Keep the context
Record configured command results, source inputs, and output artifacts together.
For developers and build teams
Turn your existing builds, tests, and scans into signed evidence. Capture what ran and what it produced on your compute or hosted infrastructure.
Your commands. Your execution environment. An inspectable record.
Keep the result and its context.Inspect the record. Verify it against your trust requirements.
Capture the work.
Logs get separated from the change they describe. CI/lock captures execution evidence so another person or system can inspect the result, check its signature, and evaluate it against requirements.
Record configured command results, source inputs, and output artifacts together.
Sign attestations so a verifier can check their integrity and signer.
Use the results in a gate decision or connect them to technical controls in the platform.
How it works
Start with a build, test, or scan your team already runs. Keep your existing tools.
Run the command with the relevant collectors and signing configuration. Retain the resulting attestation.
Check the signed record, then evaluate it against a policy or connect it to the platform.
Trust you can explain
Signed evidence is only as trustworthy as the process that produces it. If an agent controls the collector or signing authority, it can sign a false claim. Choose the execution and signing boundary for the assurance you need.
Understand the trust boundaryOn your compute or hosted infrastructure. Use your existing execution environment, including GitHub Actions, RWX, or Namespace. Capture support and setup depend on the runner; the docs describe the supported configurations.
CI/lock is TestifySec’s enterprise attestation tooling, built on the in-toto™ specification. It uses an open format for software supply-chain evidence. in-toto is a trademark of The Linux Foundation.
Start with the commands and tools you already use. CI/lock records their execution and configured outputs; your tests still determine what was checked.
Your next step
Record a real check. Inspect the evidence. Build from there.