Witness and Archivista can help a team retain evidence about software development work. They do not automatically establish that every Secure Software Development Framework practice has been followed.

This article originally described the tools for a federal audience. The useful starting point remains a specific engineering claim, such as which artifact was scanned or which validation followed a vulnerability fix.

Witness: capture and verification

Witness captures configured observations about supply-chain steps and supports verification against policy. Available attestors, signing methods, and platform support depend on the selected release. A generic statement that capture works identically in every environment is too broad.

A signature identifies a signer under a configured trust model and detects alteration of a statement. It does not prove that a compromised producer told the truth or that every step in the lifecycle was observed.

Archivista: storage and retrieval

Archivista stores attestations and provides an interface for finding and retrieving them. Keeping a record available makes later verification possible. Retrieval is not itself a policy decision.

Supporting SSDF practices

NIST SP 800-218 describes a secure development program that includes people, processes, and technology. Build, test, and remediation evidence can support selected practices. It does not replace the organization’s responsibilities for scope, review, response, and oversight.

For a useful mapping, state what the test demonstrates, which artifact or system it covers, who produced the evidence, and when it must be repeated. Preserve failed and missing results as well as successful ones.

Current TestifySec workflow

CI/lock captures the work, Pushgate checks the push, and the platform manages gates and technical control evidence. Witness remains a separate open-source project with its own maintained instructions. The appliance is a platform deployment option; it is not a shortcut to authorization.

For federal evaluation, use the government page alongside the trust architecture and the requirements that apply to the deployment.