Node.js server and admin console, the Databox ecosystem includes Rust native components for hardware integration, system management, and connector bridging.

POS Edge & Proxy

  • POS Edge (native): Rust POS edge with ESC/POS thermal printer support, cash drawer control, QR code generation, local HTTP server, and IPC.
  • POS Edge Proxy (rust): Proxy layer for POS edge communication.
  • Hardware Abstraction: Hardware abstraction layer for printers, cash drawers, and barcode scanners.

System & Integration

  • Installer (native): Cross-platform installer with macOS launchd service registration, platform-aware Node.js provisioning, pre-flight checks, and deployment handoff.
  • Tray Supervisor (rust): System tray supervisor for desktop lifecycle management.
  • Connector Sidecar (rust): Connector sidecar for IPMS integration with ODBC/LDAP bridging and RDF mapping.

CKAN Bridge — Pod→CKAN Publication Pipeline

An opt-in microservice that publishes governed Solid Pod data to a CKAN open-data portal. The bridge reads from Pods via Solid-OIDC, validates with SHACL, translates RDF to tabular form, and publishes via the CKAN Action API — with idempotent retries, reconciliation drift detection, and correction propagation.

Bridge Microservice (TypeScript)

  • Solid-OIDC Client: DPoP-bound access tokens for reading Pods; short-lived, cached, fail-closed on expiry.
  • CKAN Action API Client: HTTP-only RPC client (package_show, package_create, package_update, datastore_create/upsert/search, organization_show/create, user_show, activity_data_list).
  • SHACL Validator: Fail-closed validation before any data reaches CKAN; non-compliant data is quarantined.
  • RDF→Tabular Translator: Program-profile-driven field mapping with PII anonymisation (stripped, hashed, generalised) and evidence recording.
  • Publication Pipeline: Idempotent via sha256(podIri:contentDigest); bounded retries with quarantine on max-retries-exceeded.
  • Webhook Handler: HMAC-SHA256 signature verification, idempotent event deduplication, routes dataset_created/updated/deleted events.
  • Reconciliation & Drift Detection: Periodic sweeps compare Pod state with CKAN state; detects editor-originated drift and orphaned CKAN datasets.
  • Correction Propagation: Propagates Databox review dispositions (corrected, statement-associated, partially-corrected, etc.) to CKAN datasets with per-recipient notification duties.
  • Metadata Feedback: Writes append-only feedback entries back to the Pod when CKAN metadata changes.
  • Disclosure Ledger: Append-only evidence chain recording every publication, correction, and anonymisation event.
  • HTTP Endpoints: /health, /publish, /webhook.

CKAN Plugin (Python)

  • Thin Plugin: ckanext-databox-bridge — no business logic, no RDF parsing, no Solid auth. All heavy lifting is in the bridge microservice.
  • Webhook Emission: Emits HMAC-signed webhooks on dataset lifecycle events (created, updated, deleted) to the bridge.
  • Custom Action API: ckan_bridge_status (public read-only) and ckan_bridge_sync (service-token-only) for callback synchronisation.
  • Dataset Schema Extensions: Adds databox_provenance_iri, databox_policy_iri, databox_shacl_shape_iri, databox_consent_receipt_iri fields to CKAN dataset schemas.
  • Write Access Control: Bridge service API token is the only authorised writer; public users get read-only.

Testing

  • 197 unit tests across 18 test suites — 92.5% statement coverage.
  • Adversarial security tests: HMAC replay, signature forgery, token expiry fail-closed, DPoP key load failure.
  • Conformance tests: SHACL fail-closed, idempotency dedup, max-retries quarantine, Pod 403 fail-closed.
  • E2E integration test: Full Pod→SHACL→translate→CKAN publish→ledger flow.

Deployment

  • Kubernetes: Deployment, Service, ConfigMap, NetworkPolicies, Kustomize manifests included.
  • Secrets: CKAN API token, DPoP key, webhook secret mounted from Kubernetes Secrets — never inlined.
  • Config: SHACL shapes and program profile mounted from ConfigMaps.
  • Strict ESLint: TypeScript strict + stylistic presets; zero lint errors.

