# TestifySec > The platform for developer and agent trust. CI/lock captures the work; Pushgate checks the push; the platform manages gates and technical-control evidence. Match commands and supported capabilities to the installed release. Some imported reference tracks development source. Retain version limits, correction notes, and trust boundaries when quoting. A signature establishes attribution and integrity under configured trust; it does not prove that a producer was honest or that code is safe. Blog posts are dated context, not the current command reference. ## Blog archive - [FedRAMP 20x: Building Technical Evidence You Can Review](https://www.testifysec.com/blog/fedramp-20x-guide.md) - [Technical Control Evidence, Collected Where the Work Happens](https://www.testifysec.com/blog/how-pipeline-native-compliance-is-transforming-fedramp-authorization.md) - [Check the Package Before You Publish It](https://www.testifysec.com/blog/preventing-claude-code-leak-attestation-policies.md) - [The LiteLLM Incident: Why Package Startup Behavior Matters](https://www.testifysec.com/blog/cilock-litellm-supply-chain-attack.md) - [CI/CD Isolation: Keep Production Authority Away from Untrusted Code](https://www.testifysec.com/blog/ci-cd-isolation-protecting-secrets.md) - [The Trivy Compromise: What Pinning, Isolation, and Evidence Each Do](https://www.testifysec.com/blog/cilock-action-supply-chain-attacks.md) - [Can You Trust the Evidence an Agent Gives You?](https://www.testifysec.com/blog/compliance-evidence-fiction.md) - [Beyond “Trust Me, We Ran the Security Scan”: Evidence You Can Inspect](https://www.testifysec.com/blog/cole-cryptographic-security-scan-evidence.md) - [Modern Software Is Assembled, Not Written: Following Component Provenance](https://www.testifysec.com/blog/cole-software-provenance-traceability.md) - [Claude Code Hooks: Useful Feedback Before the Gate](https://www.testifysec.com/blog/claude-code-hooks.md) - [Platform Driven Compliance with Sigstore at Autodesk](https://www.testifysec.com/blog/automating-compliance-autodesk.md) - [The CrowdStrike Update: Testing Needs Evidence and Scope](https://www.testifysec.com/blog/crowdstrike-incident.md) - [Sigstore vs. in-toto](https://www.testifysec.com/blog/sigstore-vs-in-toto.md) - [Our Role in Protobom, An Open Source Software Supply Chain Tool](https://www.testifysec.com/blog/protobom.md) - [JUDGE and AWS CDK: Lessons from Our Deployment Pipeline](https://www.testifysec.com/blog/judge-cdk.md) - [Announcing JUDGE in AWS Marketplace](https://www.testifysec.com/blog/aws-marketplace-release.md) - [Announcing the Witness GitLab Component](https://www.testifysec.com/blog/witness-gitlab-component.md) - [Shifting Liability in the Supply Chain](https://www.testifysec.com/blog/shifting-liability-in-the-supply-chain.md) - [Automating Technical Evidence for a FedRAMP Review](https://www.testifysec.com/blog/automating-fedramp-compliance.md) - [in-toto Security Audit Response](https://www.testifysec.com/blog/in-toto-sec-audit-response.md) - [Witness and Archivista Join the in-toto Project](https://www.testifysec.com/blog/witness-donation.md) - [Secure Supply Chain with Archivista](https://www.testifysec.com/blog/secure-supply-chain-with-archivista.md) - [JUDGE GitLab Support](https://www.testifysec.com/blog/judge-gitlab-support.md) - [Welcome Fred Kautz](https://www.testifysec.com/blog/blog-welcome-fred-kautz.md) - [Welcome Chris Hughes](https://www.testifysec.com/blog/blog-welcome-chris-h.md) - [Zero Trust in the Software Supply Chain](https://www.testifysec.com/blog/zero-trust-in-the-supply-chain.md) - [What Is the SSDF, and Where Does Technical Evidence Fit?](https://www.testifysec.com/blog/what-is-the-ssdf.md) - [What Is a Software Supply Chain Attestation?](https://www.testifysec.com/blog/what-is-a-supply-chain-attestation.md) - [Keyless Signing With Witness and Sigstore](https://www.testifysec.com/blog/keyless-signatures-sigstore.md) - [Generating and Verifying Attestations With Witness](https://www.testifysec.com/blog/attestations-with-witness.md) - [Witness, Archivista, and Evidence for Secure Development](https://www.testifysec.com/blog/ssdf_compiance_with_witness.md) - [DevSecOps: Moving from Implicit Trust to Explicit Proof](https://www.testifysec.com/blog/devsecops-moving-from-implicit-trust-to-explicit-proof.md) - [Securing Our Vision: The $6.4M Seed Funding Milestone](https://www.testifysec.com/blog/funding-announcement.md) - [The Software Supply Chain - A History of Security Failure](https://www.testifysec.com/blog/software-supply-chain-history-of-failure.md) - [Building an Effective Software Supply Chain Policy](https://www.testifysec.com/blog/why-standardized-attestations-matter.md) - [Go Generics in Witness](https://www.testifysec.com/blog/generics-in-witness.md) - [Enhancing Supply Chain Security with TestifySec](https://www.testifysec.com/blog/enhancing-supply-chain-security.md) - [Compliance, AI, and DevOps in Finance](https://www.testifysec.com/blog/compliance-ai-finance.md) - [Guardians of the Dataverse: Securing the AI Supply and Data Chain](https://www.testifysec.com/blog/guardians-dataverse.md) - [AI Training in Kubernetes](https://www.testifysec.com/blog/ai-training-kubernetes.md) - [Secure Release Processes with in-toto Policy Verification](https://www.testifysec.com/blog/secure-release-processes.md) - [Trust No System: The Unsettling Reality of Zero Trust](https://www.testifysec.com/blog/trust-no-system.md) - [Enhancing Open Source Software Integrity](https://www.testifysec.com/blog/enhancing-open-source-integrity.md) - [Uncovering the History of Your Software Artifacts](https://www.testifysec.com/blog/uncovering-history-software.md) - [Demystify Modern Signing: Keys, Certs, and Envelopes](https://www.testifysec.com/blog/demystify-modern-signing.md) - [A Step Closer to in-Toto'lly Secure: Using in-toto and OPA Gatekeeper](https://www.testifysec.com/blog/in-toto-opa-gatekeeper.md) - [The Burden of Security in Software Maintenance](https://www.testifysec.com/blog/security-burden-maintenance.md) - [Linux xz and the Great Flaws in Open Source](https://www.testifysec.com/blog/linux-xz-open-source-flaws.md) - [Diversity, Equity, and Inclusion in OpenSSF](https://www.testifysec.com/blog/dei-openssf.md) - [Know the Compliance Impact Before the Pull Request Merges](https://www.testifysec.com/blog/github-pr-compliance-impact.md) - [A Signed Build Is Not SLSA Level 3: Lessons from Our Hugo Experiment](https://www.testifysec.com/blog/slsa-level-3-in-75-minutes.md) - [The Signed Record We Didn’t Have in March](https://www.testifysec.com/blog/signed-record-we-didnt-have-in-march.md) - [Trace a Test Before You Trust Its Cache Hit](https://www.testifysec.com/blog/trace-tests-before-caching.md) - [Introducing Pushgate: Evidence Before a Push Is Accepted](https://www.testifysec.com/blog/introducing-pushgate.md)