# Get started with CI/lock

Source: https://www.testifysec.com/docs/cilock

Install CI/lock, capture your first signed attestation, and connect your evidence to the TestifySec platform.

![](https://www.testifysec.com/media/brand-assets/products/cilock/cilock-mark-color.svg)Getting started

Capture signed evidence from your existing commands, then inspect and verify the result.

## Before you start

Choose a machine or CI runner where you can run a build, test, or scan. You will configure signing as part of the first-attestation guide.

## Your first workflow

1. [**Install CI/lock**Choose the binary for your environment and verify the installation.](https://www.testifysec.com/docs/cilock/getting-started/installation)
2. [**Create your first attestation**Run a real command, inspect the signed record, and verify it against a policy.](https://www.testifysec.com/docs/cilock/getting-started/first-attestation)
3. [**Connect to the platform (optional)**Configure authentication and send evidence to your platform environment.](https://www.testifysec.com/docs/cilock/getting-started/connect-to-the-platform)

## Check your result

You can inspect the signed attestation for your command and verify it against the policy in the first-attestation guide.

## Run it in your workflow

- [CI quickstart](https://www.testifysec.com/docs/cilock/getting-started/quickstart-ci)
  
  Capture evidence from a pipeline.
- [GitHub Actions](https://www.testifysec.com/docs/cilock/tutorials/github-actions-pipeline)
  
  Add evidence collection to an Actions workflow.
- [GitLab CI](https://www.testifysec.com/docs/cilock/tutorials/gitlab-ci-pipeline)
  
  Capture and verify evidence in GitLab.

## Reference

- [CLI commands](https://www.testifysec.com/docs/cilock/reference/cli)
  
  Flags, subcommands, and usage.
- [Attestors](https://www.testifysec.com/docs/cilock/attestors)
  
  Choose what CI/lock records.
- [Supported tools](https://www.testifysec.com/docs/cilock/tools)
  
  Find capture guidance for your existing tools.

## Understand the evidence

- [Attestations](https://www.testifysec.com/docs/cilock/concepts/attestations)
  
  What the signed record contains.
- [Signing and identity](https://www.testifysec.com/docs/cilock/concepts/signing-and-identity)
  
  How evidence is attributed.
- [Trust models](https://www.testifysec.com/docs/cilock/trust)
  
  Choose and understand the verification boundary.

## When you need help

- [Verify the CI/lock binary](https://www.testifysec.com/docs/cilock/getting-started/verify-the-cilock-binary)
  
  Check the downloaded release.
- [Execution support](https://www.testifysec.com/docs/concepts/support-matrix)
  
  Check available and planned configurations.
- [Frequently asked questions](https://www.testifysec.com/docs/cilock/faq)
  
  Answers about capture, signing, and verification.

## Continue with another product

CI/lock captures the work. Pushgate checks the push. The platform manages gates and evidence.

[![](https://www.testifysec.com/media/brand-assets/products/pushgate/pushgate-mark-color.svg)Pushgate docs](https://www.testifysec.com/docs/pushgate)[![](https://www.testifysec.com/media/brand-assets/products/platform/shield-blue.svg)Platform docs](https://www.testifysec.com/docs/platform)