Testing & Deployment

The Databox extension is fail-closed and unit-tested across all subsystems, with integration tests proving live CSS/OIDC/WAC operation. Deployment guides cover Docker Compose and Kubernetes.

Test Coverage

  • 188 unit test files across 24 Databox subsystems (agent, authorization, bridge, IPMS, compliance, context, credential, evidence, feed, gateway, identifiers, notification, ODRL, policy, profile, proof, provisioning, receipt, review, storage, tenant).
  • 99 IPMS-specific unit tests covering module APIs, stores, and handlers.
  • 6 integration tests including live CSS/OIDC/WAC, IPMS handler, IPMS accessibility, Oxigraph sync, vanilla mode, and vertical profiles.
  • Fail-closed stubs verified by dedicated test — no stub silently permits access.

Deployment Options

  • Docker Compose: IPMS deployment via docker-compose.ipms.yml with environment configuration.
  • Kubernetes: Kubernetes manifests for production IPMS deployment.
  • Secret Management: Secret templates for deployment configuration.
  • Live CSS Preset: Experimental Components.js preset for mounting the Forge inside a running CSS instance.
  • Native Installer: Cross-platform installer for macOS with service registration.

41-Language International Support

The Forge Admin console ships with full internationalisation (i18n) across 41 languages spanning European, South American, Asian, and Middle Eastern regions. A built-in language selector in the sidebar allows instant switching with preference persistence.

🇬🇧 English 🇫🇷 Français 🇮🇹 Italiano 🇳🇱 Nederlands 🇪🇸 Español 🇩🇪 Deutsch 🇬🇷 Ελληνικά 🇵🇹 Português 🇵🇱 Polski 🇸🇪 Svenska 🇩🇰 Dansk 🇳🇴 Norsk 🇫🇮 Suomi 🇨🇿 Čeština 🇭🇺 Magyar 🇷🇴 Română 🇧🇬 Български 🇭🇷 Hrvatski 🇸🇰 Slovenčina 🇸🇮 Slovenščina 🇪🇪 Eesti 🇱🇻 Latviešu 🇱🇹 Lietuvių 🇧🇷 Português (BR) 🇨🇳 中文 (简体) 🇹🇼 中文 (繁體) 🇯🇵 日本語 🇰🇷 한국어 🇻🇳 Tiếng Việt 🇹🇭 ไทย 🇮🇩 Bahasa Indonesia 🇲🇾 Bahasa Melayu 🇵🇭 Filipino 🇮🇳 हिन्दी 🇧🇩 বাংলা 🇮🇳 தமிழ் 🇸🇦 العربية 🇮🇱 עברית 🇮🇷 فارسی 🇹🇷 Türkçe

Cross-Platform Installer

  • macOS Support: Universal installer for both Intel (x86_64) and Apple Silicon (Metal/aarch64) architectures.
  • Platform-Aware Node.js Provisioning: Automatically downloads the correct Node.js binary for the host platform and architecture.
  • Native Service Registration: Uses launchd and launchctl for macOS service management with privilege detection.

Native POS Edge

  • Rust Hardware Bridge: Native POS-edge component in Rust for direct hardware integration.
  • Thermal Printer Support: ESC/POS protocol support for thermal receipt printers.
  • Cash Drawer Control: Direct cash drawer kick-out commands via connected printer hardware.
  • HTTP & IPC: Local HTTP server with IPC for inter-process communication and lifecycle events.

Industry Applications

Discover how the Solid Databox fundamentally transforms data governance and relationships across every sector.

Loading applications...

Interactive Demonstrators

Explore the live integrations currently running on this Databox server instance.

NOTE: This static GitHub Pages version cannot run the backend provisioner APIs. Clone the repo and run locally for full interactivity.

Seraphim Welfare Demonstrator

Generate a secure connection string for a new welfare consumer ("Charles James"). The consumer can scan this QR code with their mobile Databox app to establish a trust relationship.

MegaMart Loyalty Forge

Generate a secure connection string for a new synthetic loyalty customer ("Customer 042"). This will forge a new program relationship and post a digital receipt to their Databox.

Case Worker Dashboard

Active Case: Charles James

This panel securely renders the cryptographic receipts and live references for the data physically committed to the Databox server.

No case data provisioned yet. Please provision the consumer first.