# Witness, Archivista, and Evidence for Secure Development

Source: https://www.testifysec.com/blog/ssdf_compiance_with_witness

Author: Cole Kennedy

Published: 2023-04-12

Updated: 2026-10-06

Use captured test and build records to support scoped SSDF practices, with verification and storage kept separate.

Editorial update · October 6, 2026

Revised by TestifySec Editorial to remove unsupported outcome claims and explain the current product and trust boundaries. The original publication date and URL are preserved.

- [Current TestifySec docs →](https://www.testifysec.com/docs)
- [Trust architecture →](https://www.testifysec.com/docs/cilock/trust)

Witness and Archivista can help a team retain evidence about software development work. They do not automatically establish that every Secure Software Development Framework practice has been followed.

 

This article originally described the tools for a federal audience. The useful starting point remains a specific engineering claim, such as which artifact was scanned or which validation followed a vulnerability fix.

 

## Witness: capture and verification

 [Witness](https://witness.dev/) captures configured observations about supply-chain steps and supports verification against policy. Available attestors, signing methods, and platform support depend on the selected release. A generic statement that capture works identically in every environment is too broad. 

A signature identifies a signer under a configured trust model and detects alteration of a statement. It does not prove that a compromised producer told the truth or that every step in the lifecycle was observed.

 

## Archivista: storage and retrieval

 [Archivista](https://github.com/in-toto/archivista) stores attestations and provides an interface for finding and retrieving them. Keeping a record available makes later verification possible. Retrieval is not itself a policy decision. 

## Supporting SSDF practices

 [NIST SP 800-218](https://csrc.nist.gov/pubs/sp/800/218/final) describes a secure development program that includes people, processes, and technology. Build, test, and remediation evidence can support selected practices. It does not replace the organization’s responsibilities for scope, review, response, and oversight. 

For a useful mapping, state what the test demonstrates, which artifact or system it covers, who produced the evidence, and when it must be repeated. Preserve failed and missing results as well as successful ones.

 

## Current TestifySec workflow

 [CI/lock captures the work](https://www.testifysec.com/docs/cilock/getting-started/first-attestation), Pushgate checks the push, and the platform manages gates and technical control evidence. Witness remains a separate open-source project with its own maintained instructions. The appliance is a platform deployment option; it is not a shortcut to authorization. 

For federal evaluation, use the [government page](https://www.testifysec.com/government) alongside the [trust architecture](https://www.testifysec.com/docs/cilock/trust) and the requirements that apply to the deployment.
