Skip to main content

For developers and build teams

CI/lock

Record the work.
Prove what ran.

Turn your existing builds, tests, and scans into signed evidence. Capture what ran and what it produced on your compute or hosted infrastructure.

Your commands. Your execution environment. An inspectable record.

EXECUTION → SIGNED RECORDIllustrative example
Choose the work to capture
Tests evidencepayments-api · a71f3c2
✓ Recorded
Work observed
Unit test run
Result
Exit code 0
Subject
Commit a71f3c2
Producer
Configured build runner
Record
Signed attestation

Keep the result and its context.Inspect the record. Verify it against your trust requirements.

Capture the work.

A green check is a result. Keep the work behind it.

Logs get separated from the change they describe. CI/lock captures execution evidence so another person or system can inspect the result, check its signature, and evaluate it against requirements.

Keep the context

Record configured command results, source inputs, and output artifacts together.

Make the record verifiable

Sign attestations so a verifier can check their integrity and signer.

Put the evidence to work

Use the results in a gate decision or connect them to technical controls in the platform.

How it works

From a command to evidence you can use.

  1. 01

    Choose a real check

    Start with a build, test, or scan your team already runs. Keep your existing tools.

  2. 02

    Capture it with CI/lock

    Run the command with the relevant collectors and signing configuration. Retain the resulting attestation.

  3. 03

    Inspect and verify

    Check the signed record, then evaluate it against a policy or connect it to the platform.

Follow the product guide

Trust you can explain

A signature protects the record. The producer matters, too.

Signed evidence is only as trustworthy as the process that produces it. If an agent controls the collector or signing authority, it can sign a false claim. Choose the execution and signing boundary for the assurance you need.

Understand the trust boundary

Before you start

Clear answers.

Go deeper in the docs
Where does CI/lock run?

On your compute or hosted infrastructure. Use your existing execution environment, including GitHub Actions, RWX, or Namespace. Capture support and setup depend on the runner; the docs describe the supported configurations.

How does CI/lock relate to in-toto?

CI/lock is TestifySec’s enterprise attestation tooling, built on the in-toto™ specification. It uses an open format for software supply-chain evidence. in-toto is a trademark of The Linux Foundation.

Do I need to change my tests?

Start with the commands and tools you already use. CI/lock records their execution and configured outputs; your tests still determine what was checked.

Your next step

Start with one command.

Record a real check. Inspect the evidence. Build from there.

Create your first attestation