Assurance as a by-product of software development

Not a separate manual compliance activity.

PhD Research

An Ulster University PhD project developing continuous, explainable, and auditable open-source software supply-chain assurance as a by-product of normal engineering workflows.

The research connects software-development evidence to explicit assurance obligations using ontology-based models, smart-contract automation, and tamper-evident records to improve release confidence, traceability, and regulatory readiness.

Continuous assurance by design

Overview

A framework built for trust

This project focuses on a practical challenge in modern software delivery: how to connect everyday engineering evidence to explicit assurance obligations in a way that is transparent, scalable, and usable in real development environments.

Developed within Ulster University, the research is grounded in academic rigor while addressing real-world needs around governance, compliance, traceability, and release confidence across open-source software supply chains.

Abstract digital flow particles and cyber network connection background representing software assurance and traceable security evidence
Research Focus

Core research themes

The framework is organized around complementary components that make assurance more continuous, explainable, and auditable without forcing teams to abandon established workflows.

Assurance models

Define explicit obligations that connect claims, evidence, and decision points for trustworthy software release decisions.

Ontology-based modelling

Represent dependencies, controls, actors, and evidence relationships in a form that can be reasoned about consistently.

Explainable automation

Use smart-contract and rules-based evaluation to automate checks while keeping outcomes understandable and defensible.

Tamper-evident records

Create durable evidence trails that strengthen traceability, accountability, and regulatory readiness over time.

Workflow

How assurance flows

A four-step pipeline connects governance obligations to engineering evidence, automated evaluation, and a tamper-evident record.

1. Encode the obligations

Governance becomes machine-readable

Policies, procedures, roles, evidence requirements, deadlines, exceptions and compliance regulations are formalised.

2. Observe the work

Engineering produces evidence as normal

Repositories, builds, reviews, SBOMs, signatures, provenance and vulnerability information provide assurance-relevant output.

3. Assess and decide

Smart-contract-driven evaluation

The output is assessed against the obligation to determine the appropriate response that may alert, escalate, permit, block, ignore or require human review.

4. Record with integrity

Permissioned blockchain record

A tamper-evident record links pseudonymous actor references, policy versions, evidence hashes, timestamps, assurance decisions and state changes.

Key Outcomes

Why this research matters

Less

repeated compliance work

Reduce duplicated assurance effort by reusing evidence generated during normal development.

More

release confidence

Support stronger decision-making with clearer links between evidence, obligations, and outcomes.

Better

traceability

Maintain auditable records that improve accountability across the software supply chain.

Get in touch

Contact PhD Research for collaboration opportunities, research discussions, or questions about software assurance and supply-chain resilience.

PhD Candidate

Seamus McMillen

Phone
+44 755 739 3353

Email
seamus@conmuto.net

LinkedIn
linkedin.com/in/seamusmcmillen