Step 1
Define the decision
Your service sends who is asking, what they need, which policy version applies, and channel context. The format is the same for live API calls and offline packets.
Binary eligibility for clearance, estate access, and the defence workforce.
Short answer: AffixIO returns a signed yes or no for clearance, facility access, and supplier assurance - evaluated against sources you authorise, without exporting full vetting or HR files to line systems.
Stateless verification · No standing PII store · ML-DSA ready
The Ministry of Defence runs one of the UK's most demanding identity and access environments: permanent staff, reserves, contractors, multinational partners, and classified systems. Programmes need to verify facts without duplicating sensitive records across every consuming application.
Traditional approaches copy vetting outcomes, HR attributes, or registry fields into secondary databases for each new system. That increases breach surface, complicates accreditation, and makes audit trails harder to reconcile across estates.
AffixIO approach: AffixIO sits behind your API gateway and returns a signed yes or no for a defined policy. Clearance gating, estate access, and supplier checks consume the same decision model whether the caller is a web service, a gate reader, or an offline field device.
Confirm clearable or not clearable for role assignment without exporting full vetting files to line managers or contractors.
Prove current employment or visit authorisation at the gate, including offline validation for remote sites.
Verify professional registration, export control signals, and personnel vetting outcomes through a single API contract.
Confirm service-linked facts for councils and charities without transmitting full service records.
Machine-to-machine decisions between systems at different classification boundaries using minimal attributes.
The same three-step model used across AffixIO applies here: describe the decision, evaluate against sources you control, return yes or no with proof.
Step 1
Your service sends who is asking, what they need, which policy version applies, and channel context. The format is the same for live API calls and offline packets.
Step 2
Checks run against registries and rules you authorise. Sensitive fields stay in systems you already operate wherever the design allows.
Step 3
The response is explicit, signed where required, and suitable for audit or partner handoff. AffixIO does not retain the request after the decision.
A thin stateless layer between citizen channels and core departmental systems. It answers eligibility questions; it does not replace case management, payments, or identity providers.
Further reading: technical architecture, what AffixIO is, government data integration.
Binary outcomes for role assignment workflows, with pseudonymised audit metadata.
Signed proofs validated locally when networks are degraded.
Repeatable checks for contractor competencies and registration status.
{
"eligible": true,
"proof": "<signed verification artefact>",
"decision_id": "dec_…",
"evaluated_at": "2026-05-15T12:00:00Z"
}
OpenAPI documentation: api.affix-io.com. Integrate via REST, webhooks, or SDKs.
Connect through your API gateway with TLS, mutual authentication where required, and departmental logging.
Run inside your accredited boundary when policy requires on-premise or private cloud.
Validate signed proofs locally where connectivity is limited. See offline verification.
Machine clients receive the same binary signals as citizen channels. See M2M verification.
Deployments align with MOD cloud and on-premise patterns, including private connectivity to registries you operate or sponsor.
Built for long-lived programmes that must plan beyond legacy signatures and minimise data held at the verification boundary.
No long-term store of who asked or the attributes inside a request. Supports proportionate DPIA narratives.
Artefacts can use Module-Lattice-Based Digital Signature Algorithm (ML-DSA), aligned with NIST post-quantum direction, with optional HSM-backed key ceremonies.
Where policy allows, demonstrate that a rule evaluated to yes without exporting underlying registry content.
Patent pending: AffixIO verification pipeline protected under GB2510622.0 (pending).
See GDPR compliance and privacy policy.
Share your channel mix, assurance constraints, and first use case. We will respond with a practical integration outline.
AffixIO is an independent technology provider. References to UK departments and agencies describe integration patterns for eligible programmes; they do not imply endorsement. Operational deployment is subject to your organisation's assurance, procurement, and data-sharing agreements.