Skip to content

Technology and Service Register

Field Value
Reference REG-002
Type Register
Version 1.00
Status Approved
Owner Technical Lead
Approver Board
Approval Record
Effective Date 2026-08-05
Next Review 2027-08-05
Review Requirements As defined in STD-001
Classification Internal

Purpose

This register records the technology platforms, hosted services and third-party providers relied upon by BRSA.

It provides a single point of reference to support governance, operational continuity, disaster recovery and committee handover.


Scope

This register includes hosted services, cloud platforms, software-as-a-service (SaaS) providers, source code repositories and other externally provided services critical to BRSA operations.

It does not record individual devices, personal software or short-lived development resources.


Technology & Service Register

Service Purpose Provider Owner Criticality Authentication Backup / Recovery Notes
GitHub Source code, governance documents and version control GitHub Technical Lead High MFA Repository backups Organisation repositories
Oracle Cloud Infrastructure (OCI) Hosting platform Oracle Technical Lead High MFA Oracle tenancy recovery Compute, networking and storage
OCI Object Storage Backup repository Oracle Technical Lead High MFA Object replication / lifecycle Primary backup location
Cloudflare DNS, SSL, security and edge services Cloudflare Technical Lead High MFA Account recovery Public DNS and proxy services
Ghost Website and membership platform Self-hosted Technical Lead High MFA where available Database and content backups Public website
MySQL Website database Self-hosted Technical Lead High Local credentials Database backups Supports Ghost
Brevo Transactional email Brevo Technical Lead Medium MFA Account recovery Website email delivery
Zoho Mail Committee email Zoho Technical Lead High MFA Account recovery Organisation email service
Proton Pass (planned) Shared credential management Proton Technical Lead High MFA Recovery phrase Intended replacement for personal password storage
Gmail Long-term administrative mailbox Google Technical Lead Medium MFA Google account recovery Used for selected long-term communications

Notes

  • Credentials are managed separately and are not recorded in this register.
  • Recovery information for critical services shall be stored securely and be accessible to authorised committee members.
  • Changes to critical services should be reflected in this register as part of the implementation process.

  • ADR-001 Engineering & Documentation Principles
  • REG-001 Document Register
  • POL-001 Data Protection Policy

Review Requirements

As defined in STD-001.


Change History

Version Date Author Summary
0.10 2026-07-16 Technical Lead Initial version.
0.50 2026-07-24 DC Version -> 0.50; Status -> Review; Next Review -> cleared (was 2026-08-31)
0.50 2026-08-05 DC Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05
1.00 2026-08-05 DC Version -> 1.00; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05