Technology and Service Register¶
| Field | Value |
|---|---|
| Reference | REG-002 |
| Type | Register |
| Version | 1.00 |
| Status | Approved |
| Owner | Technical Lead |
| Approver | Board |
| Approval Record | |
| Effective Date | 2026-08-05 |
| Next Review | 2027-08-05 |
| Review Requirements | As defined in STD-001 |
| Classification | Internal |
Purpose¶
This register records the technology platforms, hosted services and third-party providers relied upon by BRSA.
It provides a single point of reference to support governance, operational continuity, disaster recovery and committee handover.
Scope¶
This register includes hosted services, cloud platforms, software-as-a-service (SaaS) providers, source code repositories and other externally provided services critical to BRSA operations.
It does not record individual devices, personal software or short-lived development resources.
Technology & Service Register¶
| Service | Purpose | Provider | Owner | Criticality | Authentication | Backup / Recovery | Notes |
|---|---|---|---|---|---|---|---|
| GitHub | Source code, governance documents and version control | GitHub | Technical Lead | High | MFA | Repository backups | Organisation repositories |
| Oracle Cloud Infrastructure (OCI) | Hosting platform | Oracle | Technical Lead | High | MFA | Oracle tenancy recovery | Compute, networking and storage |
| OCI Object Storage | Backup repository | Oracle | Technical Lead | High | MFA | Object replication / lifecycle | Primary backup location |
| Cloudflare | DNS, SSL, security and edge services | Cloudflare | Technical Lead | High | MFA | Account recovery | Public DNS and proxy services |
| Ghost | Website and membership platform | Self-hosted | Technical Lead | High | MFA where available | Database and content backups | Public website |
| MySQL | Website database | Self-hosted | Technical Lead | High | Local credentials | Database backups | Supports Ghost |
| Brevo | Transactional email | Brevo | Technical Lead | Medium | MFA | Account recovery | Website email delivery |
| Zoho Mail | Committee email | Zoho | Technical Lead | High | MFA | Account recovery | Organisation email service |
| Proton Pass (planned) | Shared credential management | Proton | Technical Lead | High | MFA | Recovery phrase | Intended replacement for personal password storage |
| Gmail | Long-term administrative mailbox | Technical Lead | Medium | MFA | Google account recovery | Used for selected long-term communications |
Notes¶
- Credentials are managed separately and are not recorded in this register.
- Recovery information for critical services shall be stored securely and be accessible to authorised committee members.
- Changes to critical services should be reflected in this register as part of the implementation process.
Related Documents¶
- ADR-001 Engineering & Documentation Principles
- REG-001 Document Register
- POL-001 Data Protection Policy
Review Requirements¶
As defined in STD-001.
Change History¶
| Version | Date | Author | Summary |
|---|---|---|---|
| 0.10 | 2026-07-16 | Technical Lead | Initial version. |
| 0.50 | 2026-07-24 | DC | Version -> 0.50; Status -> Review; Next Review -> cleared (was 2026-08-31) |
| 0.50 | 2026-08-05 | DC | Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05 |
| 1.00 | 2026-08-05 | DC | Version -> 1.00; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05 |