Assurance as a by-product of software development
Not a separate manual compliance activity.
PhD Research
An Ulster University PhD project developing continuous, explainable, and auditable open-source software supply-chain assurance as a by-product of normal engineering workflows.
The research connects software-development evidence to explicit assurance obligations using ontology-based models, smart-contract automation, and tamper-evident records to improve release confidence, traceability, and regulatory readiness.
Overview
A framework built for trust
This project focuses on a practical challenge in modern software delivery: how to connect everyday engineering evidence to explicit assurance obligations in a way that is transparent, scalable, and usable in real development environments.
Developed within Ulster University, the research is grounded in academic rigor while addressing real-world needs around governance, compliance, traceability, and release confidence across open-source software supply chains.

Research Focus
Core research themes
The framework is organized around complementary components that make assurance more continuous, explainable, and auditable without forcing teams to abandon established workflows.
Assurance models
Define explicit obligations that connect claims, evidence, and decision points for trustworthy software release decisions.
Ontology-based modelling
Represent dependencies, controls, actors, and evidence relationships in a form that can be reasoned about consistently.
Explainable automation
Use smart-contract and rules-based evaluation to automate checks while keeping outcomes understandable and defensible.
Tamper-evident records
Create durable evidence trails that strengthen traceability, accountability, and regulatory readiness over time.
Workflow
How assurance flows
A four-step pipeline connects governance obligations to engineering evidence, automated evaluation, and a tamper-evident record.
◫
1. Encode the obligations
Governance becomes machine-readable
Policies, procedures, roles, evidence requirements, deadlines, exceptions and compliance regulations are formalised.
⌘
2. Observe the work
Engineering produces evidence as normal
Repositories, builds, reviews, SBOMs, signatures, provenance and vulnerability information provide assurance-relevant output.
◎
3. Assess and decide
Smart-contract-driven evaluation
The output is assessed against the obligation to determine the appropriate response that may alert, escalate, permit, block, ignore or require human review.
⬢
4. Record with integrity
Permissioned blockchain record
A tamper-evident record links pseudonymous actor references, policy versions, evidence hashes, timestamps, assurance decisions and state changes.
Key Outcomes
Why this research matters
Less
repeated compliance work
Reduce duplicated assurance effort by reusing evidence generated during normal development.
More
release confidence
Support stronger decision-making with clearer links between evidence, obligations, and outcomes.
Better
traceability
Maintain auditable records that improve accountability across the software supply chain.
Get in touch
Contact PhD Research for collaboration opportunities, research discussions, or questions about software assurance and supply-chain resilience.
PhD Candidate
Seamus McMillen
Phone
+44 755 739 3353
Email
seamus@conmuto.net
LinkedIn
linkedin.com/in/seamusmcmillen